Privacy Policy

Last updated: July 2026 (v2.12)Effective: June 2026

CyberOrbit AI Pty Ltd (ACN 700 012 157, ABN 75 700 012 157) ('CyberOrbit', 'we', 'us', 'our'), provides an AI-powered penetration testing and vulnerability assessment platform. This policy explains how we handle personal information when you use our website, platform, dashboard, APIs and related services. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) and, where they apply, the EU and UK GDPR, the California privacy laws, India's Digital Personal Data Protection Act 2023, and other applicable data protection laws.

1. Who we are and our roles

The entity responsible for your personal information is CyberOrbit AI Pty Ltd (ACN 700 012 157, ABN 75 700 012 157). To reach our Data Protection Officer or privacy team, use the privacy & data-rights form at the bottom of this page.

The role we play under data protection law depends on the data and the relationship:

  • For account and website data, we generally act as a controller.
  • For assessment data, any personal information contained in scan results and vulnerability evidence is processed by us as a processor on the customer's instructions. The customer (or, in an MSP arrangement, the MSP's end client) is the controller.

2. What information we collect

Information you provide:

  • Account information: name, work email, company name, job title, phone (optional), and authentication credentials
  • Billing information: billing contact and address. Card details are collected and processed directly by Stripe; we do not store full card numbers
  • Assessment configuration: target domains, URLs, IP ranges, scope definitions, authorisation documents, and any test credentials you choose to provide
  • Communications: support tickets, emails, and feedback

Information collected automatically:

  • Usage data: login times, dashboard interactions, feature usage, API calls, and report activity
  • Technical data: IP address, approximate location, browser and device type, operating system, log files, and diagnostic data

When we test systems you authorise, we collect security testing data, which may incidentally include personal information present in your systems (such as DNS and subdomain data, HTTP headers, TLS/SSL configuration, service and version information, application responses, and vulnerability evidence). We only collect assessment data from systems for which a signed Penetration Testing Authorisation is in place.

Information collected via our public tools (External Security Check). The External Security Check is a public, unauthenticated tool that lets you run a security-posture check against a domain you own or are authorised to assess. It is an active check, not a passive one. As well as reading what your domain returns publicly (HTTP security headers, TLS configuration, DNS records and publicly discoverable subdomains), it actively sends requests to the domain you nominate, including requesting a fixed, bounded list of common sensitive paths and locations (for example, environment and configuration files such as /.env, exposed version-control directories such as /.git, and open or listable directories) to detect files that should not be publicly exposed. The active file probe sends only GET requests to that fixed list, and runs only after you verify a work email at the scanned domain via a single-use magic link. This active probing is governed by our Acceptable Use Policy. When you use it, we collect:

  • The scanned domain: the apex domain you enter for us to assess, collected when you run the check
  • Your source IP address, collected when you run the check as part of our security and abuse-prevention record. We do not collect your email address at scan time — the passive posture scan runs on the domain and your attestation alone
  • Your acceptance of the Acceptable Use attestation, together with its timestamp and the IP address it was accepted from, collected when you run the check and retained as authorisation and abuse-prevention evidence
  • Your work email and company name, collected at the report-unlock gate when you ask us to release your full report — not when you run the check. Your email domain must match the scanned apex domain, and free or personal mailbox providers are rejected. This own-domain match, together with the attestation you accepted at scan time, is our authorisation model (mirroring Acceptable Use Policy section 2): it gives us reasonable assurance that you control, and are entitled to request a check of, the domain in question. Your work email also anchors the single-use magic-link verification that gates the active file probe and the release of the remaining findings
  • The resulting security-posture snapshot: the gauge scores and findings we generate about your own domain (for example, HTTP header, TLS, DNS and publicly discoverable subdomain configuration), including any software and version fingerprints we detect from your domain's responses, which we cross-reference against public vulnerability and end-of-life data (CVE / EOL matching). A short summary (four gauges plus the top five findings) is returned immediately; the remainder is released after you verify your email address via a single-use magic link
  • Exposed-file probe results: where the active file probe runs (after email verification), the specific sensitive paths we requested and short excerpts of what your domain returned at each, so we can evidence the finding. Because these excerpts are fetched from your domain, they can momentarily contain secrets present in an exposed file; our recon-redaction control masks recognised secrets before they appear in your report, but this is a safety net, not a guarantee. To generate the report, this content is processed momentarily on our United States hosting (Railway) before being returned to your browser (see international data transfers below); we do not retain these excerpts at rest, and only the probe outcome and a finding count are recorded in our audit and security logs. Because an exposed configuration file can contain secrets, treat your report as sensitive

We use this information to deliver the check and report you requested, to keep authorisation and abuse-prevention evidence, and (on the basis set out below) for B2B marketing follow-up and, where consented, analytics and attribution. Retention periods are set out under 'Data retention'.

Point-of-collection notice. At each point of collection — the scan page (scanned domain, source IP and attestation) and the report-unlock gate (work email and company name) — we give you a concise collection notice: who we are, what we collect, why we collect it, that we may follow up with B2B marketing where you provide a work email, and how to opt out or exercise your privacy rights — consistent with Australian Privacy Principle 5. Consistent with our cookie notice and consent gate, EU/UK visitors are asked to provide their details and to consent explicitly before we capture their information or run any analytics or attribution; analytics and attribution do not fire before that consent.

Information collected via our public tools (Agent / MCP Security Check). The Agent / MCP Security Check is a public tool that lets you upload a software dependency manifest or lockfile (for example package.json, package-lock.json, yarn.lock) or an AI agent / MCP client configuration, and returns a standards-based (CycloneDX) inventory of the components and, where an agent configuration is supplied, the declared tools, scopes and connectors it is configured to reach, risk-ranked against public vulnerability data. When you use it, we collect:

  • the file you upload and its contents, which we process only to generate and deliver the inventory you requested
  • the generated output (the CycloneDX inventory and its risk flags)
  • your work email and company name, collected through the gate to deliver the output and, on the basis set out below, for B2B marketing follow-up (free or personal mailboxes are rejected)
  • your source IP and your authorisation attestation (that you are entitled to submit the file), with a timestamp, kept as authorisation and abuse-prevention evidence

We treat your uploaded file and the generated output as security-sensitive and at the same tier as assessment evidence, because a lockfile or agent configuration can contain secrets (registry credentials, API keys, tokens, connection strings, internal hostnames) and the output maps what an attacker would target. Before we store your upload or send any part of it to a service provider, we automatically detect and strip secrets we recognise. We never write raw upload contents to our logs. You should still remove any live secrets before uploading; automated redaction is a safety net, not a guarantee. We use your upload only to generate and deliver the output. We do not use it for training and we do not repurpose it. Retention periods are set out under 'Data retention'. This tool performs an automated inventory only; it does not run an injection test, does not prove a component or path is exploitable, and its output is not a signed or certified assessment report.

Point-of-collection notice (APP 5). At the point you use the tool we tell you what we collect, why, our identity as controller, and how to exercise your rights. For visitors in the EU, EEA and UK we obtain consent before setting non-essential analytics or attribution, consistent with the ePrivacy Directive and the UK PECR.

3. How we use your information

We use personal information to:

  • Provide, operate and secure the Services and deliver assessment reports
  • Authenticate users and prevent unauthorised access, fraud and abuse
  • Process payments and manage billing
  • Provide support and communicate about the Services
  • Improve the Services, including our detection logic (using de-identified or aggregated data wherever practicable)
  • Comply with legal obligations

We do not sell personal information, and we do not use identifiable customer vulnerability data for marketing.

4. Legal bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, the legal basis we rely on depends on the purpose of the processing, as set out below. You may withdraw consent at any time where we rely on consent.

PurposeLegal basis (GDPR / UK GDPR Art. 6)
Providing, operating and delivering the Services, including assessment reports, to our customers and their personnelContractual necessity (Art. 6(1)(b)) — and, for personnel of a corporate customer, legitimate interests (Art. 6(1)(f)) in performing the contract with their employer
Authenticating users and preventing unauthorised access, fraud and abuseLegitimate interests (Art. 6(1)(f)) — securing the Services and our customers' accounts; legal obligation (Art. 6(1)(c)) where security record-keeping is required
Processing payments and managing billingContractual necessity (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records
Providing support and communicating about the ServicesContractual necessity (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in responding to enquiries
Improving the Services and our detection logic (using de-identified or aggregated data wherever practicable)Legitimate interests (Art. 6(1)(f)) in developing and improving our products
Retaining consent and authorisation-to-test evidence after account closure or an erasure requestLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) in establishing, exercising or defending legal claims
Sending marketing communicationsConsent (Art. 6(1)(a)), or legitimate interests (Art. 6(1)(f)) for existing-customer communications about similar services, subject to an opt-out
Setting non-essential (analytics) cookiesConsent (Art. 6(1)(a)), obtained via our cookie banner
Complying with legal obligations and responding to lawful requestsLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) in protecting our and others' rights
Running the External Security Check on your own domain — the passive posture scan (scanned domain, source IP and attestation captured at scan time) and the active exposed-file probe that runs after email verification — and capturing your work email and company name at the report-unlock gate to deliver the report you requestedContractual necessity / steps taken at your request (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in providing the tool
Retaining the Acceptable Use attestation and source IP as authorisation and abuse-prevention evidence for the External Security CheckLegitimate interests (Art. 6(1)(f)) in preventing misuse of the tool and establishing, exercising or defending legal claims; legal obligation (Art. 6(1)(c))
Sending B2B marketing follow-up to a corporate subscriber who used the External Security Check, with an opt-out honouredLegitimate interests (Art. 6(1)(f)) in corporate-subscriber marketing (free or personal mailboxes are rejected), subject to an opt-out
Analytics and attribution associated with the External Security Check (including PostHog identify, alias and session replay)Consent (Art. 6(1)(a)) and ePrivacy / PECR; obtained via our consent gate and cookie banner and not fired before consent
Generating and delivering the Agent / MCP Security Check output from a file you upload, and capturing your work email, company name and source IP to deliver itContractual necessity / steps taken at your request (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in providing the tool
Detecting and stripping secrets in an upload before storage or sub-processor transfer, and retaining the authorisation attestation and source IP as authorisation and abuse-prevention evidenceLegitimate interests (Art. 6(1)(f)) in securing the tool and preventing misuse, and establishing, exercising or defending legal claims; legal obligation (Art. 6(1)(c))
Sending B2B marketing follow-up to a corporate subscriber who used the tool, with an opt-out honouredLegitimate interests (Art. 6(1)(f)) in corporate-subscriber marketing (free or personal mailboxes are rejected), subject to an opt-out
Analytics and attribution associated with the Agent / MCP Security Check (including PostHog identify, alias and session replay)Consent (Art. 6(1)(a)) and ePrivacy / PECR; obtained via our consent gate and cookie banner and not fired before consent

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may ask us for more information about that balancing through the privacy & data-rights form at the bottom of this page. Personal data incidentally present in assessment data is processed by us as a processor on the customer's instructions and on the customer's legal basis.

5. Artificial intelligence and automated decision-making

We use artificial intelligence as part of the Services. AI models (provided by our AI sub-processors, Anthropic, OpenAI and Groq) analyse security testing data to help identify, classify, and describe potential vulnerabilities, and to help draft assessment findings. The AI assists our experts; it does not make final decisions on its own.

Human validation is in the loop. AI-generated findings are reviewed and validated by our OSCP-certified engineers before they form part of an assessment report. We do not make any decision based solely on automated processing that produces a legal effect concerning you, or that similarly significantly affects you, within the meaning of Article 22 of the GDPR and UK GDPR. The Services are a security-testing tool for our business customers; they are not used to evaluate, score, or make decisions about individual data subjects.

Where the GDPR or UK GDPR applies and any processing were to involve solely automated decision-making with legal or similarly significant effects, you would have the right not to be subject to that decision, to obtain human intervention, to express your point of view, and to contest the decision. Where the Australian Privacy Act and India's Digital Personal Data Protection Act apply, we provide transparency about our use of AI consistent with those laws, including the emerging requirements to explain automated decisions. You can ask us about our use of AI in the Services, or request human review of a finding that concerns you, through the privacy & data-rights form at the bottom of this page.

We do not use AI to make credit, employment, insurance, or similar decisions about individuals, and we do not use your data, or assessment data, to train publicly available AI models. Our AI sub-processors process data on our instructions to provide the Services and, under their API terms, do not use data submitted through their APIs to train their models.

6. How we share information (sub-processors)

We share personal information with the service providers and teams below. Each is bound by contractual data protection obligations and may process data only on our instructions.

  • Railway: infrastructure — hosting, application servers, database, and hosting and processing of Agent / MCP Security Check uploads and output (United States)
  • Anthropic: AI analysis and adaptive testing of findings (United States)
  • OpenAI: AI adversarial review of findings and vector embeddings (United States)
  • Groq: AI reconnaissance and vulnerability-scan analysis (United States)
  • OpenRouter: AI gateway enforcing zero-data-retention (ZDR) routing for LLM analysis; routes Claude to ZDR-covered backends (AWS Bedrock, Google Vertex) and serves the OpenAI/Llama tiers (United States)
  • AWS Bedrock: ZDR-covered serving of Claude models for gateway-routed (ZDR) LLM analysis (United States)
  • Google Vertex AI : ZDR-covered serving of Claude models for gateway-routed (ZDR) LLM analysis (United States)
  • E2B: sandbox execution of active scans and adaptive probing (United States)
  • Stripe: payment processing (United States)
  • Google Workspace : transactional and business email (United States)
  • PostHog: product analytics (EU, with US option)
  • SK Tech Services (India validation team) : human validation of AI-generated findings by OSCP-certified engineers (India)

Findings and vulnerability evidence, which may contain personal information, are disclosed to our OSCP-certified engineers in India who validate AI-generated results. This is a cross-border disclosure under APP 8 of the Australian Privacy Act and an international transfer under the GDPR/UK GDPR. We protect these transfers through a written services agreement imposing contractual data protection obligations, including, where applicable, GDPR Module 3 Standard Contractual Clauses (processor-to-processor), the UK International Data Transfer Addendum, APP 8 protections, and India DPDPA compliance.

Uploads to the Agent / MCP Security Check are processed on our United States hosting (Railway) and are a cross-border disclosure. The tool is automated and deterministic: it parses your file and, to flag known vulnerabilities, sends only the component coordinates it identifies (the package name and version, which are not personal information and are not part of your raw upload) to the public Open Source Vulnerabilities database (OSV.dev, operated in the United States). It does not send your upload to an AI sub-processor and does not route it to our India validation team. If we later add AI-assisted enrichment to this tool, we will disclose the additional recipient here first, and our secret-stripping runs before any such transfer.

We may also disclose personal information where required by law, to protect our or others' rights and safety, and in connection with a corporate transaction (in which case we will notify affected individuals).

7. International data transfers

Personal information may be processed in the United States, the European Union, and India, as set out above. Where we transfer personal information across borders, we put appropriate safeguards in place, which may include Standard Contractual Clauses (EU Module 2 for controller-to-processor flows and Module 3 for processor-to-processor flows), the UK International Data Transfer Addendum, and APP 8 contractual protections for Australian personal information. We do not currently claim certification under the EU-US Data Privacy Framework.

8. Cookies and analytics

We use essential, functional, and analytics cookies. Our analytics are provided by PostHog. For EU/EEA/UK visitors, non-essential cookies are set only with consent. We do not use advertising cookies or cross-site tracking. Full details are in our Cookie Policy. You can disable cookies in your browser settings, though this may affect some functionality.

9. Data storage and security

We implement technical and organisational security measures appropriate to the risk, including encryption in transit and at rest, access controls and least-privilege, multi-factor authentication for administrative access, audit logging of sensitive actions, multi-tenant logical data segregation, secure software development practices, and an incident response process. Infrastructure is hosted on Railway, with data processed in Australia, the United States, the European Union, or India depending on the service provider. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Data breach notification

If we become aware of a data breach involving personal information, we will assess it and respond in line with the laws that apply.

  • Under the Australian Notifiable Data Breaches scheme, where we are the responsible entity, we will assess whether a breach is an 'eligible data breach' and complete that assessment within 30 days of becoming aware of the grounds to suspect one. If notification is required, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
  • Where we process data on a customer's behalf as a processor, we will notify the relevant customer (controller) without undue delay after becoming aware of a personal data breach, so the customer can meet its own notification obligations (including the GDPR's 72-hour controller deadline).

Report suspected security issues via our security disclosure form.

11. Data retention

We retain personal information only as long as necessary for the purposes described in this policy or as required by law:

  • Account data: while the account is active; deleted within 90 days of account closure unless law requires longer
  • Assessment data (scan results, evidence): up to 90 days after assessment completion, unless you request earlier deletion or a longer retention is agreed
  • Assessment reports: available in your account for up to 2 years, or as agreed
  • Audit and security logs: up to 2 years. These records (which may include user IDs, IP addresses and user-agent data) provide the security audit trail we are required to maintain.
  • External Security Check lead data (work email, company name, source IP, attestation timestamp and IP): 12 months from last activity, rolled forward on re-use
  • External Security Check run data (full findings, including detected software and version fingerprints and CVE / EOL matches, plus gauge scores, source IP and scanned domain): 90 days from creation. The single-use magic-link token is TTL-bound (24 hours) and cleared on use.
  • External Security Check exposed-file probe excerpts (the sensitive paths requested and short sanitised response excerpts): not retained at rest. They are generated at the email-verification step, returned to you in your report, then discarded; only the probe outcome and a finding count are recorded in the audit and security logs (up to 2 years).
  • Agent / MCP Security Check uploaded file (raw manifest / config): deleted on delivery of the output, and in any event within 7 days of upload
  • Agent / MCP Security Check generated output (CycloneDX inventory and risk flags): up to 30 days, then purged; you keep any copy you download
  • Agent / MCP Security Check lead data (work email, company name, source IP, attestation): 12 months from last activity, rolled forward on re-use
  • Consent and authorisation-to-test records: retained for the life of the relationship plus up to 7 years where required by law, as legal-claims and criminal-law authorisation evidence, even after account closure or an erasure request
  • Billing and financial records: 7 years (tax and accounting law)
  • Support communications: up to 3 years
  • De-identified / aggregated data: may be retained indefinitely and cannot be re-identified to you

You can request early deletion using the privacy & data-rights form below.

When you ask us to delete your information, we delete or de-identify it, except records we must keep by law — in particular consent and authorisation-to-test evidence and financial records — which we retain for the minimum period required to establish, exercise or defend legal claims (GDPR / UK GDPR Art. 17(3)(b) and (e); Australian Privacy Principle 11.2). We tell you when this exception applies to your request.

12. MSP and channel arrangements

CyberOrbit is increasingly delivered through Managed Service Providers (MSPs) who resell the platform, sometimes white-labelled, to their own end clients. In a typical MSP arrangement, the end client is the controller of personal information within its own systems and assessment data; the MSP is typically a controller (or joint controller) in its relationship with its end client, with CyberOrbit acting as a processor (or sub-processor) downstream; and our sub-processors sit further down the chain. Where you are an end client of an MSP, the MSP is your first point of contact for privacy requests and is responsible for providing you with notice of the sub-processor chain (including our India validation team).

13. Your rights

Subject to the law that applies to you, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete or erase your information
  • Object to or restrict certain processing
  • Withdraw consent
  • Receive your data in a portable format
  • Complain to a regulator

To exercise any of these rights, use the privacy & data-rights form at the bottom of this page. We may need to verify your identity. We will respond within the timeframe required by the applicable law (generally 30 days; 45 days for CCPA requests).

In Australia, if you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. EU/UK individuals may lodge a complaint with their local supervisory authority or the UK ICO. California residents may request to know, delete, and correct personal information and are entitled to non-discrimination for exercising these rights; we do not sell or 'share' personal information for cross-context behavioural advertising.

14. Children's privacy

The Services are intended for business use by individuals aged 18 and over. We do not knowingly collect personal information from children. If you believe we have, contact our privacy team using the form below and we will delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised 'Last updated' date and, for material changes, notify registered users by email or in-app notice.

16. Contact us

For any privacy-related questions or requests, including matters for our Data Protection Officer, use the privacy & data-rights form at the bottom of this page. By post: we do not publish a street address; contact us via the form at https://cyberorbit.ai/contact.

CyberOrbit AI · Australia