Privacy policy and personal data protection
This Privacy Policy explains how Crinos Cybersecurity collects, uses, stores, and protects your personal data when you use the IronBOT automated penetration testing platform ("platform", "we"). It applies to registered users, organization members, and website visitors.
What data we collect
Registration and profile data: name, email, phone number, preferred language, password (stored in a non-recoverable/encrypted form), and, where applicable, two-factor authentication secret and recovery codes.
Organization data: organization name and slug, user role (owner, member, viewer), and links between users and organizations.
Target and pentest data: hostname, repository URL, chosen verification method, submitted authorization documents (including their content, which may contain personal data of third-party signatories), test scope, scan results, vulnerability findings, and generated reports.
Payment data: processed directly by our payment processor (Stripe) — IronBOT does not store full credit card numbers, only customer/subscription identifiers provided by Stripe.
Technical data: IP address, browser and device type, access logs, and platform usage metadata, collected for security, fraud prevention, and technical diagnostics.
Support data: content of support tickets, exchanged messages, and submitted attachments (PDFs, images).
How we use your data
Service delivery: creating and managing your account, running requested pentests, generating reports, processing payments, sending operational notifications (transactional emails), and providing technical support.
Security and fraud prevention: verifying legitimate authorization over tested targets, detecting misuse of the platform, and protecting our systems and those of third parties.
Service improvement: understanding how the platform is used to fix issues and develop new features.
Legal compliance: retaining records when required by law or to respond to requests from competent authorities, including in cases of suspected misuse of a pentest against a target without legitimate authorization.
Sharing with third parties
We share personal data only with service providers strictly necessary for operating the platform, always under contractual confidentiality and security obligations:
- Payment processor (Stripe) — billing and subscription identification data;
- S3-compatible object storage provider — authorization documents, reports, and support attachments;
- Email (SMTP) provider — sending transactional notifications;
- Artificial intelligence provider (LLM) — pentest technical data, for generating analyses and reports;
- Cloud infrastructure provider — isolated execution of test agents.
We do not sell or license your personal data to third parties for their own marketing purposes. We may disclose personal data to third parties when required by law, in response to legal process, court order, or a request from a competent authority, including investigations related to misuse of the platform for unauthorized tests.
Data retention
We retain your personal data for as long as necessary to fulfill the purposes described in this policy or to comply with applicable legal and contractual obligations, including the retention period for target authorization evidence needed for accountability purposes in case of a dispute over the legitimacy of a pentest.
Information security
We adopt technical and administrative security measures appropriate to the risk involved, including encryption of passwords and sensitive secrets, network isolation when executing pentest agents, and role-based access control. No system is absolutely secure; in the event of a relevant security incident, we will notify affected users and the competent authorities as required by applicable law.
Children's data
IronBOT is not intended for minors and does not knowingly collect personal data from children. If we identify such data, it will be removed from our records.
Cookies
Only cookies strictly necessary for the platform to function (e.g., language preference, authentication session) are mandatory and inherent to use.
Our advertising tracking, usage-preference, and analytics cookies are optional on the website and do not exist on the platform. Our analytics cookies may share data with access and search analysis tools (e.g., Google Analytics, Google Search Console) and social networks (e.g., Facebook, Instagram).
We do not use third-party advertising tracking cookies on the platform.
Your rights
You have the right to confirm the existence of processing, access, correct, request portability, or request deletion of your personal data, as well as to withdraw previously given consent, subject to mandatory retention required by law or necessary for the defense of rights in disputes over the legitimacy of a pentest. Requests may require identity verification before being fulfilled.
Changes to this policy
We may update this Privacy Policy periodically. Material changes will be communicated by email or notice on the platform before taking effect.
How to contact us
Questions, requests, or complaints related to the processing of personal data can be sent to Crinos Cybersecurity's Data Protection Officer:
Data Protection Officer: Angelo Tiéres Gomes Calde
- By email at contato@ironbot.io;
- By regular mail to Rua Santa Luzia, 651, 25th floor, Centro, Rio de Janeiro / RJ, Brazil.