COOKIE POLICY & CONSENT PREFERENCES · COMPLIANT SEPTEMBER 2026

Cookie Governance & Privacy Center

AttackSurface maintains a zero-advertising, zero-cross-site-tracker architecture. Review our active cookie registry below and customize your preferences in real-time.

1. Strictly Necessary Cookies

Always Active

These cookies are vital for the cryptographic security, user authentication, and CSRF protection of AttackSurface. They cannot be disabled.

Cookie / Storage KeyPurpose & Security ScopeDurationType
session_tokenCryptographically signed operator session credential for authenticated routes14 DaysHTTP-Only / Secure
csrftokenCryptographic nonces preventing Cross-Site Request Forgery attacksSessionCookie (SameSite Lax)
attacksurface_cookie_consentPreserves your governance consent choices across visits1 YearCookie & LocalStorage

2. Functional & Interface Preferences

Optional

These cookies remember your interface preferences between browser visits, such as the White Aesthetic 3D canvas, sidebar pin state, and data density.

Cookie / Storage KeyPurpose & Security ScopeDurationStatus
theme_preferenceRemembers selected visual HUD theme (White Aesthetic 3D / Dark AMOLED)1 YearALLOWED
sidebar_collapsedSaves your preferred operator navigation sidebar dock state1 YearALLOWED

3. Operational & Diagnostic Telemetry

Optional

Anonymous first-party telemetry that measures API latency and detects client-side rendering crashes. We never sell data or share data with ad exchanges.

KeyPurpose & Security ScopeDurationStatus
_as_perf_telemetryAnonymous percentile latency aggregation across geographic regions30 DaysBLOCKED

Ready to Save Your Choices?

Your preferences take effect instantly and synchronize across all open AttackSurface tabs.

4. Absolute Zero Advertising Guarantee

AttackSurface is a security intelligence system engineered for elite penetration testers, security engineers, and enterprise blue teams. We do not integrate Google AdSense, Facebook Pixel, LinkedIn Insight Tags, or commercial broker cookies. Your research activity, target watchlists, and observed differences are strictly private.

Direct Security Desk: attacksurface.alerts@gmail.comPrivacy Policy →