Last updated: 2026-08-21
When you create an account we collect your email, display name, and hashed password. When you use the platform we also process:
We use this data to run security analyses, produce remediation plans, and generate reports for you. We do not sell customer data. We do not use customer data to train public models.
We transmit limited, necessary data to the following services in the course of providing the product:
Audit logs are retained for 90 days by default. Scan uploads and derived findings are retained for the life of your account or until you delete them. Sessions expire within 30 days of last use.
You can request access, export, or deletion of your data by emailing info@crusadersec.com. EU residents have additional rights under GDPR (access, rectification, erasure, portability, objection). California residents have analogous rights under CCPA.
Customer credentials and MFA secrets are encrypted at rest with AES-256-GCM. All traffic is HTTPS with HSTS. We publish a security contact at /.well-known/security.txt.
We will post any material change here with a new "Last updated" date and, where legally required, notify account holders by email.
Contact: info@crusadersec.com