ThreatSense

Security Policy

Last updated: October 11, 2026

AES-256 at rest
TLS 1.2+ in transit
Passive checks only

1. Security by Design

ThreatSense is a passive public-website and domain checker. Security is built into every layer of the product: we never authenticate to your systems, we never run intrusive scans, and we only read what the public can already see. We apply least-privilege access and defence-in-depth throughout.

2. Data Protection

All account data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Each customer’s data is logically isolated and never crosses tenant boundaries. Scan results belong to you and are retained only as needed to provide the service.

3. Access Control

Access to production systems is restricted to authorised personnel. We enforce least-privilege, role-based access (owner, admin, member) and audit logging of administrative actions.

4. Passive Checks Only

ThreatSense performs passive, evidence-based checks of public website and domain configuration only. We never log in to your systems, brute force, bypass authentication, crawl private areas, run exploit attempts or scan arbitrary IP ranges. Private IP addresses, localhost and cloud metadata endpoints are blocked.

5. Infrastructure & Monitoring

The platform runs on hardened cloud infrastructure with continuous monitoring and automated alerting. We deploy via immutable infrastructure with signed artifacts.

6. Incident Response

We maintain a documented incident response plan with defined severity levels and escalation paths. In the event of a security incident, we will notify affected customers without undue delay and provide ongoing updates through resolution.

7. Responsible Disclosure

If you discover a vulnerability in ThreatSense, please report it responsibly to security@threatsense.example. We acknowledge reports within 48 hours. Please do not publicly disclose issues before we have remediated them.

8. Contact

Security inquiries: security@threatsense.example.