ThreatSense
Security Policy
Last updated: October 11, 2026
AES-256 at rest
TLS 1.2+ in transit
Passive checks only
1. Security by Design
ThreatSense is a passive public-website and domain checker. Security is built into every layer of the product: we never authenticate to your systems, we never run intrusive scans, and we only read what the public can already see. We apply least-privilege access and defence-in-depth throughout.
2. Data Protection
All account data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Each customer’s data is logically isolated and never crosses tenant boundaries. Scan results belong to you and are retained only as needed to provide the service.
3. Access Control
Access to production systems is restricted to authorised personnel. We enforce least-privilege, role-based access (owner, admin, member) and audit logging of administrative actions.
4. Passive Checks Only
ThreatSense performs passive, evidence-based checks of public website and domain configuration only. We never log in to your systems, brute force, bypass authentication, crawl private areas, run exploit attempts or scan arbitrary IP ranges. Private IP addresses, localhost and cloud metadata endpoints are blocked.
5. Infrastructure & Monitoring
The platform runs on hardened cloud infrastructure with continuous monitoring and automated alerting. We deploy via immutable infrastructure with signed artifacts.
6. Incident Response
We maintain a documented incident response plan with defined severity levels and escalation paths. In the event of a security incident, we will notify affected customers without undue delay and provide ongoing updates through resolution.
7. Responsible Disclosure
If you discover a vulnerability in ThreatSense, please report it responsibly to security@threatsense.example. We acknowledge reports within 48 hours. Please do not publicly disclose issues before we have remediated them.
8. Contact
Security inquiries: security@threatsense.example.