Privacy Policy

Last updated: March 28, 2026

1. Introduction

Pentrust (“Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at pentrust.dev, our automated penetration testing platform, and related services (collectively, “Services”).

By using our Services, you consent to the data practices described in this Privacy Policy. If you do not agree with the data practices described in this policy, you should not use our Services.

2. Information We Collect

2.1 Personal Information.

We may collect personal information that you voluntarily provide to us when you:
  • Register for an account (name, email address)
  • Subscribe to our services (billing information, payment details)
  • Contact our support team
  • Participate in surveys or promotions
  • Sign up for newsletters

2.2 Authentication Information.

We collect and store authentication credentials you provide for gray-box or white-box testing, including:
  • Login credentials (encrypted)
  • API keys (encrypted)
  • VPN configurations (encrypted)

All sensitive credentials are encrypted using industry-standard encryption (AES-256) before storage.

2.3 Scan Data.

When you use our security testing Services, we collect:
  • Target domain and URL information
  • Scan configurations and parameters
  • HTTP requests and responses from the target
  • Discovered endpoints and parameters
  • Security findings and vulnerability data
  • Scan logs and execution traces
  • Screenshots of target applications

2.4 Usage Data.

We automatically collect certain information when you visit, use, or navigate our Services:
  • IP address and browser type
  • Device and operating system information
  • Pages visited and features used
  • Time spent on pages and click patterns
  • Referring website or application
  • Log data and error reports

2.5 Cookies and Similar Technologies.

We use cookies and similar tracking technologies to collect information about your browsing activities. See our Cookie Policy section below for more details.

3. How We Use Your Information

We use the information we collect for various purposes, including:

  • Providing Services: To operate, maintain, and provide our security testing Services, including executing scans, generating reports, and delivering findings.
  • Account Management: To create and manage your account, authenticate your identity, and provide customer support.
  • Billing: To process payments, send invoices, and manage subscriptions.
  • Communication: To send you updates, security alerts, technical notices, and respond to your inquiries.
  • Improvement:To analyze usage patterns, troubleshoot issues, and improve our Services' functionality and user experience.
  • Security: To detect, prevent, and address fraud, abuse, security risks, and technical issues.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.
  • AI Training: We may use anonymized scan data to improve our AI models and detection capabilities. Personal information and identifying details are removed before any such use.

4. How We Protect Your Information

We implement appropriate technical and organizational security measures to protect your personal information and scan data:

  • Encryption: All sensitive data is encrypted at rest (AES-256) and in transit (TLS 1.3). Credentials are additionally encrypted before database storage using our encryption service.
  • Access Controls: We implement role-based access controls (RBAC) and strict authentication requirements for internal access to systems.
  • Database Security: Row Level Security (RLS) policies ensure that you can only access your own data.
  • Regular Audits: We conduct regular security assessments and vulnerability scans of our own infrastructure.
  • Data Minimization: We only collect and retain data necessary for providing our Services.
  • Employee Training: Our staff undergo security awareness training and are bound by confidentiality obligations.

However, please be aware that no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

5. Data Retention

5.1 Retention Periods.

We retain your information for as long as your account is active or as needed to provide you with our Services. Specific retention periods:
  • Account Information: Retained for the duration of your account plus 30 days after deletion, unless legal obligations require longer retention.
  • Scan Results: Retained according to your subscription plan. You may delete scan history at any time through your dashboard.
  • Billing Information: Retained for 7 years as required by tax and accounting regulations.
  • Log Data: Retained for 90 days for security and debugging purposes.

5.2 Deletion.

When you delete your account or specific data, we will remove it from our active systems within 30 days. Backup copies may persist for up to 90 days before being permanently deleted.

6. Sharing and Disclosure

6.1 Third-Party Service Providers.

We may share your information with trusted third-party service providers who assist us in operating our Services:
  • Cloud hosting and infrastructure providers
  • Payment processors
  • Email and communication services
  • Analytics providers
  • AI/ML service providers (for vulnerability analysis)

These providers are contractually bound to use your information only for the purposes of providing services to us and maintaining appropriate security measures.

6.2 Legal Requirements.

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas).

6.3 Business Transfers.

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

6.4 With Your Consent.

We may share your information with third parties when we have your explicit consent to do so.

6.5 Aggregated Data.

We may share aggregated or anonymized information that does not identify you personally for research, analysis, or marketing purposes.

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access: You can request a copy of the personal information we hold about you.
  • Correction: You can request that we correct inaccurate or incomplete information.
  • Deletion: You can request that we delete your personal information, subject to certain legal exceptions.
  • Portability: You can request a copy of your data in a structured, machine-readable format.
  • Restriction: You can request that we limit the processing of your information.
  • Objection: You can object to the processing of your information for certain purposes.
  • Withdraw Consent: Where we rely on your consent, you can withdraw it at any time.

To exercise these rights, please contact us at [email protected]. We will respond to your request within 30 days.

7.1 GDPR Rights (EU/EEA Residents).

If you are in the European Union, you have additional rights under the GDPR. Our legal basis for processing your data is primarily performance of our contract with you (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)), where applicable.

7.2 CCPA Rights (California Residents).

California residents have specific rights under the CCPA, including the right to know what personal information we collect, the right to delete personal information, and the right to opt-out of the sale of personal information. We do not sell personal information.

8. Cookie Policy

We use cookies and similar technologies to enhance your experience on our Services:

  • Essential Cookies: Required for the operation of our Services (e.g., authentication, security).
  • Functional Cookies: Enable enhanced functionality and personalization (e.g., theme preferences).
  • Analytics Cookies: Help us understand how visitors interact with our Services (e.g., PostHog, Google Analytics).

You can control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our Services.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from your jurisdiction.

When we transfer data internationally, we implement appropriate safeguards, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions where applicable
  • Additional technical and organizational security measures

10. Children's Privacy

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete such information.

11. Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and the relevant supervisory authorities in accordance with applicable laws. We will provide such notification without undue delay after becoming aware of the breach, where required by law.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last updated” date. For significant changes, we will provide additional notice (e.g., email notification). We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For data protection inquiries from EU residents, you may also contact our EU representative at [email protected].