Privacy Policy
This policy explains what we collect when you visit axeploit.com or use Axeploit to scan your own websites, why we collect it, and the choices you have.
01Overview
Axeploit ("Axeploit," "we," "us") is a commercial scanning product. Customers use it to test websites and APIs they own or operate. This Privacy Policy covers our marketing site, accounts, scans, reports, and support.
If you use Axeploit under an organization's workspace, that organization is typically the controller of Scan Data, and we process it to provide the Service. For website visitors and individual account holders, Axeploit is the controller of the personal information described below.
02Information we collect
We collect information in three ways: you give it to us, we generate it when you use the Service, and we receive a limited amount from infrastructure and analytics providers.
You provide
- Account details such as name, work email, company, and password or SSO identifiers.
- Billing details processed by our payment provider (we do not store full card numbers on our servers).
- Scan configuration: target domains, URLs, APIs, credentials you choose to supply for authenticated scans, and notification destinations such as Slack or webhooks.
- Messages you send through contact forms, email, or support channels.
We generate or observe
- Usage data: logins, scan runs, feature use, plan limits, and diagnostic logs.
- Scan Data: crawl results, request and response metadata needed to test targets, vulnerability findings, and reports.
- Device and network data such as IP address, browser type, and approximate location derived from IP, used for security and operations.
03How we use information
We use personal information to:
- Create and authenticate accounts, and provide the scanning platform.
- Run scans you request, generate reports, and send alerts you configure.
- Process payments, prevent fraud, and enforce plan limits.
- Provide support, respond to inquiries, and communicate product or security notices.
- Improve detection quality using aggregated or de-identified patterns that do not identify you or your customers.
- Secure the Service, investigate abuse, and comply with law.
We do not sell your personal information, and we do not use Scan Data to train public models or to advertise to your users.
04Scan data
Scan Data can include URLs, API paths, headers, and findings that describe security weaknesses. That information is sensitive. We treat it as confidential customer data and process it only to operate the Service you requested.
- You decide which of your websites and APIs to scan, and which credentials to store for authenticated testing.
- Only submit targets you own, operate, or have permission to test. You are responsible for that authorization.
- Reports and integrations (email, Slack, webhooks, PDF exports) will contain findings. Restrict who can receive them.
- If a finding includes a secret (for example an exposed key), treat the report as highly confidential and rotate the secret.
07Retention
We keep account and billing records for as long as the account is active and for a period afterward as required for tax, dispute, and security purposes. Scan Data and reports are retained for the life of the workspace unless you delete them or your plan specifies a shorter window.
After deletion or account closure, residual copies may remain in backups for a limited time until those backups cycle. We may retain information that we must keep to investigate abuse or comply with law.
08Security
We use administrative, technical, and physical safeguards appropriate to a security product, including encryption in transit, access controls, and monitoring. No method of storage or transmission is perfectly secure. You also have a role: use strong authentication, limit who can see reports, and rotate any credentials you store for authenticated scans.
09Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of sales or sharing. We do not sell personal information.
To exercise a right, email support@axeploit.com. We may need to verify your identity. If you are a member of an organization's workspace, some requests (especially about Scan Data) should go through that organization's admin.
You may also lodge a complaint with your local data protection authority. We would rather hear from you first so we can try to fix the issue.
10International transfers
Axeploit is based in India. We may also process information in other countries where we or our vendors operate, including the United States. Those countries may have different data protection laws than your own. Where required, we use appropriate safeguards for cross-border transfers, such as standard contractual clauses.
Enterprise customers who need a data processing addendum can request one from sales@axeploit.com.
11Children
Axeploit is a business service. We do not knowingly collect personal information from children under 16, and the Service is not directed at them. If you believe a child has provided us information, contact us and we will delete it.
12Changes
We may update this policy as our practices or the law change. We will post the revised policy here and update the "Last updated" date. For material changes, we will provide additional notice, such as email or an in-product message, where required.
13Contact
Privacy questions and requests: support@axeploit.com. General inquiries: axeploit.com/contact.
Questions
Email support@axeploit.com or visit our contact page.
