Privacy Policy
Effective 2 September 2026
CyberSpec Pro Ltd. (“CyberSpec,” “we,” “us”) operates cyberspec.pro and portal.cyberspec.pro. This policy explains what data we collect, why, and what rights you have over it.
Information we collect
- Account data — email, password (stored hashed, never in plaintext), organization name, and OAuth identity if you sign in with Google or GitHub.
- Billing data — handled directly by Polar, our payment processor (see “Third parties” below). We never see or store your card details.
- Scan and asset data — the domains, IPs, and CIDR ranges you add, ownership-verification tokens, and the scan findings (CVEs, CVSS scores, host:port data) those scans produce.
- Waitlist signups — email, and optionally name/company/use case, used only to notify you at launch. The submitting IP address is stored as a keyed HMAC, never in the clear, solely to rate-limit abusive signups; that rate-limit record expires after one hour.
- Audit and security logs — actor, action, IP address, and timestamp for security-relevant actions on your account (e.g. asset ownership attestations).
How we use it
To provide the scanning service itself (running scans, correlating findings, generating reports), to operate your account and billing, to notify you about your scans and findings, to prevent abuse, and to respond to support requests. We do not sell your data.
Third parties
These aren’t subprocessors acting on our instructions — each is its own controller for the data it handles:
- Google Sign-In / GitHub Sign-In — if you choose OAuth login, the identity provider authenticates you; we receive your name and email, not your password.
- Polar — our payment processor, acting as Merchant of Record. Polar is the seller on every transaction, collects and remits sales tax/VAT itself, and handles your payment details directly — see Polar’s privacy policy.
- Cloudflare (optional, onboarding) — if you connect Cloudflare to auto-verify domain ownership, the access token is used once to write a DNS record, then discarded. Nothing Cloudflare-related is stored afterward.
Subprocessors
Vendors that process data on our instructions, as part of running the service:
- AWS — application hosting.
- MongoDB Atlas — primary database.
- Cloudflare — object storage (R2) and edge/CDN.
- Vercel — hosts cyberspec.pro and runs cookieless performance analytics on it.
- Resend — transactional and alert email delivery.
- WorkOS — single sign-on, for customers on our Enterprise plan only.
- Google Gemini API — generates the AI-written executive summary in your PDF reports from your scan findings. The underlying findings remain the durable record; the summary is presentation only.
- PostHog — planned for in-app product analytics on the portal; not yet in use.
Cookies and analytics
The marketing site (cyberspec.pro) uses Google Analytics (GA4) to measure traffic — see Google’s privacy policy. It also loads Leadsy (r2.leadsy.ai), a third-party visitor-identification tag. Both load on every visit without a separate cookie-consent prompt today. Vercel’s performance analytics on this site are cookieless and carry no identifier. The portal (portal.cyberspec.pro) does not run Google Analytics or Leadsy — it is not indexed by search engines and uses only cookieless first-party performance monitoring, plus your session cookie.
Data retention
- Findings: kept for the life of the asset.
- Audit logs: 1 year.
- Scan history (metadata): kept indefinitely; raw scan output: 30 days.
- Generated reports: 90 days, regenerated on demand after.
- Data export bundles you request: 7 days, one-time download.
- Account deletion: 30-day recoverable grace period, then permanently deleted.
Your rights
You can export your organization’s data or request account deletion at any time from Settings → Privacy in the portal. Deletion requests have a 30-day grace period during which you can cancel. Depending on where you’re located, you may also have the right to access, correct, or object to how we use your data — contact us below to exercise any of these.
Data security
Data in transit is encrypted (TLS). Passwords are hashed, never stored in plaintext. Report downloads use short-lived, access-controlled links rather than public URLs. We can’t promise perfect security — no one can — but these are the concrete measures in place today.
Children’s privacy
CyberSpec is a business tool and isn’t directed at, or knowingly used by, children under 16.
Changes to this policy
If we make a material change, we’ll update the date at the top of this page, and portal users will be asked to re-accept it on next login.
Company information
CyberSpec Pro Ltd. does not yet have a published registered business address. For any written correspondence, use the contact below.
Contact
Questions about this policy, or want to exercise a privacy right directly rather than through the portal? Email legal@cyberspec.pro.