WebDefect
PRIVACY & DATA GOVERNANCE

Privacy Policy

Last updated: August 2026

1. Information We Collect

To deliver external attack surface visibility and maintain deterministic scan history, we process:

  • Submitted target domain names, IP addresses, and URLs
  • Public perimeter telemetry, TLS certificates, DNS records, and response headers
  • User profile identifiers (Google OAuth name and verified email) upon sign-in
  • Anonymous cryptographic session tokens for non-authenticated quota controls

2. How We Utilize Telemetry Data

Scan telemetry is used strictly to compile security audit reports, calculate posture ratings, compute historic posture drift, and prevent service abuse. We never sell customer audit logs or target asset inventories to third-party data brokers or marketing entities.

3. Data Retention & Erasure

Registered users retain the ability to delete historic scan runs from their account console at any time. Account deletion requests submitted to privacy@webdefect.com are permanently purged from persistent storage within 30 days.

Questions or GDPR / CCPA data subject requests?

privacy@webdefect.com