Privacy Policy

Last updated: October 2, 2026

1. Who we are

AttackerView is operated by Valerio Baudo, a sole proprietor (eenmanszaak) registered in the Netherlands (KVK: 000058562370). We are the data controller for the personal data described in this policy, unless otherwise stated.

For privacy-related questions, contact us at [email protected].

2. What data we collect

Account data

When you sign in via GitHub or Google OAuth, we receive and store your name, email address, and profile picture. We don't store passwords - authentication is handled entirely by your OAuth provider.

Scan data

When you or another user scans a domain, we collect and store the results of the scan, including:

  • DNS records, TLS certificate details, HTTP headers, and DNSSEC validation results from the target domain.
  • Email security configuration data (SPF, DKIM, DMARC, MTA-STS records).
  • Crawled page URLs and content from publicly accessible pages (and access-controlled pages if you provide credentials).
  • Detected technologies, software versions, WordPress plugin and theme identifiers.
  • Security misconfigurations, vulnerability findings, and CVE verification probe results.
  • HTTP request and response data from the scan (stored encrypted - see Security section). This data is viewable within your account when you inspect individual endpoints in the sitemap.

Scan credentials

If you provide credentials for authenticated crawling (username/password, cookies, or custom headers), those credentials are encrypted at rest using AES-256-GCM before storage. We decrypt them only at scan time to perform the authenticated crawl. The scan runner process never has direct database access - it receives decrypted credentials from the worker only for the duration of the scan.

If we cannot find the fields of your login form automatically, we send a short summary of the login page's form elements (tags, names, labels, placeholders, and visible text) to an AI model provider to identify them. We never send your credentials. See Section 6.

Finding data

Security issues detected by scans are tracked as persistent findings in your account. Each finding stores: the check that identified it, severity, evidence, the target URL, and a timeline of state changes (detected, fixed, regressed, severity changed). If you mark a finding as "accepted" (risk acceptance), that decision and timestamp are stored.

AI pentesting data

When you run an AI-powered penetration test, we collect and store:

  • Pentest reports: The report for each run stays after a trial or subscription ends. It is deleted when you delete that domain or your account. It is not kept or deleted on the same schedule as transcripts, HAR recordings, or live events.
  • Test transcripts: A record of the AI agent's actions, decisions, and findings during the test. Stored encrypted at rest. Retained for 30 days after the test completes, then automatically deleted.
  • HTTP traffic recordings (HAR format): Full request/response data from all HTTP interactions the AI agent makes with your application during the test. Stored encrypted at rest. Retained for 90 days, then automatically deleted.
  • Cross-session observations: The AI agent retains observations about your application across multiple test sessions to improve testing effectiveness. These include patterns it noticed, endpoints it tested, and authentication states it discovered. Observations are scoped to the specific domain, encrypted at rest, and automatically expire after 12 weeks.
  • Pentest events: Real-time progress events streamed during the test. Retained for 24 hours, then automatically deleted.

We use third-party AI models to power pentesting, including the testing agent and finding validation. Only the real-time test session context (what the agent observes during the current test) and finding evidence under review are processed by our AI model providers. We only use them under Do Not Train terms: they may not train their models on your data. We do not send your stored scan data, credentials, or account information to them. See Section 6 and Section 8 for more details.

Surface discovery data

After a scan, we may query public data sources (certificate transparency logs, DNS records, TLS certificates) to discover related hosts and services. This may reveal hostnames, IP addresses, and certificate details for domains you didn't explicitly submit. This data is stored within your tenant's connection map.

Webhook and integration data

If you configure webhooks, we store your webhook endpoint URL and an HMAC-SHA256 signing key (encrypted at rest). We also store delivery records (status, timestamps, response codes) for troubleshooting.

If you configure third-party integrations (Vanta, Drata), we store your integration credentials (OAuth tokens or API keys, encrypted at rest) and track delivery health (last successful push, last error).

API key data

If you create API keys, we store a one-way SHA-256 hash of the key (we cannot recover the full key) and a short prefix for display purposes. We also store usage counters for rate limiting.

Notification preferences

We store your email notification preferences: whether you want monitoring scan alerts (and at what severity threshold), whether you want weekly digest emails (paid tiers only), and whether you want to be notified about newly discovered related hosts.

Usage data

  • IP address - stored in scan metadata for anonymous scan rate limiting (5 scans per IP per day). Retained with the scan record.
  • Domain visit timestamps (to show you what changed since your last visit).

ChatGPT plugin and Claude connector

When you ask ChatGPT or Claude to check a website with AttackerView, OpenAI or Anthropic sends us the domain you asked about. We do not receive your name, email or conversation, and we do not store the identifiers they attach to the request. The check needs no account and is not saved to our database: the result is kept in server memory for up to one hour to answer repeat questions about the same domain, and our error logs may record the domain when a check fails. Results describe the domain's public DNS, email and TLS configuration, which can include contact addresses published in DNS (for example in DMARC records).

Abuse report data

If you submit an abuse report for public scan results, we store the reported hostname, your reason, any details you provide, your optional email address, and your IP address. IP addresses are used for rate limiting (3 reports per IP per day) and abuse prevention.

Payment data

Payment processing is handled entirely by Stripe. We do not see, store, or process your credit card number or banking details. We receive subscription status updates from Stripe via webhooks to manage your tier access. Stripe is PCI DSS Level 1 certified. See Stripe's privacy policy.

Multi-tenancy

If you sign in with a corporate email address (e.g., [email protected]), your account is placed in a shared organizational tenant with other users from the same email domain. This means colleagues at the same company can see all domains, scan results, findings, and settings within the shared tenant. If you sign in with a personal email (Gmail, Yahoo, etc.), you get a private tenant visible only to you.

Tenant assignment is automatic and based on your email domain. We use a list of approximately 4,000 known free email provider domains (Gmail, Yahoo, Outlook, etc.) to distinguish personal from corporate email addresses.

3. How we use your data

  • To provide the service: running scans, displaying results, tracking findings, managing your account and subscriptions, delivering webhook payloads, pushing data to your configured integrations, running AI-powered penetration tests, and sending email notifications.
  • To improve the service: analyzing anonymized, aggregated scan data to improve our detection capabilities. This data cannot be traced back to you or any specific domain.
  • To communicate with you: sending scan completion notifications, monitoring alerts when findings change (counts-only summary for free accounts, full details for paid accounts), weekly digest summaries (paid tiers only), discovery alerts for newly found related hosts, billing notifications, and (with your consent) product updates.
  • To generate compliance evidence: mapping your scan findings to security framework controls (SOC 2, ISO 27001, PCI DSS, HIPAA) for your compliance evidence reports.
  • To enforce our terms: detecting abuse, rate limiting, and preventing unauthorized use.
  • To comply with the law: responding to legal requests and fulfilling our legal obligations.

4. Legal basis for processing (GDPR)

If you're in the EU/EEA/UK, we process your data on these legal bases:

  • Contract performance: Processing necessary to provide you the service you signed up for (account management, running scans, running AI pentests, delivering results, sending configured notifications, pushing data to your configured integrations).
  • Legitimate interest: Service improvement, security, fraud prevention, aggregated analytics, and public scan result publication (informing domain owners about their security posture). We've assessed that these interests don't override your privacy rights.
  • Consent: Marketing communications (you can opt out at any time).
  • Legal obligation: Tax records, responding to valid legal requests.

5. Scan data and third-party domains

When we scan a domain, we may incidentally collect data that could include personal information present on that domain (e.g., email addresses in DNS records, names in TLS certificates, or personal data on publicly accessible web pages).

For this data, we act as a data processor on behalf of the user who initiated the scan (the data controller). Scan report data is:

  • Stored only to make scan results available to the user.
  • Not shared with third parties, except where the user has explicitly configured an integration (Vanta, Drata) or webhook endpoint.
  • Not used for marketing or profiling.
  • Deletable by the user at any time by deleting the associated domain or requesting account deletion.

Public scan results may be displayed publicly on /d/[hostname]. Domain owners can request removal by contacting [email protected] or see our Terms and Conditions (Section 14).

6. Data shared with third parties

When you configure third-party integrations or webhooks, you direct us to send certain data to those services. Here is exactly what is shared:

Webhooks (your endpoint)

When scan events occur (new findings, fixed findings, scan completion, etc.), we send a JSON payload to your configured URL containing: event type, finding title, severity, description, target hostname, and relevant metadata. We do not send raw HTTP traffic, stored credentials, or full page content via webhooks.

Vanta integration

When enabled, we push vulnerability finding data to Vanta's API: finding title, severity (converted to a 0-10 numeric scale), description, remediation guidance, target URL, and a unique finding identifier. We do not send raw HTTP traffic, scan credentials, or your account data.

Drata integration

When enabled, we push finding data to Drata's external evidence API: finding title, severity, description, and remediation guidance. We do not send raw HTTP traffic, scan credentials, or your account data.

AI model providers (AI pentesting and login form detection)

When you run an AI-powered penetration test, test session data (agent observations, tool outputs, and test decisions) and finding evidence are processed by third-party AI model providers. Which models and providers we use can change over time. Whichever we use, we always use them under Do Not Train terms: they process your data solely to generate AI responses and validate findings, and they may not train their models on it.

Unlike Vanta and Drata (which you explicitly configure), our AI model providers are operational sub-processors that are used automatically when you trigger a penetration test. We do not send your stored scan data, credentials, or account information to them - only the real-time test session context and relevant HTTP traffic evidence for finding validation.

They are also used during authenticated scans when we cannot find your login form's fields automatically. In that case we send a summary of the login page's form elements (tags, names, labels, placeholders, and visible text), never your credentials, under the same Do Not Train terms.

In the GDPR context, when you configure integrations, you are instructing us (your processor) to transfer data to a sub-processor. Vanta, Drata, and our AI model providers process this data under their own terms and privacy policies. You are responsible for ensuring you have appropriate agreements in place with Vanta and Drata.

7. Data security

We take data security seriously. Here's what we do:

  • Encryption at rest: All sensitive data is encrypted using AES-256-GCM before being stored. This includes: HTTP traffic from scans (request/response bodies and headers), stored scan credentials (usernames, passwords, cookies, custom headers), webhook signing keys, integration credentials (Vanta OAuth tokens, Drata API keys), pentest transcripts, and pentest HAR recordings. This is the same encryption standard used by banks and government agencies.
  • Encryption in transit: All connections to AttackerView use TLS (HTTPS). We enforce HTTPS on all endpoints.
  • Key rotation: Our encryption supports key rotation without downtime. Old data can be decrypted with the previous key while new data uses the current key.
  • Full-text search without decryption: We use lossy search indexes (PostgreSQL tsvector) for scan traffic search. The original data cannot be reconstructed from these indexes - they exist only to enable search functionality within your account.
  • API key hashing: API keys are stored as one-way SHA-256 hashes. We cannot recover the original key after creation.
  • Webhook signing: Webhook payloads are signed with HMAC-SHA256 so you can verify they originated from AttackerView and weren't tampered with in transit.
  • Architecture isolation: Our scan runner process is stateless and has no direct database access. Scan credentials are decrypted by the worker process and passed to the runner only for the duration of the scan. The runner never touches stored data directly. The pentest runner operates in an isolated container with network-level scope enforcement via proxy allowlisting.

8. Our service providers (sub-processors)

We use the following third-party services to operate AttackerView:

ProviderPurposeCompliance
NeonDatabase hosting (PostgreSQL)SOC 2 Type II
HetznerApplication hosting (EU servers)ISO 27001, GDPR compliant
StripePayment processingPCI DSS Level 1, SOC 2
GitHub / GoogleOAuth authenticationSOC 2
CloudflareDNS resolution (1.1.1.1), tunnelSOC 2, ISO 27001
AI model providersAI models for the pentesting agent, finding validation review, and login form detection during authenticated scansDo Not Train: never used to train their models

User-configured sub-processors

If you enable integrations, the following services also process your data at your direction:

ProviderPurposeData shared
VantaCompliance platform integration (user-configured)Finding metadata (title, severity, URL, remediation)
DrataCompliance platform integration (user-configured)Finding metadata (title, severity, description, remediation)

Vanta and Drata only receive data when you explicitly configure and enable the integration. They are not active sub-processors unless you choose to connect them.

All service providers process data only on our behalf and under our instructions. We have data processing agreements in place where required.

If you need a Data Processing Agreement (DPA) for your organization's compliance requirements, contact us at [email protected].

9. Data retention

  • Account data: Retained as long as your account is active. Deleted within 90 days of an account deletion request (see your account settings), or within 30 days if we terminate your account.
  • Scan results (snapshots and findings): Retained as long as your account is active. Findings persist across scans and track the full lifecycle of each security issue.
  • HTTP traffic data: Encrypted traffic from scans is retained for 30 days for non-monitored domains, then automatically deleted. Monitored domains (active Watchtower subscription) retain traffic for the full monitoring period.
  • Scan event logs: Non-monitored domains retain events from the latest 2 completed scans. Monitored domains retain 90 days of event history.
  • Stored credentials: Encrypted credentials are deleted when you remove them, delete the associated domain, or delete your account.
  • Surface discovery data: Discovery events are periodically pruned (latest 2 runs for non-monitored domains, 90 days for monitored domains).
  • Pentest reports: Kept after a trial or subscription ends. Deleted when you delete that domain or your account.
  • Pentest transcripts: Retained for 30 days after the test completes, then automatically deleted. This period is separate from the pentest report.
  • Pentest HAR recordings: Retained for 90 days after the test completes, then automatically deleted.
  • Pentest cross-session memory: Automatically expires after 12 weeks. Scoped to individual domains.
  • Pentest events: Retained for 24 hours, then automatically deleted.
  • Webhook delivery records: Delivery status records (success/failure, timestamps) are retained for troubleshooting purposes and periodically cleaned up.
  • Integration credentials: Encrypted OAuth tokens and API keys are deleted when you disconnect the integration or delete your account.
  • API keys: Key hashes are deleted when you revoke the key or delete your account.
  • Abuse reports: Retained for our records to track patterns and resolve disputes.

10. Account deletion

You can request deletion of your account at any time through your account settings. The process includes a 90-day retention period during which you can cancel the request. After the retention period, all your personal data, scan data, findings, credentials, pentest data, integrations, webhooks, and API keys are permanently deleted.

If you are the sole user in a shared tenant, the entire tenant is deleted. If other users remain, your personal association is removed and shared resources are reassigned.

You can also exercise your right to erasure by emailing [email protected].

11. Cookies

We use only essential cookies required for the service to function:

  • Session cookie: Keeps you signed in. Set by Auth.js. Expires when you sign out or after the session timeout.
  • CSRF token: Protects against CSRF attacks. Essential for security.

We do not use analytics cookies, advertising cookies, or tracking pixels. We don't use Google Analytics, Facebook Pixel, or any similar tracking tools.

12. International data transfers

Our servers are hosted in the EU (Hetzner, Germany). Our database provider (Neon) stores data in the EU (AWS eu-central-1, Frankfurt).

Some of our service providers (Stripe, GitHub, Google) are US-based companies, and our AI model providers may be located outside the EU/EEA, including in the US. Where data is transferred outside the EU/EEA, we rely on:

  • EU-US Data Privacy Framework adequacy decisions (where applicable).
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Service providers' own GDPR compliance programs and certifications.

If you configure integrations with Vanta or Drata (US-based companies), you are directing us to transfer finding data to those services. The same transfer safeguards (DPF, SCCs) apply to those transfers.

When you run AI pentests, real-time test session data is processed by our AI model providers, and so is the login form summary when an authenticated scan needs help finding your login fields. The same safeguards above apply, and every provider works under Do Not Train terms.

13. Your rights

Under GDPR, CCPA, and similar data protection laws, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure: Ask us to delete your personal data ("right to be forgotten"). You can use our self-service account deletion feature or email us.
  • Restriction: Ask us to limit how we process your data.
  • Portability: Receive your data in a structured, machine-readable format. Scan data can be exported via our API.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email [email protected]. We'll respond within 30 days. If you're in the EU, you also have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (AP).

14. Data we don't collect

For the avoidance of doubt:

  • We don't sell your personal data. Ever.
  • We don't share your data with advertisers.
  • We don't build advertising profiles.
  • We don't use tracking pixels or third-party analytics.
  • We don't store your OAuth provider password.
  • We don't store your payment card details (Stripe handles that).
  • We don't train AI models on your scan data or pentest data, and neither do our AI model providers (Do Not Train).

15. Children's privacy

AttackerView is not intended for use by anyone under 16 years of age. We don't knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we'll delete it.

16. Data breach notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34.
  • Document the breach, its effects, and the remedial actions taken.

17. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. Your continued use of AttackerView after changes are posted constitutes acceptance of the updated policy.

18. Contact

For privacy-related questions or to exercise your data rights:

[email protected]

Valerio Baudo
Sole proprietor (eenmanszaak), registered in the Netherlands
Trading as AttackerView