Legal
PRIVACY POLICY
Last updated: 17 August 2026
This Privacy Policy explains what information the Attack Surface Management system ("ASM", "we", "the system") collects from registered users, why we collect it, and how it is protected. This project is operated as an academic prototype for authorized security testing and asset-visibility purposes only.
INFORMATION WE COLLECT
When you create an account or use the system, we store:
- Account details: first name, last name, username, email address, and a securely hashed password (we never store your plaintext password).
- Authentication data: temporary CAPTCHA answers and one-time email verification codes, held only for the few minutes needed to complete sign-in or sign-up, then discarded.
- Scan and target data: domains you mark as authorized for scanning, and the assets, ports, and vulnerabilities discovered against them.
- Audit logs: a record of security-relevant events on your account (login attempts, MFA verification, password changes) used to detect abuse and support incident investigation.
- Technical data: your IP address is used transiently to enforce rate limits on login/sign-up attempts and is not stored long-term as part of your profile.
HOW WE USE THIS INFORMATION
- To authenticate you and keep your account secure (password hashing, CAPTCHA, email-based multi-factor authentication).
- To operate the core function of the service: discovering and tracking assets and vulnerabilities on domains you have explicitly authorized.
- To detect suspicious activity, such as repeated failed logins, through audit logging and rate limiting.
- To send you one-time verification codes by email during sign-up and login.
We do not sell, rent, or share your personal data with third parties for marketing purposes. We do not use advertising or analytics trackers.
COOKIES
We use only strictly necessary cookies:
- A session cookie to keep you signed in.
- A CSRF protection mechanism to prevent forged form submissions.
These cookies are required for the system to function and are not used for tracking or advertising. A separate browser-local flag (not a cookie) remembers that you've dismissed the cookie notice.
DATA RETENTION
Account and scan data is retained for as long as your account is active. Audit log entries are retained to support security investigations. You may request deletion of your account and associated data by contacting a system administrator.
DATA SECURITY
Passwords are hashed with bcrypt and never stored or logged in plaintext. All authenticated pages are protected by role-based access control, CSRF protection, and rate limiting on authentication endpoints. Scans are only ever run against targets you have explicitly marked as authorized.
YOUR RIGHTS
You may access, correct, or request deletion of your personal data at any time by contacting a system administrator. If you believe your account has been compromised, contact an administrator immediately so it can be disabled.
CHANGES TO THIS POLICY
This policy may be updated as the system evolves. Material changes will be reflected by updating the "Last updated" date above.