Egnyte Generative Artificial Intelligence (“AI”) Policy
The generative AI-powered solutions of Egnyte’s all-in-one-platform (“Egnyte Generative AI”) have evolved over the years, from sensitive information classification to detection of anomalous usage patterns to the more recent introduction of content intelligence for our users. Throughout all our Egnyte Generative AI innovation, our core values have remained consistent: we continue to strive to provide each customer with a platform that safeguards its most valuable and sensitive information and fuels its essential business processes. We understand the adoption of Egnyte Generative AI brings unique risks and challenges. As such, we have developed this Egnyte Generative AI Policy (“Policy”) to showcase our principles in creating a better Egnyte Generative AI experience for our users.
Note: Egnyte also maintains a separate, internal policy to govern AI adoption and internal usage within Egnyte’s employee base.
Egnyte may update this Policy from time to time on written notice (which may include posting the updated Policy on Egnyte’s website) to reflect changes in applicable laws, standards, and/or privacy and security practices. Any capitalized terms herein that are not defined shall have the same meaning ascribed to them in Customer’s agreement with Egnyte.
Generative AI Principles for Egnyte-Developed AI
Egnyte Generative AI supports Egnyte’s apps and integrations, as well as the features of the Egnyte Platform, such as content collaboration, data security, data governance, privacy and compliance, controlled external file sharing, and the integration ecosystem.
Egnyte Generative AI models are built upon the AI principles listed below:
- Data Privacy and Security.
- General: Data privacy and security continue to be of utmost importance to Egnyte when developing and implementing Egnyte Generative AI. Each customer remains the owner of its Content and, in using Egnyte Generative AI on Content, Customer is training the Egnyte Generative AI for Customer’s use. Egnyte Generative AI’s access to and processing of Content is subject to Customer’s Egnyte domain configuration, content governance policies, and administrative settings. Absent Customer’s explicit authorization, Customer Content within Customer’s Egnyte domain will not be (i) accessible by personnel of Egnyte, nor (ii) used for training large language model (“LLM”) AI tools available to the public at large or used to train underlying LLMs that would apply to other customers or in a manner whereby Customer Content could be commingled with other Egnyte customer data or exposed to any other Egnyte customer. These requirements shall be imposed by Egnyte on any applicable LLM subprocessors as part of Egnyte’s agreements with such providers.
- Metadata Traits Aggregation: Certain metadata-centric traits relating to Content may be identified by our systems and aggregated - in an automated fashion - with other similar information in Egnyte’s systems to help improve customers’ and users’ experiences in the usage of Egnyte Generative AI. In no manner will Egnyte’s systems be deployed to identify Customer proprietary or confidential information to Egnyte personnel or allow for the use of such information by Egnyte personnel.
- Personal Data Protection: Any personal data accessed by Egnyte Generative AI is done so within the framework of a user’s prompt, and the minimum access necessary for creating the response is the norm by design and default.
- Data Residency. Egnyte Generative AI operates on separate deployments by region. This allows for Content subject to data residency requirements under applicable data protection laws, such as the General Data Protection Regulation (“GDPR”), to remain in the required region. For clarity, when using Egnyte Generative AI, Customer’s Content will remain stored in the data residency region configured for Customer’s domain by a Customer Administrator; provided, however, that Egnyte shall have no liability for changes to data residency or global processing made in response to subsequent Administrator configurations.
- Output Explainability. The Egnyte Generative AI solution will cite the source data and its limitations when generating output per a user’s prompt.
- Data Quality. Egnyte Generative AI augments out-of-the-box foundational models (trained on general knowledge) with domain-specific knowledge related to a user’s prompt and/or task at hand. Customer can select high-quality data sources, such as specific documents or sets of documents, which allow for more specific output generation.
- Egnyte Generative AI Transparency. Egnyte will continue to: (i) identify clearly to users that they are interacting and/or chatting with Egnyte Generative AI when Egnyte Generative AI appears for usage by such users, and (ii) provide information on how to use Egnyte Generative AI to ensure our customers are receiving the full benefits of its capabilities.
- Compliance and Bias Reduction. In its operations and offerings, including Egnyte Generative AI, Egnyte strives for compliance with applicable laws and regulations, including any applicable requirements of Regulation (EU) 2024/1689 ("EU AI Act") and the California AI Transparency Act (SB 942). Egnyte Generative AI’s foundation incorporates the principles of bias reduction and discriminatory practices avoidance.
AI Classification Model
Egnyte Generative AI does not rise to the level of a “general purpose AI model” as set forth under Article 51 of the EU AI Act. Egnyte Generative AI has not been built to perform multiple tasks, rather its focus is on generating unique output for a particular customer or user as more particularly described above under the principle of “Data Privacy and Security.”
Customer Usage
While Egnyte strives to develop accurate and reliable Egnyte Generative AI output, there are inherent limitations with what AI can generate. It is Customer’s responsibility to conduct human review on all Egnyte Generative AI-generated output. Customer should not rely on Egnyte Generative AI when making business decisions, including, but not limited to, critical employment, financial, legal, and health-related determinations, and Egnyte fully disclaims any liability relating to any such reliance by Customer. Customer must ensure its use of Egnyte Generative AI complies with internal policies, obligations, and applicable laws, such as data protection, privacy, and security regulations.
Customer’s Administrator can configure Egnyte Generative AI via the admin console. For clarity, Customer may not opt-out of the use of Egnyte Generative AI in its entirety.
Third-Party AI Solutions
Egnyte may offer customers and their users the ability to leverage optional third-party AI solutions via API integrations, partnerships, etc. This includes any “bring-your-own-model” integrations for Customer-sourced LLMs. Egnyte makes no commitment that any such solutions will be hosted or supported by Egnyte throughout the term of the Agreement, and any use of such solutions by Customer is at Customer’s sole risk. Egnyte shall have no liability for any such third-party solutions or content, which shall remain between Customer and the third-party content provider.
Subcontractors
Customer should understand that certain functions of Egnyte’s Services, including Egnyte Generative AI, may leverage third-party subcontractors, including third-party cloud providers. Egnyte remains the primary provider of the Services and is responsible for all such subcontracted obligations under our customer agreements. Before we engage with these subcontractors, Egnyte performs due diligence on the subcontractor’s privacy and security practices. Egnyte also executes appropriate contractual agreements with such subcontractors in an effort to meet the requirements of applicable data protection laws.
A current list of Egnyte’s subcontractors/subprocessors may be found at the following link: https://www.egnyte.com/subcontractors.
Last updated: July 2026