ThreatSense

Privacy Policy

Last updated: October 11, 2026

1. Overview

ThreatSense, Inc. (“ThreatSense,” “we,” “us”) provides a passive public-website and domain checker for small businesses and small teams. It runs evidence-based, passive checks of what the public can already see about your website and domain, and produces a plain-English, prioritised list of what to fix first. This Privacy Policy explains what data we collect, how we use it, and the choices you have.

2. Data We Process

We process the following categories of data to deliver the service:

  • Account data: name, work email, company, role, and authentication credentials (hashed).
  • Scan inputs: the domain you ask us to check. We only perform passive public checks against it.
  • Observations and findings: public HTTP, TLS, DNS, email-configuration and technology signals, plus CVE matches from public sources (NVD, CISA KEV, EPSS, OSV).
  • Report delivery data: if you ask us to email a report, the email address you provide for that one-time send, only with your consent.
  • Usage data: aggregated, pseudonymised telemetry about feature usage for product improvement.

3. How We Use Data

We use your data exclusively to:

  • Run passive, evidence-based checks of your public website and domain.
  • Produce a plain-English, prioritised report of what to fix first.
  • Operate, secure, and maintain the platform.
  • Provide support and fulfil our contractual obligations.

We do not sell your data, share it for advertising, or use it to train models for other customers. Your data is logically isolated and never crosses tenant boundaries.

4. Data Retention

We retain scan and finding data for the duration of your subscription and for 90 days thereafter to support export and wind-down. Account data is deleted within 30 days of account termination unless retention is required by law.

5. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Checks are passive and read-only; we never authenticate to your systems. Access is least-privilege and logged. See our Security Policy for details.

6. Your Rights

You may access, correct, export, or delete your data at any time from your workspace settings or by contacting privacy@threatsense.example. EU/UK customers have GDPR rights; California residents have CCPA rights. We will respond within 30 days.

7. Subprocessors

We use vetted subprocessors for infrastructure (cloud hosting), billing (Stripe), and report delivery. A current list is available on request. All subprocessors are bound by data processing agreements.

8. International Transfers

Data may be processed in the United States and other regions where our infrastructure operates. We rely on Standard Contractual Clauses for lawful cross-border transfers.

9. Contact

Questions about this policy or your data? Email privacy@threatsense.example.