Skip to content
Private Beta ·invite-only access. Reach out to get in.
policy document · privacy

Privacy Policy

This document describes the data we collect, why we collect it, how we protect it, and what rights you have over it. It is written to be readable. Where we use technical or legal terminology, we explain what it means.

Effective
May 19, 2026
Last updated
May 19, 2026
Version
2.0
section 01

Overview

This Privacy Policy (the "Policy") describes how vulneraibility.com ("vulneraibility", "we", "us", or "our") collects, uses, discloses, and protects information when you access our website, dashboard, APIs, and related services (collectively, the "Service"). It applies to data we collect from account holders, prospective customers, and visitors. By using the Service you agree to the data practices described here.

Controller of record

For the purposes of EU/UK GDPR and similar regulations, vulneraibility.com is the data controller of the personal data we collect through the Service. Data-subject inquiries can be submitted via our contact page.

section 02

Data we collect

We collect the minimum information required to deliver the Service. We do not maintain hidden tracking pipelines, advertising identifiers, or surveillance telemetry.

2.1 Information you provide

Account data: email address, optional username, authentication tokens (issued by our auth provider), and the technology stack you declare to receive matched CVE alerts.

Billing data: when you subscribe to a paid tier, our payment processor (Stripe, Inc.) collects card details directly. We receive a tokenised reference (Stripe customer ID), the plan tier, the subscription status, and invoice metadata. We do not store full card numbers, CVVs, or banking credentials.

Support correspondence: any information you voluntarily share by email or through the in-product feedback channels.

2.2 Information collected automatically

Server logs: standard HTTP request metadata (timestamp, path, status code, user agent, IP address) retained for security and abuse prevention. These logs are rotated and purged on a fixed retention schedule (see Section 7).

Session cookies: a single signed cookie set by our authentication layer to maintain your logged-in session. No third-party analytics, behavioural, or advertising cookies are deployed by the Service.

2.3 Information from third parties

When you connect an optional integration (Telegram, Slack), the provider returns a webhook URL or chat identifier scoped to the channel you authorize. We do not request, read, or store any other content from those workspaces.

section 03

Purposes and legal bases

We process personal data only for the purposes described below, each tied to a lawful basis under GDPR Article 6.

  • Service delivery (Art. 6(1)(b), contract): matching new CVEs against your declared stack, sending alerts via the channels you have configured, providing access to dashboards and APIs.
  • Billing and tax compliance (Art. 6(1)(b) and (c)): processing subscription payments, issuing invoices, retaining accounting records.
  • Security and abuse prevention (Art. 6(1)(f), legitimate interest): rate limiting, fraud detection, incident response, log analysis.
  • Communication about the Service (Art. 6(1)(b) and (a)): account-related notifications, optional product updates you have opted into.
  • Legal compliance (Art. 6(1)(c)): responding to lawful requests from authorities, complying with regulatory obligations.
section 04

How we share data

We share personal data only with the categories of recipients below, and only to the extent necessary for them to perform their function.

4.1 Sub-processors

We engage the following service providers to operate the Service. Each is bound by a data-processing agreement requiring confidentiality, security, and compliance with applicable data-protection law.

Sub-processorPurposeRegion / safeguards
Stripe, Inc.Payment processing, subscription management, invoicingUnited States (EU SCCs in place)
Resend, Inc.Transactional email delivery (alerts, magic links)United States (EU SCCs in place)
Hosting / managed Postgres providerApplication hosting, database storageEuropean Union (Frankfurt)
Telegram FZ-LLCOptional user-initiated alert channelUnited Arab Emirates (only chat identifiers shared)
Slack Technologies, LLCOptional user-initiated alert channelUnited States (only webhook URLs shared)

4.3 No sale of personal information

We do not sell personal information as defined by the California Consumer Privacy Act, nor do we share personal information for cross-context behavioural advertising.

section 05

International transfers

Our infrastructure and certain sub-processors are located in the United States and the European Union. Where personal data is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission Standard Contractual Clauses (2021/914) and equivalent UK and Swiss addenda, supplemented by technical and organisational measures including encryption in transit and at rest.

section 06

Security

We apply industry-standard administrative, technical, and physical safeguards to protect personal data against unauthorized access, alteration, disclosure, or destruction.

  • Transport: TLS 1.2 or higher for all connections to the Service.
  • Authentication: passwordless sign-in via signed magic links; session tokens are short-lived and signed with rotating server-side secrets.
  • Storage: encryption at rest for the primary database and backups.
  • Access: principle of least privilege; production access is restricted to a small number of personnel and audited.
  • API access: per-key bearer tokens with timing-safe verification; revocation is instant and freezes the key budget immediately.
  • Monitoring: anomaly detection on authentication and rate-limit endpoints; alerting on production error rates.

No internet-facing service can be guaranteed absolutely secure. If we become aware of a personal-data breach that meets the materiality threshold under applicable law, we will notify affected users and the relevant supervisory authority within the timelines required (72 hours under GDPR Article 33).

section 07

Data retention

We retain personal data only for as long as necessary for the purposes set out in this Policy.

  • Account data: retained while your account is active. Deleted immediately when you delete your account from the dashboard, except where retention is required for legal, accounting, or security purposes.
  • Billing records: retained for the period required by applicable tax and accounting law (typically 7 to 10 years).
  • Server logs: retained for up to 90 days, then purged.
  • Backups: encrypted snapshots are retained for up to 35 days, after which they are overwritten.
section 08

Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

8.1 How to exercise your rights

You can exercise most of these rights directly from your dashboard (Settings > Account): export your data, edit your declared stack, or delete your account. For any request that cannot be completed self-service, submit it via our contact page from the email address associated with your account. We respond within one month of receiving a verifiable request (extendable to three months for complex requests, with notice).

8.2 Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is available at edpb.europa.eu.

section 09

Children

The Service is intended for use by professionals aged 18 or older. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided personal data, contact us and we will take steps to delete it.

section 10

Changes to this Policy

We may update this Policy from time to time to reflect changes to the Service, our practices, or applicable law. When we make material changes, we will notify you by email (to the address associated with your account) and update the "Effective date" at the top of this document. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

section 11

Contact us

Questions, requests, and concerns regarding this Policy or our data practices can be submitted via our contact page. We monitor that channel and route privacy enquiries to the appropriate owner.

document end

Questions about this Policy can be submitted via our contact page. We monitor that channel and route privacy enquiries to the appropriate owner.