Privacy Policy
Draft — this is a starting point for your legal counsel to review (including GDPR compliance for EU/Irish customers) before commercial launch, not a substitute for legal advice.
1. What we collect
- Account data: name, email, hashed password (never stored in plain text).
- Organisation data: company name, industry, country, subscription/billing details (via Stripe).
- Asset & scan data: domains/IPs you register, and the results of DNS/TLS/port/CVE checks run against them.
- Audit data: a log of actions taken in your account, for security and compliance purposes.
2. How we use it
Solely to provide the service: running the security checks you request, generating reports, enforcing plan limits, and communicating with you about your account. We do not sell your data.
3. Third parties
We share data with the minimum necessary third parties to operate the service: our hosting provider (Vercel), database provider, payment processor (Stripe), transactional email provider (Resend), and public data sources we query on your behalf (NIST NVD, Certificate Transparency logs) — we do not send your account or billing data to those public sources, only the domain/IP you asked us to check.
4. Data retention
Account and scan data is retained for as long as your account is active. Removing a member from an organisation preserves their historical activity for audit purposes but revokes their access. Contact us to request deletion of your account and associated data.
5. Your rights (EU/EEA users)
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and may object to or restrict certain processing. Contact your account administrator or us directly to exercise these rights.
See also our Terms of Service & Acceptable Use Policy.
Last updated: draft, not yet finalized for commercial launch.