Government & Law Enforcement Data Request Policy
Last updated: 7 September 2026
MugatuAI LLC (“MugatuAI”, “we”, “us”) — publisher of MugatuAI Signal.
Document Reference: POL-LE-GOV-2026-V1. This policy governs how Mugatu AI handles requests or legal demands from domestic and international law enforcement agencies, government bodies, intelligence entities, and judicial authorities.
Document Reference & Scope
Target Scope: Global operations, infrastructure, software suites (Signal, Cloakworks, Shield), and employee protocols
Custodian: Legal & Information Security Office ( legal@mugatu.ai)
1. Purpose and Core Commitment
This Policy sets forth the principles, standards, and operational procedures governing how Mugatu AI, Inc. ("Mugatu AI") handles requests or legal demands from domestic and international law enforcement agencies, government bodies, intelligence entities, and judicial authorities seeking access to data.
Mugatu AI is committed to customer privacy, data sovereignty, and procedural due process. Mugatu AI does not provide any government or law enforcement agency with direct, voluntary, unfettered, or "backdoor" access to its systems, customer environments, or telemetry. Every government demand is subjected to strict legal scrutiny and verified against our technical architecture.
2. Architectural Limitations on Data Disclosure
Mugatu AI's core products—including Signal, Cloakworks, and Shield—are built on a deterministic, client-boundary, ephemeral architecture. Government agencies serving legal demands on Mugatu AI must understand the fundamental technical limitations of our environment:
- No Persistent Customer Data Stores: Customer Data, prompts, source code snippets, and operational payloads are inspected ephemerally in volatile RAM or directly within the customer's local client environment or designated compute boundary. Mugatu AI does not store, log, retain, or index customer payload data on central servers.
- Inability to Decrypt or Reconstruct: Mugatu AI does not possess, manage, or retain private cryptographic keys utilized in local customer governance or client-side masking. Consequently, Mugatu AI cannot decrypt, reconstruct, or produce plaintext payloads that execute inside customer boundaries.
- Scope of Accessible Information: The only information potentially within Mugatu AI's possession, custody, or control consists of account management metadata, commercial billing records, and high-level aggregated operational telemetry (e.g., license status, tenant connectivity timestamps).
3. Legal Thresholds for Government Demands
Mugatu AI evaluates all incoming demands under applicable statutory and constitutional frameworks, including the U.S. Electronic Communications Privacy Act (ECPA, 18 U.S.C. § 2701 et seq.), the CLOUD Act, the Foreign Intelligence Surveillance Act (FISA), and international data protection laws (including the EU GDPR).
Mugatu AI will not disclose any information absent a valid, legally binding process meeting the minimum standards outlined below.
| Request Mechanism | Permissible Scope Under Law | Mugatu AI Required Verification |
|---|---|---|
| Subpoena (Civil, Criminal, or Administrative) | Non-content subscriber records only (e.g., enterprise account name, billing address, service duration, payment transactions). | Must be issued by a court of competent jurisdiction or authorized administrative agency with statutory authority. |
| Court Order (e.g., 18 U.S.C. § 2703(d)) | Historical connection logs, non-content operational records, or specified transaction metadata. | Requires a judicial finding of "specific and articulable facts" showing reasonable grounds that records are relevant to an active criminal investigation. |
| Search Warrant (Rule 41 or State Equivalent) | Stored communications or contents within company custody (if any existed). | Must be signed by a neutral judge/magistrate upon a sworn finding of probable cause; must narrowly specify targets, dates, and locations. |
| National Security Demands (NSLs, FISA Directives) | Limited subscriber identity records (NSLs under 18 U.S.C. § 2709) or targeted foreign intelligence collection (FISA orders). | Must strictly adhere to statutory authorization, non-discrimination standards, and executive oversight frameworks. |
4. Procedural Protocols for Intake and Challenge
Every legal demand served upon Mugatu AI must undergo the following five-stage verification pipeline:
[ Receipt & Verification ] → [ Customer Notice Evaluation ] → [ Legal & Technical Review ] → [ Narrow / Challenge ] → [ Minimum Disclosure ]
- Step 1: Formal Service & Ingestion. All demands must be served directly to Mugatu AI Legal Counsel via registered agent or through legal@mugatu.ai. No employee outside designated legal personnel is authorized to accept service or discuss system architectures with law enforcement agents.
- Step 2: Customer Notice Requirement (Default Principle). Mugatu AI's policy is to notify the affected enterprise customer immediately upon receipt of any government demand prior to disclosing any records, providing a copy of the legal process so the customer may seek a protective order or quash the demand.
Statutory Nondisclosure Orders (Gag Orders): If a demand is accompanied by a non-disclosure order (e.g., 18 U.S.C. § 2705(b)), Mugatu AI will review the gag order for overbreadth. Unless bound by a constitutionally sound, judicially signed order prohibiting notification, customer notice will be provided. Where gag orders expire or are lifted, Mugatu AI provides retroactive notice to the customer. - Step 3: Legal Scrutiny and Technical Invalidation. Counsel verifies:
- Proper jurisdiction, venue, and authentic signature by an authorized judicial officer;
- Specificity of targets, dates, and account identifiers (generic, dragnet, or bulk requests are rejected prima facie); and
- Technical viability: If the demand requests payload content, prompt text, or decryption keys, Mugatu AI responds with an affidavit of technical impossibility confirming zero retention under Section 2.
- Step 4: Challenging Unlawful or Overbroad Demands. Mugatu AI will contest, quash, or narrow any demand that:
- Lacks a valid statutory basis or violates constitutional guarantees (e.g., Fourth Amendment, First Amendment);
- Requests extraterritorial data in violation of international law or conflict-of-law principles;
- Imposes an undue operational or architectural burden, such as ordering Mugatu AI to re-engineer its software, install backdoors, or disable client-side telemetry filters; or
- Contains unconstitutional or indefinite nondisclosure provisions.
- Step 5: Minimum Necessary Production. If compelled by final court order after all legal appeals and motions to quash are exhausted, Mugatu AI produces only the absolute minimum amount of metadata strictly necessary to satisfy the legal mandate.
5. International Requests & the U.S. CLOUD Act
- Non-U.S. Requests: Mugatu AI does not disclose data directly to foreign law enforcement or foreign intelligence agencies unless the request proceeds through a formal Mutual Legal Assistance Treaty (MLAT), an executive agreement under the U.S. CLOUD Act (18 U.S.C. § 2523), or letters rogatory through a domestic U.S. federal court.
- Cross-Border Conflicts (GDPR / Chapter V): If compliance with a U.S. government demand would compel Mugatu AI to violate foreign data protection laws (such as GDPR Article 48 regarding non-EEA judgments and orders), Mugatu AI will assert statutory conflict-of-laws defenses and seek judicial resolution to protect customer data sovereignty.
6. Emergency Requests (Exigent Circumstances)
Pursuant to 18 U.S.C. § 2702(b)(8) and § 2702(c)(4), Mugatu AI may disclose non-content records to law enforcement only if:
- Mugatu AI reasonably believes that an emergency involving immediate danger of death or serious physical injury to any person requires disclosure without delay; and
- The requesting agency submits a sworn Emergency Disclosure Form detailing the factual basis, the imminent threat, and the justification for proceeding without a warrant.
Emergency disclosures are restricted to the minimum information required to mitigate the immediate physical threat and must be approved by the Chief Executive Officer or General Counsel.
7. Transparency Reporting
To maintain enterprise accountability, Mugatu AI publishes an annual Transparency Report documenting:
- The total volume of legal demands received (criminal subpoenas, search warrants, court orders, NSLs, and FISA orders);
- The category of requesting authorities (federal, state, local, international);
- The disposition of each demand (complied in whole, narrowed, challenged, or rejected); and
- The number of customer accounts impacted.
Mugatu AI reports national security demands in statutory reporting bands permitted by federal law (e.g., 50 U.S.C. § 1874) to maximize public transparency within legal parameters.
8. Contact for Law Enforcement
All legal notices, subpoenas, court orders, or emergency requests must be submitted to:
Mugatu AI, Inc.
Attn: Legal Department – Law Enforcement Compliance
Address: 1000 N Water St, Milwaukee, WI 53202
Email: legal@mugatu.ai | lawenforcement@mugatu.ai
Submission of legal process does not constitute an agreement or acceptance of jurisdiction by Mugatu AI.
Disclaimer: This policy provides internal operational guidance and public enterprise standards for responding to government demands. It should be reviewed annually by outside corporate and national security legal counsel.