Privacy Policy
Last updated: September 27, 2026
This policy explains how PentSeal (“PentSeal”, “we”, “us”) handles personal data when you visit pentseal.com, create an account, subscribe to a paid plan or use the security-testing workspace. It applies to the hosted service only. For the security controls behind it, see the Trust page.
1. Data we collect
- Account data. Name, work email address, role, organization name, authentication identifiers and session records. Passwords are stored only as salted hashes.
- Service data. Engagements, assets, targets, findings, evidence records, authorizations and audit logs that you or your team enter into the workspace. This is customer-supplied data and remains yours.
- Billing data. Plan, subscription status, billing contact and invoice/payment status. Card and bank details are collected and stored by our payment processor (Stripe) and never reach PentSeal servers.
- Technical and usage data. IP address, user agent, request metadata and platform logs generated by the hosting provider, used for security, abuse prevention and reliability.
- Communications. Messages you send to support, security or contact addresses, and the replies we send.
2. How we use it
- Provide, operate and secure the service, including authentication and access control.
- Process subscriptions, invoices and payments, and manage the free trial.
- Detect, investigate and prevent abuse, fraud and unauthorized testing.
- Respond to support and security reports and maintain service records.
- Meet legal, tax and accounting obligations.
- Improve reliability and performance of the platform.
Where the EU/UK GDPR applies, we rely on: performance of a contract (providing the service and processing your subscription), legitimate interests (securing the service, preventing abuse, improving reliability), consent (optional analytics and marketing cookies), and legal obligation (tax and accounting records). You can withdraw cookie consent at any time via Privacy preferences.
3. Cookies and analytics
We use strictly necessary cookies for authentication and session management (these cannot be switched off because the service will not work without them). Optional analytics and marketing cookies are used only if you enable them in Privacy preferences. Your choice is stored on your device and, when you are signed in, recorded against your account.
4. Subprocessors
We use a small set of providers to run the service. Each processes data only as needed to deliver its function:
- Vercel — application hosting, edge network and serverless runtime. Processes request metadata and ephemeral platform logs.
- Upstash — managed Redis, the primary data store for sessions, engagements, assets, findings, evidence records and audit logs. Sensitive fields carry an additional application-layer encryption before storage.
- Stripe — payment processing for paid plans. Holds billing contact and payment details; card details never reach PentSeal servers.
- GitHub — source control and CI/CD for our own codebase. No customer engagement data is intended to reach GitHub.
5. Retention
Account and service data is retained for as long as your account is active and for a reasonable period afterwards so you can recover records or meet audit needs. Billing and tax records are retained as required by law. Security and platform logs are kept for a limited operational window and then discarded. When retention ends, data is deleted or irreversibly anonymized.
6. How we protect it
Data is encrypted in transit, sensitive fields are encrypted at the application layer before storage, access to production systems is restricted and audit-logged, and administrative actions are gated behind break-glass controls. No system is perfect; the Trust page sets out the controls and their honest limits.
7. International transfers
We and our subprocessors may process data in countries other than your own. Where personal data is transferred across borders we rely on appropriate safeguards, such as the provider’s standard contractual clauses or an equivalent mechanism.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise a right, email privacy@pentseal.com. We will verify your identity and respond within the timeframe required by applicable law. There is currently no self-serve account deletion; deletion requests are handled manually through that address. If you are in the EU/UK you also have the right to complain to your local supervisory authority.
9. Children
PentSeal is a business tool and is not directed at children. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected by a new “Last updated” date on this page and, where appropriate, communicated to account holders before they take effect.
11. Contact
Privacy questions: privacy@pentseal.com. Security reports: security@pentseal.com. General enquiries: contact page.