Legal

Privacy Policy

Last updated: September 29, 2026 · Effective for securityposture.dev

1. Overview

This Privacy Policy explains how SecurityPosture (“we”, “us”) collects, uses, and shares information when you use our website, domain analysis tools, monitoring features, and related services (the “Service”). By using the Service you agree to this policy. Product rules are described in our Terms and Conditions.

2. Information we collect

  • Account data — email, name, workspace details, and authentication information when you create an account or sign in.
  • Scan inputs — domains and related configuration you submit for analysis or monitoring.
  • Scan outputs — discovered assets, technologies, certificates, findings, scores, and AI explanations stored in your workspace.
  • Billing data — plan, purchase history, and payment status. Card details are processed by our payment provider; we do not store full card numbers.
  • Technical data — IP address, browser/device info, cookies/session tokens, and basic analytics for security and reliability.

3. How we use information

  • Provide external discovery, posture analysis, and monitoring
  • Authenticate users, manage workspaces, and prevent abuse
  • Process subscriptions and send transactional notices
  • Improve product quality using aggregated or de-identified signals where appropriate
  • Comply with law and enforce our Terms

We do not sell your personal information. Scan results in your workspace are not published as a public attack-surface database.

4. External / public data

The Service analyzes publicly observable information associated with domains you submit (DNS, certificates, headers, public technologies, and similar signals). We do not ask for credentials for basic external analysis, and we do not intentionally access private systems.

5. Sharing & processors

We share data only as needed to run the Service, including with:

  • Infrastructure providers — hosting, database, auth, and object storage
  • AI / processing vendors — models that help explain findings in plain language
  • Payment providers — checkout and billing
  • Email delivery — transactional messages
  • Authorities when required by law or to protect rights and safety

6. Cookies & sessions

We use cookies and similar technologies for authentication, session security, and basic site function. Disabling cookies may prevent sign-in or workspace use.

7. Retention

We keep account, billing, and scan records while your account is active and as needed for operations, security, and legal obligations. You may request deletion of your account or specific scans by contacting us; some records may be retained where required by law.

8. Security

We use industry-standard measures such as encryption in transit and access controls on workspace data. No method of transmission or storage is 100% secure.

9. Your choices

  • Update profile and workspace settings when available in-product
  • Request deletion of scans or your account
  • Request access or correction of personal data we hold about you
  • Depending on your location, you may have additional rights under applicable privacy laws

10. International transfers

We may process information in the United States and other countries where our providers operate. If you access SecurityPosture from elsewhere, you understand your information may be transferred to those locations.

11. Children’s privacy

SecurityPosture is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.

12. Changes

We may update this Privacy Policy. Material changes will be reflected by the “Last updated” date on this page. Continued use after changes constitutes acceptance.

13. Contact

Privacy questions: hello@securityposture.dev.

Terms and Conditions · Security · Scan a domain · Home