Back to Home

Privacy Policy

Last Updated: April 2026

At Sectora, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application security platform.

1. Information We Collect

We collect information you provide directly to us, including: • Account Information — when you create an account, we collect your email address and name. • Scan Data — when you run scans, we process and store information about your applications, including URLs, vulnerabilities found, and scan configurations. • Usage Data — we collect information about how you use our service, including features used, pages viewed, and actions taken. • Device Information — we collect information about the device and browser you use to access our service.


2. How We Use Your Information

We use the information we collect to: • Provide, maintain, and improve our services • Process and complete security scans • Send you technical notices, updates, and security alerts • Respond to your comments, questions, and support requests • Monitor and analyze trends, usage, and activities • Detect, investigate, and prevent fraudulent transactions and other illegal activities


3. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. Scan results are retained for 90 days by default, though you can configure longer retention periods. You can request deletion of your account and associated data at any time by contacting us at privacy@sectora.io.


4. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including: • Encryption of data in transit (TLS 1.3) and at rest (AES-256) • Regular security assessments and penetration testing • Access controls and authentication requirements • Monitoring and logging of access to sensitive data For more details, see our Security page.


5. MCP Server (mcp.sectora.io)

When you use the Sectora MCP endpoint at mcp.sectora.io/mcp, we log each request for abuse detection, rate-limit enforcement, and service reliability. What we log: • Request metadata — a unique request ID, the JSON-RPC method name, and (when applicable) the tool name called • Connection metadata — IP address, country (derived from IP), and User-Agent • Performance data — latency, HTTP status code, success/failure • API key prefix (first 12 characters) — only for authenticated requests; the full key is never logged • Timestamp What we do NOT log: • Tool arguments — we do not record the CVE IDs, keywords, or IP addresses you look up • Tool response content — we do not store what the tool returns to you • Full API keys • Any payload you send or receive through the MCP Retention: 30 days, after which logs are permanently deleted. Use of logs: abuse detection, rate-limit accounting, billing for authenticated tiers, and internal service improvement. Logs are not shared with third parties except when legally required. Free-tier users: anonymous usage is identified only by IP address and, if used, the first 12 characters of your API key. There is no correlation to your Sectora account unless you are signed in.


6. Data Sharing

We do not sell your personal information. We may share your information only in the following circumstances: • With your consent — we may share information when you give us explicit permission • Service Providers — we use third-party services to help operate our platform (hosting, email, analytics) • Legal Requirements — we may disclose information if required by law or to protect rights, safety, or property • Business Transfers — if we are involved in a merger or acquisition, your information may be transferred


7. Your Rights

Depending on your location, you may have certain rights regarding your personal information: • Access — request access to your personal information • Correction — request correction of inaccurate information • Deletion — request deletion of your personal information • Export — request a copy of your data in a portable format • Opt-out — opt out of marketing communications To exercise these rights, contact us at privacy@sectora.io.


8. Cookies and Tracking

We use cookies and similar technologies to: • Maintain your session and authentication state • Remember your preferences • Understand how you use our service • Improve our platform based on usage patterns You can control cookies through your browser settings.


9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this privacy policy.


10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date.


11. Sectora Browser Shield (Browser Extension)

The Sectora Browser Shield browser extension is a managed security agent. When installed (typically deployed by your organization's IT administrator), it protects the browser from extension-based risk, phishing, and data theft, and reports security signals to your organization's Sectora console. What the extension collects and sends to Sectora (https://sectora.io): • Device & enrollment data — browser, browser version, operating system, and an enrollment identifier that binds the device to your organization. • Installed-extension metadata — the id, name, install type, and requested permissions of extensions on the device, used to assess extension risk. • Security events — for a flagged page or a risky download: the finding type, the verdict, and the domain/host involved. What the extension does NOT collect or transmit: • Page content, the text you read, or anything you type • Form field values, passwords, or credentials • Your full browsing history of benign sites — only security-relevant events leave the device • Keystrokes Privacy by design: phishing and credential-theft detection runs locally inside the page; only boolean security verdicts and finding types leave the page — never the page's contents or your inputs. Use of this data: solely to provide the managed browser-security service to your organization (extension-risk assessment, threat blocking, and admin reporting). This data is not sold and is not used for advertising or any purpose unrelated to that security service. Retention & deletion: security events and device records are retained for the duration of the device's enrollment with your organization, and are deleted on un-enrollment or on request to privacy@sectora.io.


12. Contact Us

If you have questions about this privacy policy or our privacy practices, please contact us at: Email: privacy@sectora.io Address: Sectora Inc.