SSecuTest
PricingBlogAbout
Log InTry for Free

Data protection

Privacy Policy

How SecuTest processes personal data and keeps customer intelligence separate from proprietary global collection.

Effective: October 4, 2026Version: 2026-10-04-v4B2B only

1. Controller

CYBER CLUSTER LLC, 1209 MOUNTAIN ROAD PL NE STE R Albuquerque, NM 87110, is the controller for the processing described in this policy. A Privacy request may be submitted through the contact form.

2. Scope

This policy covers public-site visitors, account users, subscription customers, business contacts, support contacts and personal data that may appear in customer prospect records or service logs.

3. Data we process

CategoryExamples
Account and workspace dataBusiness email, verification state, workspace ID, plan, settings and authentication metadata.
Customer intelligenceDomains submitted or scanned by a customer, scan results, raw DNS evidence, notes, statuses, selected columns and exports.
Technical and security dataRequest IDs, session identifiers, timestamps, errors, rate-limit events, logs and performance metadata.
Product analyticsAllowlisted product events such as page category, acquisition-channel category, CTA placement, selected plan or cadence, scan/export actions and aggregate counts. Public events are not assigned a SecuTest analytics identifier. Authenticated application events may be associated with a one-way hashed workspace reference. SecuTest does not store email addresses, prospect domains, IP addresses, query strings, browser user-agent strings or form contents in the product analytics store.
Billing dataStripe customer and subscription references, amount, currency, status, business identity, billing address and tax data where supplied.
Contact dataName, business email, company, topic and message.

4. Customer Intelligence boundary

Customer-submitted domains, uploaded prospect files and customer scan history are processed for that customer's workspace. They are not injected into SecuTest Global Intelligence, the proprietary global dataset or SecuTest's proprietary global historical collection.

SecuTest's proprietary global intelligence, when collected, is sourced by SecuTest's own collection infrastructure rather than by reusing customer prospect lists.

5. Purposes and legal bases

We process data to provide accounts, scans, prospect intelligence, exports, subscriptions and support; prevent abuse and fraud; maintain security and reliability; measure high-level product and funnel performance; meet accounting and legal obligations; and improve detector and product quality using data we are permitted to use for that purpose.

6. Sources

We receive data from users, Stripe, Formspree, Inc., our hosting and security infrastructure, and publicly accessible internet services queried during authorized product operations or proprietary collection.

7. Providers

ProviderPurpose
Stripe, Inc. and affiliatesSubscription checkout, payments, fraud prevention and invoicing.
Formspree, Inc.Contact-form delivery and spam prevention.
OVH SASWebsite, API and infrastructure hosting in France.
OVHcloudBackups, storage and related infrastructure services.
Bunny Fonts (BunnyWay d.o.o.)Public-site web-font delivery. The authenticated application does not depend on this external font service.

8. Retention

Retention depends on the data type, active product behavior, security needs and legal obligations.

Legacy free scan reportsUp to 30 days.
Legacy paid scan reports and generated filesUp to 365 days.
Anti-abuse event dataUp to 48 hours under the current production policy.
Application and security logsUp to 90 days unless needed for an incident or claim.
Product analytics eventsUp to 90 days. The analytics store is first-party and uses no dedicated analytics cookie, local-storage identifier or session-storage identifier.
Contact-form submissionsUp to 24 months after the last relevant interaction.
Billing, invoice, tax and legal-acceptance recordsUp to 10 years or the applicable statutory period.
BackupsRolling copies for up to 14 days.

Customer prospect and scan data may be retained while the workspace is active and according to product retention controls. Deletion requests are subject to security, billing and mandatory legal-retention constraints.

9. Rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection. Individuals in France may lodge a complaint with the CNIL.

10. Automated infrastructure inference

SecuTest can automatically classify technical signals and generate confidence or commercial context. These outputs concern business infrastructure and are not intended to make decisions producing legal or similarly significant effects about natural persons.

11. Security

We use access controls, least privilege, transport encryption, signed payment webhooks, rate limiting, logging and backups. Security vulnerabilities affecting SecuTest may be reported under the security policy.

12. Cookies and local storage

SecuTest product analytics does not create a dedicated analytics cookie or browser-storage identifier. Public analytics events are stateless. In the authenticated application, the existing strictly necessary login session is used only to derive a one-way hashed workspace reference on the server. See the Cookie Policy.

13. Changes and contact

We may update this policy prospectively. Privacy questions may be submitted through the contact form.

ContentsControllerDataCustomer boundaryProvidersRetentionRightsSecurity
Privacy PolicyTerms & ConditionsCookie Policy