AttackVector.tech
Back to Home

Privacy Policy

Last updated: February 2026

1. Information We Collect

Account Information

When you sign in via Google OAuth, we collect:

  • Email address
  • Display name
  • Profile avatar
  • Authentication tokens for secure access

Scan Data

When you use our scanning services, we collect:

  • URLs and domains you submit for scanning
  • Scan results, vulnerability findings, and generated reports
  • Scan configuration preferences and history

Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers, CVVs, or full card details on our servers. We receive confirmation of payment status and subscription details from Stripe.

Usage Data

We automatically collect:

  • IP address and browser type
  • Device information and operating system
  • Pages viewed and features used
  • Log data (access times, errors, referral URLs)

2. How We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the AttackVector platform
  • Process payments and manage subscriptions
  • Generate vulnerability reports and security assessments
  • Improve our scanning accuracy and AI models
  • Monitor for abuse, fraud, and unauthorized usage
  • Send important service notifications and updates
  • Comply with legal obligations

3. Third-Party Services

We integrate with the following third-party services:

  • Google OAuth: Authentication and single sign-on
  • Stripe: Payment processing and subscription management
  • OpenAI: AI-powered vulnerability analysis, report generation, and remediation guidance
  • NVD API (NIST): CVE data retrieval and vulnerability cross-referencing

These services have their own privacy policies and may collect data as described in their respective policies.

4. Data Sharing

We do not sell your personal data. We may share data in the following circumstances:

  • With service providers listed above, solely to operate the platform
  • When required by law, subpoena, or legal process
  • To protect our rights, safety, and prevent fraud
  • With your explicit consent

Scan target URLs may be sent to third-party APIs (OpenAI, NVD) for analysis. We do not share your scan results with other users or third parties.

5. Data Security

We implement industry-standard security measures including:

  • JWT-based authentication with encrypted tokens
  • HTTPS/TLS encryption for all data in transit
  • Secure storage with access controls and logging
  • Regular security reviews of our infrastructure

No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Your Rights (GDPR)

If you are in the EU/EEA, you have the following rights under the General Data Protection Regulation:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to certain types of data processing
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at privacy@attackvector.tech

7. Data Retention

  • Scan results: Cached for 24 hours for performance. Saved reports are retained while your account is active.
  • Account data: Retained for the duration of your active account.
  • Payment records: Retained as required by applicable tax and financial regulations.

When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

8. Cookies & Local Storage

AttackVector uses:

  • Session cookies: To maintain your authenticated session
  • localStorage: To store authentication tokens and user preferences client-side

We do not use tracking cookies or third-party advertising cookies.

9. Children's Privacy

AttackVector is intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18 years of age. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy questions or to exercise your data rights, contact us at: