Privacy Policy
Last updated: September 2026
CyberSec Pro (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use and safeguard your personal data under the GDPR, Canada’s PIPEDA, the CCPA/CPRA and other applicable data protection law.
Information we collect
Account information
Full name, email address, company name, job title and billing address, provided during registration.
Usage data
- Scan configurations and target domains
- Tool selections and parameters
- Report generation history
- Login timestamps and session duration
- Feature usage analytics
Payment data
Payment processing is handled entirely by Stripe. We never store card numbers on our servers. We retain only the transaction ID and your subscription status.
Credentials you enter for a scan
Some tools need a password, token or API key for the system you are testing. These are held in memory for the duration of the job, passed to the executing agent and discarded when it ends. They are never written to our database, our logs, our backups or our analytics, and they are masked in the interface as you type them.
How we use your information
- • Provide, maintain and improve the CyberSec Pro platform
- • Process subscription payments and manage billing
- • Send critical security alerts and scan completion notifications
- • Produce aggregate, anonymised usage statistics
- • Keep the platform secure and prevent unauthorised access
- • Comply with legal obligations
We never sell, rent or share your personal data with third parties for marketing purposes.
Data security
Encrypted in transit and at rest
TLS 1.3 with perfect forward secrecy in transit. AES-256-GCM for secrets at rest, under a key kept separate from the token-signing key.
SOC 2-aligned controls
Designed against the SOC 2 Trust Services Criteria. We are not SOC 2 certified and do not claim to be.
Role-based access control
Roles are enforced on the server for every request, with least privilege by default.
Multi-factor authentication
TOTP-based MFA with single-use backup codes.
Data retention
Scan results: Deleted automatically 90 days after the scan date.
Account data: Erased immediately when you confirm account deletion — there is no grace period and no soft-delete copy. Your user record, audit trail, login history, reports, scheduled scans, API keys, notifications and IP allow-list are removed in the same request, and an organization you were the only member of is removed with it.
Audit and access logs: Retained for 12 months, then purged automatically.
Payment records: Held by Stripe for as long as tax and financial regulation requires, typically seven years. On our side we keep only the transaction ID and subscription status.
Your rights
Under the GDPR, and equivalently under PIPEDA and the CCPA/CPRA, you have the following rights:
Right of access
Request a copy of all personal data we hold about you
Right to rectification
Correct personal data that is inaccurate or incomplete
Right to erasure
Request deletion of your personal data (the “right to be forgotten”)
Right to data portability
Export your data in a machine-readable format (JSON)
Right to restrict processing
Limit how we use your data while a dispute is resolved
Right to object
Object to processing based on legitimate interests
We answer GDPR requests within 30 days. You can exercise access, portability and erasure yourself from the dashboard, or write to the address below.
Sub-processors
These are every third party that processes personal data on our behalf. We do not use any other analytics, advertising, error-tracking or customer-messaging service.
Stripe: Payment processing. PCI DSS Level 1 certified. We never see or store your full card number.
Cloudflare: CDN and TLS termination. All traffic to this site passes through Cloudflare, so it processes request metadata including your IP address. Cloudflare also stores our nightly database backups, encrypted before they leave our server — it holds ciphertext and no key.
Mailjet: Transactional email — account, billing and scan notifications. Gmail SMTP is configured as a fallback if Mailjet is unreachable.
Google Analytics: Aggregate site usage. Loaded with Google Consent Mode set to denied, so on this site it stores nothing on your device and cannot recognise you across visits.
Google, GitHub and LinkedIn sign-in: Optional. If you use one, we receive your email address, your name and a link to your profile picture, and nothing else. The picture is loaded from the provider each time your dashboard renders, so that provider can see when you are using it.
PostgreSQL and Redis (self-hosted): Primary database and session cache, running on our own infrastructure in Toronto, Canada. No third party can read them. Encrypted copies of the database are replicated off-site to Cloudflare R2, which has automatic geographic placement — so the backups are the one part of the system with no location guarantee.
Cookies and analytics
This public site sets strictly necessary cookies only, for session handling. Google Analytics is loaded with Google Consent Mode v2 defaulting every storage category to denied, so it writes nothing to your device here and sends only cookieless measurement pings. We use no advertising cookies and sell no data to advertisers.
The signed-in dashboard is separate: it shows a consent banner where you can opt in to analytics and marketing cookies, and nothing beyond strictly necessary cookies is set until you do.
Contact and Data Protection Officer
For privacy enquiries, data access requests, or to exercise any of the rights above:
support@cyber-sec-pro.com
We acknowledge privacy requests within 72 hours. Formal GDPR requests are completed within 30 days, as the law requires.
This policy is published in several languages for your convenience. If the versions differ, the English text is the one that applies.