Privacy Policy

Last updated: 2026-08-21

1. What we collect

When you create an account we collect your email, display name, and hashed password. When you use the platform we also process:

  • Vulnerability scan files (Nessus / OpenVAS) you upload
  • Microsoft Graph identity and configuration data for tenants you connect
  • Cloud-provider inventory data for the subscriptions / accounts you connect
  • IP addresses and user-agent headers from incoming requests (for security + audit)
2. How we use it

We use this data to run security analyses, produce remediation plans, and generate reports for you. We do not sell customer data. We do not use customer data to train public models.

3. Sub-processors

We transmit limited, necessary data to the following services in the course of providing the product:

  • Microsoft Azure / Entra ID / Microsoft Graph — for the tenant data you explicitly connect.
  • Azure OpenAI — CVE identifiers + vulnerability titles are sent to generate remediation plans when no curated plan is available. No customer credentials or personal identifiers are sent.
  • Azure App Service / Azure Application Insights — for hosting and operational telemetry.
4. Retention

Audit logs are retained for 90 days by default. Scan uploads and derived findings are retained for the life of your account or until you delete them. Sessions expire within 30 days of last use.

5. Your rights

You can request access, export, or deletion of your data by emailing info@crusadersec.com. EU residents have additional rights under GDPR (access, rectification, erasure, portability, objection). California residents have analogous rights under CCPA.

6. Security

Customer credentials and MFA secrets are encrypted at rest with AES-256-GCM. All traffic is HTTPS with HSTS. We publish a security contact at /.well-known/security.txt.

7. Changes

We will post any material change here with a new "Last updated" date and, where legally required, notify account holders by email.

Contact: info@crusadersec.com