Privacy Policy.
AttackSurface is committed to safeguarding the privacy of security researchers and platform operators. This policy details how we collect, store, and process your data.
1. Information We Collect
We collect only the minimum personal data required to provide security-change intelligence:
- Account Information: Name, email address, password hash (via bcrypt), and chosen role when creating an account.
- Research Configuration: Watchlisted bug bounty programs, custom targets, notification webhooks, and alert settings.
- Authentication Logs: Timestamps, IP addresses, and user-agent strings for session authorization and brute-force prevention.
2. Public Internet Telemetry
AttackSurface ingests public internet telemetry including DNS records, Certificate Transparency logs, HTTP headers, and public bug bounty program scopes. This telemetry is inherently public and is not categorized as user personal data.
3. Zero Selling of Researcher Data
We will never sell, lease, or monetize your research preferences, queries, or watchlists to advertisers, corporate defense teams, or data brokers.
Your investigative intent is treated with confidentiality. We do not notify target companies when a researcher adds an asset to their watchlist.
4. Data Retention & Deletion (GDPR / CCPA)
Under the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you retain the right to:
- Access all personal data linked to your account.
- Request immediate deletion and erasure of your account profile.
- Export your watchlists and research data in standard JSON format.
5. Contact Our Privacy Officer
If you have questions regarding this Privacy Policy or wish to request data erasure, please reach out to:
attacksurface.alerts@gmail.com