Privacy Policy
1. Data We Collect
We collect essential information to authenticate accounts and process scans safely. This includes:
- Account Metadata: Email address, username, password hashes, and organization details.
- Scan Targets: URL endpoints, API paths, and configuration flags you submit for scanning.
- Auth Credentials: If you supply auth headers or session cookies to run authenticated tests, these are processed temporarily in RAM and redacted/purged immediately, never stored permanently.
2. Scan Findings & Retention
Vulnerability findings, check metrics, and crawler logs are stored securely on our database nodes. We treat security findings with the highest level of confidentiality:
- Findings are only accessible to verified members of your organization's workspace.
- We will **never** sell, disclose, or distribute your vulnerability findings to third-party security vendors or brokers.
- You may request complete deactivation and deletion of your organization workspace, which purges all historical scan data within 30 days.
3. Security Measures
We deploy industry-standard safeguards to protect database records and check histories:
All database connections use TLS 1.3 encryption. Finding evidence and configuration payloads are encrypted at rest using AES-256. Access to our cloud orchestrator requires key authentication, and administrative operations are locked behind multi-factor authentication systems.