Privacy notice

MOSAIC is an open, community-run coordination project. This notice explains what that means for your data.

Last updated: June 2026

Our approach

MOSAIC (Multi-Organization Secure AI Coordination) is an open-source, community-driven initiative coordinated on the OWASP Foundation's GitHub. We collect as little personal information as possible and only use it to operate the project and collaborate in the open. We do not sell personal data, and we do not use it for advertising.

Information we handle

Most participation happens on third-party platforms — primarily GitHub — that have their own privacy practices. When you contribute, the following may become part of the public project record:

  • Your GitHub username, profile, and any content you post in issues, discussions, or commits
  • Contributions such as documents, comments, and suggested changes
  • Information you choose to include in an initiative card or public message

This website itself is a set of static pages. It does not require an account and does not set tracking cookies. Standard, non-identifying server logs may be retained for security and reliability by whoever hosts the site.

How information is used

Any information we handle is used solely to run the project: to coordinate between participating initiatives, maintain the public record of decisions and deliverables, respond to questions, and keep the project secure. Because this is an open initiative, contributions are public by design and may be retained indefinitely as part of the project's history.

Third-party services

We rely on services such as GitHub, and we link out to participating organizations and news sources. Those platforms and sites are governed by their own privacy policies, and we encourage you to review them. A link from this site is not an endorsement of a third party's data practices.

Your choices

Participation is voluntary. You decide what to share and what to keep private. If you would like content you contributed to be reviewed, corrected, or removed where feasible, you can raise a request through the project's GitHub repository. Note that some material may remain in the public record (for example, in version history or third-party caches) even after removal.

Children

MOSAIC is a professional coordination effort and is not directed at children. We do not knowingly collect personal information from anyone under the age required by their local law to consent to such processing.

Changes to this notice

As MOSAIC evolves, this notice may be updated. Material changes will be reflected here and, where appropriate, noted in the project repository. Continued participation after an update means you accept the revised notice.

Contact

Questions about privacy are best raised in the open via the MOSAIC GitHub repository, where the community and maintainers can respond.

This notice is provided for transparency and general information. It is not legal advice. MOSAIC's materials are released under the MIT License.