← CyberEnforced

Privacy Policy

Last updated: September 12, 2026

This is a template drafted for the CyberEnforced product and has not been reviewed by a lawyer. Replace the bracketed placeholders below and have counsel review it before relying on it for a real launch — in particular, whether you need GDPR/CCPA-specific language depends on where your users are located.

1. What this covers

This Privacy Policy explains what information CyberEnforced ("we," "us") collects when you use the Service, how we use it, and who we share it with.

2. Information we collect

  • Account information: your email address and password (stored as a salted hash, never in plain text).
  • Organization data: organization name, membership, and role (owner, admin, security manager, analyst, viewer).
  • Domain and scan data: the domains your organization adds and the DNS/SPF/DMARC/TLS results, findings, and security scores we generate from scanning them.
  • Project and task data: projects, assignments, and due dates your organization creates to track remediation.
  • Usage data: basic technical data (like IP address and browser type) collected automatically to operate and secure the Service.

3. How we use information

  • To provide the Service — running scans, computing findings and scores, and displaying your organization's data back to your organization's members;
  • To send transactional email — invitations, and overdue-finding reminders and digests;
  • To secure the Service and prevent abuse; and
  • To improve the Service.

We do not sell your personal information.

4. Who we share it with

We use the following sub-processors to run the Service. Each processes data only on our behalf and only as needed to provide their part of the Service:

  • Supabase — database, authentication, and row-level access control for all account, organization, domain, and finding data.
  • Vercel — application hosting for the web app, including scheduled jobs.
  • Render — hosting for the background worker that performs domain scans.
  • Resend — delivery of transactional email (invitations and reminders).

We don't share your data with anyone else except where required by law, to protect our rights, or with your direction.

5. Cookies and session data

We use a session cookie, set by our authentication provider, to keep you logged in. We don't use third-party advertising or tracking cookies.

6. Data retention

We retain your organization's data for as long as your organization has an active account. If you delete your organization or account, we delete the associated data within a reasonable period, except where we're required to keep it longer (for example, for legal or security reasons).

7. Security

Data is encrypted in transit. Access to another organization's data is restricted at the database level (row-level security), not just in the application, so one organization's members cannot query another's data through the Service.

8. Your rights

You can access and update most of your account and organization data directly in the Service. To request deletion of your account or data, or to ask what we hold about you, email privacy@cyberenforced.io. Depending on where you live, you may have additional rights under laws like the GDPR or CCPA; contact us and we'll address your request under the law that applies to you.

9. Children's privacy

The Service is intended for business use and is not directed to children. We don't knowingly collect personal information from children.

10. International data transfers

Our infrastructure providers may process and store data in the United States or other countries. Where required, we rely on appropriate safeguards for any such transfer.

11. Changes to this policy

We may update this Privacy Policy from time to time. We'll update the "Last updated" date above when we do, and for material changes we'll make reasonable efforts to notify account owners.

12. Contact

Questions about this policy? Email privacy@cyberenforced.io.

Terms of Use · Privacy Policy