ThreatSense
Privacy Policy
Last updated: October 11, 2026
1. Overview
ThreatSense, Inc. (“ThreatSense,” “we,” “us”) provides a passive public-website and domain checker for small businesses and small teams. It runs evidence-based, passive checks of what the public can already see about your website and domain, and produces a plain-English, prioritised list of what to fix first. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
2. Data We Process
We process the following categories of data to deliver the service:
- Account data: name, work email, company, role, and authentication credentials (hashed).
- Scan inputs: the domain you ask us to check. We only perform passive public checks against it.
- Observations and findings: public HTTP, TLS, DNS, email-configuration and technology signals, plus CVE matches from public sources (NVD, CISA KEV, EPSS, OSV).
- Report delivery data: if you ask us to email a report, the email address you provide for that one-time send, only with your consent.
- Usage data: aggregated, pseudonymised telemetry about feature usage for product improvement.
3. How We Use Data
We use your data exclusively to:
- Run passive, evidence-based checks of your public website and domain.
- Produce a plain-English, prioritised report of what to fix first.
- Operate, secure, and maintain the platform.
- Provide support and fulfil our contractual obligations.
We do not sell your data, share it for advertising, or use it to train models for other customers. Your data is logically isolated and never crosses tenant boundaries.
4. Data Retention
We retain scan and finding data for the duration of your subscription and for 90 days thereafter to support export and wind-down. Account data is deleted within 30 days of account termination unless retention is required by law.
5. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Checks are passive and read-only; we never authenticate to your systems. Access is least-privilege and logged. See our Security Policy for details.
6. Your Rights
You may access, correct, export, or delete your data at any time from your workspace settings or by contacting privacy@threatsense.example. EU/UK customers have GDPR rights; California residents have CCPA rights. We will respond within 30 days.
7. Subprocessors
We use vetted subprocessors for infrastructure (cloud hosting), billing (Stripe), and report delivery. A current list is available on request. All subprocessors are bound by data processing agreements.
8. International Transfers
Data may be processed in the United States and other regions where our infrastructure operates. We rely on Standard Contractual Clauses for lawful cross-border transfers.
9. Contact
Questions about this policy or your data? Email privacy@threatsense.example.