Last updated: October 2, 2026
AttackerView is operated by Valerio Baudo, a sole proprietor (eenmanszaak) registered in the Netherlands (KVK: 000058562370). We are the data controller for the personal data described in this policy, unless otherwise stated.
For privacy-related questions, contact us at [email protected].
When you sign in via GitHub or Google OAuth, we receive and store your name, email address, and profile picture. We don't store passwords - authentication is handled entirely by your OAuth provider.
When you or another user scans a domain, we collect and store the results of the scan, including:
If you provide credentials for authenticated crawling (username/password, cookies, or custom headers), those credentials are encrypted at rest using AES-256-GCM before storage. We decrypt them only at scan time to perform the authenticated crawl. The scan runner process never has direct database access - it receives decrypted credentials from the worker only for the duration of the scan.
If we cannot find the fields of your login form automatically, we send a short summary of the login page's form elements (tags, names, labels, placeholders, and visible text) to an AI model provider to identify them. We never send your credentials. See Section 6.
Security issues detected by scans are tracked as persistent findings in your account. Each finding stores: the check that identified it, severity, evidence, the target URL, and a timeline of state changes (detected, fixed, regressed, severity changed). If you mark a finding as "accepted" (risk acceptance), that decision and timestamp are stored.
When you run an AI-powered penetration test, we collect and store:
We use third-party AI models to power pentesting, including the testing agent and finding validation. Only the real-time test session context (what the agent observes during the current test) and finding evidence under review are processed by our AI model providers. We only use them under Do Not Train terms: they may not train their models on your data. We do not send your stored scan data, credentials, or account information to them. See Section 6 and Section 8 for more details.
After a scan, we may query public data sources (certificate transparency logs, DNS records, TLS certificates) to discover related hosts and services. This may reveal hostnames, IP addresses, and certificate details for domains you didn't explicitly submit. This data is stored within your tenant's connection map.
If you configure webhooks, we store your webhook endpoint URL and an HMAC-SHA256 signing key (encrypted at rest). We also store delivery records (status, timestamps, response codes) for troubleshooting.
If you configure third-party integrations (Vanta, Drata), we store your integration credentials (OAuth tokens or API keys, encrypted at rest) and track delivery health (last successful push, last error).
If you create API keys, we store a one-way SHA-256 hash of the key (we cannot recover the full key) and a short prefix for display purposes. We also store usage counters for rate limiting.
We store your email notification preferences: whether you want monitoring scan alerts (and at what severity threshold), whether you want weekly digest emails (paid tiers only), and whether you want to be notified about newly discovered related hosts.
When you ask ChatGPT or Claude to check a website with AttackerView, OpenAI or Anthropic sends us the domain you asked about. We do not receive your name, email or conversation, and we do not store the identifiers they attach to the request. The check needs no account and is not saved to our database: the result is kept in server memory for up to one hour to answer repeat questions about the same domain, and our error logs may record the domain when a check fails. Results describe the domain's public DNS, email and TLS configuration, which can include contact addresses published in DNS (for example in DMARC records).
If you submit an abuse report for public scan results, we store the reported hostname, your reason, any details you provide, your optional email address, and your IP address. IP addresses are used for rate limiting (3 reports per IP per day) and abuse prevention.
Payment processing is handled entirely by Stripe. We do not see, store, or process your credit card number or banking details. We receive subscription status updates from Stripe via webhooks to manage your tier access. Stripe is PCI DSS Level 1 certified. See Stripe's privacy policy.
If you sign in with a corporate email address (e.g., [email protected]), your account is placed in a shared organizational tenant with other users from the same email domain. This means colleagues at the same company can see all domains, scan results, findings, and settings within the shared tenant. If you sign in with a personal email (Gmail, Yahoo, etc.), you get a private tenant visible only to you.
Tenant assignment is automatic and based on your email domain. We use a list of approximately 4,000 known free email provider domains (Gmail, Yahoo, Outlook, etc.) to distinguish personal from corporate email addresses.
If you're in the EU/EEA/UK, we process your data on these legal bases:
When we scan a domain, we may incidentally collect data that could include personal information present on that domain (e.g., email addresses in DNS records, names in TLS certificates, or personal data on publicly accessible web pages).
For this data, we act as a data processor on behalf of the user who initiated the scan (the data controller). Scan report data is:
Public scan results may be displayed publicly on /d/[hostname].
Domain owners can request removal by contacting [email protected] or see our Terms and Conditions (Section 14).
When you configure third-party integrations or webhooks, you direct us to send certain data to those services. Here is exactly what is shared:
When scan events occur (new findings, fixed findings, scan completion, etc.), we send a JSON payload to your configured URL containing: event type, finding title, severity, description, target hostname, and relevant metadata. We do not send raw HTTP traffic, stored credentials, or full page content via webhooks.
When enabled, we push vulnerability finding data to Vanta's API: finding title, severity (converted to a 0-10 numeric scale), description, remediation guidance, target URL, and a unique finding identifier. We do not send raw HTTP traffic, scan credentials, or your account data.
When enabled, we push finding data to Drata's external evidence API: finding title, severity, description, and remediation guidance. We do not send raw HTTP traffic, scan credentials, or your account data.
When you run an AI-powered penetration test, test session data (agent observations, tool outputs, and test decisions) and finding evidence are processed by third-party AI model providers. Which models and providers we use can change over time. Whichever we use, we always use them under Do Not Train terms: they process your data solely to generate AI responses and validate findings, and they may not train their models on it.
Unlike Vanta and Drata (which you explicitly configure), our AI model providers are operational sub-processors that are used automatically when you trigger a penetration test. We do not send your stored scan data, credentials, or account information to them - only the real-time test session context and relevant HTTP traffic evidence for finding validation.
They are also used during authenticated scans when we cannot find your login form's fields automatically. In that case we send a summary of the login page's form elements (tags, names, labels, placeholders, and visible text), never your credentials, under the same Do Not Train terms.
In the GDPR context, when you configure integrations, you are instructing us (your processor) to transfer data to a sub-processor. Vanta, Drata, and our AI model providers process this data under their own terms and privacy policies. You are responsible for ensuring you have appropriate agreements in place with Vanta and Drata.
We take data security seriously. Here's what we do:
We use the following third-party services to operate AttackerView:
| Provider | Purpose | Compliance |
|---|---|---|
| Neon | Database hosting (PostgreSQL) | SOC 2 Type II |
| Hetzner | Application hosting (EU servers) | ISO 27001, GDPR compliant |
| Stripe | Payment processing | PCI DSS Level 1, SOC 2 |
| GitHub / Google | OAuth authentication | SOC 2 |
| Cloudflare | DNS resolution (1.1.1.1), tunnel | SOC 2, ISO 27001 |
| AI model providers | AI models for the pentesting agent, finding validation review, and login form detection during authenticated scans | Do Not Train: never used to train their models |
If you enable integrations, the following services also process your data at your direction:
| Provider | Purpose | Data shared |
|---|---|---|
| Vanta | Compliance platform integration (user-configured) | Finding metadata (title, severity, URL, remediation) |
| Drata | Compliance platform integration (user-configured) | Finding metadata (title, severity, description, remediation) |
Vanta and Drata only receive data when you explicitly configure and enable the integration. They are not active sub-processors unless you choose to connect them.
All service providers process data only on our behalf and under our instructions. We have data processing agreements in place where required.
If you need a Data Processing Agreement (DPA) for your organization's compliance requirements, contact us at [email protected].
You can request deletion of your account at any time through your account settings. The process includes a 90-day retention period during which you can cancel the request. After the retention period, all your personal data, scan data, findings, credentials, pentest data, integrations, webhooks, and API keys are permanently deleted.
If you are the sole user in a shared tenant, the entire tenant is deleted. If other users remain, your personal association is removed and shared resources are reassigned.
You can also exercise your right to erasure by emailing [email protected].
We use only essential cookies required for the service to function:
We do not use analytics cookies, advertising cookies, or tracking pixels. We don't use Google Analytics, Facebook Pixel, or any similar tracking tools.
Our servers are hosted in the EU (Hetzner, Germany). Our database provider (Neon) stores data in the EU (AWS eu-central-1, Frankfurt).
Some of our service providers (Stripe, GitHub, Google) are US-based companies, and our AI model providers may be located outside the EU/EEA, including in the US. Where data is transferred outside the EU/EEA, we rely on:
If you configure integrations with Vanta or Drata (US-based companies), you are directing us to transfer finding data to those services. The same transfer safeguards (DPF, SCCs) apply to those transfers.
When you run AI pentests, real-time test session data is processed by our AI model providers, and so is the login form summary when an authenticated scan needs help finding your login fields. The same safeguards above apply, and every provider works under Do Not Train terms.
Under GDPR, CCPA, and similar data protection laws, you have the right to:
To exercise any of these rights, email [email protected]. We'll respond within 30 days. If you're in the EU, you also have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (AP).
For the avoidance of doubt:
AttackerView is not intended for use by anyone under 16 years of age. We don't knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we'll delete it.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. Your continued use of AttackerView after changes are posted constitutes acceptance of the updated policy.
For privacy-related questions or to exercise your data rights:
Valerio Baudo
Sole proprietor (eenmanszaak), registered in the Netherlands
Trading as AttackerView