Privacy Policy
Your privacy matters. This policy explains how MadStack collects, uses, protects, and manages information when you use our platform and services.
1 Overview
At MadStack Inc. ("MadStack", "we", "our", or "us"), we are deeply committed to protecting your privacy and ensuring the security of the data entrusted to our offensive application security platform. This Privacy Policy details our policies and practices regarding the collection, use, processing, and disclosure of personal data when you interact with our websites, software-as-a-service (SaaS) products, scanner agents, and associated security engineering tools (collectively, the "Services").
As an enterprise-grade cybersecurity vendor, we process information in two distinct roles: as a Data Controller for account data, billing details, and marketing interactions, and as a Data Processor when running automated vulnerability scans, code audits, and telemetry operations on behalf of our enterprise customers.
2 Information We Collect
We collect information in several ways depending on how you use our platform and the scope of our security engagement:
Account & Profile Information
Full names, corporate email addresses, job titles, password hashes, Single Sign-On (SSO) metadata, billing addresses, and payment authentication details.
Security Telemetry & Targets
Target domain URLs, IP ranges, API authorization tokens, repository metadata, vulnerability payload logs, and HTTP request/response inspection artifacts.
- Technical Log Data: IP addresses, browser types, operating system details, device identifiers, and system diagnostic logs.
- Integration Credentials: OAuth tokens for GitHub, GitLab, Jira, AWS, and Kubernetes clusters necessary to deliver automated code remediation features.
3 How We Use Information
MadStack utilizes the collected data strictly for specified operational, technical, and analytical purposes aimed at protecting customer infrastructure:
5 Data Security
As a cybersecurity platform, we hold ourselves to the highest global standards. Our defense-in-depth architecture encompasses:
AES-256
Encryption at Rest
TLS 1.3
Encryption in Transit
SOC 2 Type II
Certified Compliance
All target vulnerability findings are isolated using multi-tenant logical boundaries and encrypted with customer-managed key options (KMS) for Enterprise tier accounts.
6 Your Privacy Rights
Depending on your location (including GDPR in Europe and CCPA/CPRA in California), you hold statutory rights regarding your personal information:
8 Third-Party Services
Our platform integrates with specialized enterprise software partners to deliver seamless vulnerability management. These partners process data under strict Data Processing Agreements (DPAs):
- Cloud Compute: Amazon Web Services (US East/West, EU Frankfurt)
- Payment Gateway: Stripe Inc. (PCI-DSS Level 1 compliant)
- Security Intelligence: National Vulnerability Database (NVD) sync endpoints
9 Changes to This Policy
We may periodically update this Privacy Policy to reflect advancements in our security technology or changes in regulatory frameworks. Material modifications will be communicated via email alerts to account administrators and highlighted on our homepage prior to taking effect.
