Legal
Privacy Policy
Last updated: September 29, 2026 · Effective for securityposture.dev
1. Overview
This Privacy Policy explains how SecurityPosture (“we”, “us”) collects, uses, and shares information when you use our website, domain analysis tools, monitoring features, and related services (the “Service”). By using the Service you agree to this policy. Product rules are described in our Terms and Conditions.
2. Information we collect
- Account data — email, name, workspace details, and authentication information when you create an account or sign in.
- Scan inputs — domains and related configuration you submit for analysis or monitoring.
- Scan outputs — discovered assets, technologies, certificates, findings, scores, and AI explanations stored in your workspace.
- Billing data — plan, purchase history, and payment status. Card details are processed by our payment provider; we do not store full card numbers.
- Technical data — IP address, browser/device info, cookies/session tokens, and basic analytics for security and reliability.
3. How we use information
- Provide external discovery, posture analysis, and monitoring
- Authenticate users, manage workspaces, and prevent abuse
- Process subscriptions and send transactional notices
- Improve product quality using aggregated or de-identified signals where appropriate
- Comply with law and enforce our Terms
We do not sell your personal information. Scan results in your workspace are not published as a public attack-surface database.
4. External / public data
The Service analyzes publicly observable information associated with domains you submit (DNS, certificates, headers, public technologies, and similar signals). We do not ask for credentials for basic external analysis, and we do not intentionally access private systems.
5. Sharing & processors
We share data only as needed to run the Service, including with:
- Infrastructure providers — hosting, database, auth, and object storage
- AI / processing vendors — models that help explain findings in plain language
- Payment providers — checkout and billing
- Email delivery — transactional messages
- Authorities when required by law or to protect rights and safety
6. Cookies & sessions
We use cookies and similar technologies for authentication, session security, and basic site function. Disabling cookies may prevent sign-in or workspace use.
7. Retention
We keep account, billing, and scan records while your account is active and as needed for operations, security, and legal obligations. You may request deletion of your account or specific scans by contacting us; some records may be retained where required by law.
8. Security
We use industry-standard measures such as encryption in transit and access controls on workspace data. No method of transmission or storage is 100% secure.
9. Your choices
- Update profile and workspace settings when available in-product
- Request deletion of scans or your account
- Request access or correction of personal data we hold about you
- Depending on your location, you may have additional rights under applicable privacy laws
10. International transfers
We may process information in the United States and other countries where our providers operate. If you access SecurityPosture from elsewhere, you understand your information may be transferred to those locations.
11. Children’s privacy
SecurityPosture is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.
12. Changes
We may update this Privacy Policy. Material changes will be reflected by the “Last updated” date on this page. Continued use after changes constitutes acceptance.
13. Contact
Privacy questions: hello@securityposture.dev.