Privacy & Data Protection Policy

SecureLens Privacy Policy

Last Updated: January 1, 2026 • SecureLens Platform Inc.

Zero AI Training

We never use your source code, scan results, or AST tokens to train public AI models.

Ephemeral Processing

Uploaded files and source code artifacts are audited in sandbox containers and wiped post-scan.

End-to-End Encryption

All stored telemetry, findings, and credentials are encrypted via AES-256 at rest and TLS 1.3 in transit.

1. Information We Collect

When you use SecureLens, we collect only the information strictly necessary to provide vulnerability assessment services:

  • Account Data: Name, work email address, organization name, job title, and password hashes (bcrypt/argon2).
  • Scan Telemetry: Target hostnames, URLs, repository URLs, discovered vulnerability metadata (CWE, CVSS, remediation advisories), and execution logs.
  • Integration Credentials: User-supplied API keys (Google Gemini, OpenAI, Groq, OpenRouter) and webhook URLs (Slack, Jira, Discord), stored in isolated local client storage or securely encrypted environment variables.

2. How We Use and Protect Your Data

Your vulnerability reports and source code findings are strictly private to your authenticated workspace. SecureLens does NOT sell, rent, monetize, or share your proprietary scan results or vulnerability intelligence with any third party, marketing broker, or public repository.

3. Data Retention & Erasure

You retain full control over your telemetry. You may delete individual findings, purge past scan runs, or completely delete your workspace at any time directly from the SecureLens Dashboard or REST API. Upon workspace deletion, all associated findings, logs, and report snapshots are permanently purged from active databases.

4. Contact Data Protection Officer

For GDPR/CCPA data export requests, deletion verification, or privacy questions:

Email: privacy@securelens.io • Data Protection Officer, SecureLens Platform Inc.