Legal & Compliance

Privacy Policy

Your privacy matters. This policy explains how MadStack collects, uses, protects, and manages information when you use our platform and services.

1 Overview

At MadStack Inc. ("MadStack", "we", "our", or "us"), we are deeply committed to protecting your privacy and ensuring the security of the data entrusted to our offensive application security platform. This Privacy Policy details our policies and practices regarding the collection, use, processing, and disclosure of personal data when you interact with our websites, software-as-a-service (SaaS) products, scanner agents, and associated security engineering tools (collectively, the "Services").

As an enterprise-grade cybersecurity vendor, we process information in two distinct roles: as a Data Controller for account data, billing details, and marketing interactions, and as a Data Processor when running automated vulnerability scans, code audits, and telemetry operations on behalf of our enterprise customers.

2 Information We Collect

We collect information in several ways depending on how you use our platform and the scope of our security engagement:

Account & Profile Information

Full names, corporate email addresses, job titles, password hashes, Single Sign-On (SSO) metadata, billing addresses, and payment authentication details.

Security Telemetry & Targets

Target domain URLs, IP ranges, API authorization tokens, repository metadata, vulnerability payload logs, and HTTP request/response inspection artifacts.

  • Technical Log Data: IP addresses, browser types, operating system details, device identifiers, and system diagnostic logs.
  • Integration Credentials: OAuth tokens for GitHub, GitLab, Jira, AWS, and Kubernetes clusters necessary to deliver automated code remediation features.

3 How We Use Information

MadStack utilizes the collected data strictly for specified operational, technical, and analytical purposes aimed at protecting customer infrastructure:

Vulnerability Assessment & Fixes: To execute authorized penetration tests, static/dynamic application scans, and generate contextual auto-remediation PRs.
Platform Maintenance & Optimization: To monitor infrastructure health, debug software issues, and enhance heuristic AI scanning precision.
Compliance & Abuse Prevention: To verify target ownership before performing intrusive security tests and prevent unauthorized platform usage.

4 Data Sharing and Disclosure

Strict No-Sale Commitment: MadStack does not sell, rent, or trade customer data or vulnerability telemetry to third parties or advertising networks under any circumstances.

We share data only with trusted entities under strict contractual safeguards:

  • Sub-processors: Vetted cloud infrastructure providers (AWS, GCP), authentication gateways (Okta), and customer success systems.
  • Legal & Regulatory Demands: When required by subpoena, court order, or binding law enforcement request, provided we notify you unless legally restricted.
  • Corporate Transfers: In connection with a merger, acquisition, or sale of company assets, subject to standard non-disclosure agreements.

5 Data Security

As a cybersecurity platform, we hold ourselves to the highest global standards. Our defense-in-depth architecture encompasses:

AES-256

Encryption at Rest

TLS 1.3

Encryption in Transit

SOC 2 Type II

Certified Compliance

All target vulnerability findings are isolated using multi-tenant logical boundaries and encrypted with customer-managed key options (KMS) for Enterprise tier accounts.

6 Your Privacy Rights

Depending on your location (including GDPR in Europe and CCPA/CPRA in California), you hold statutory rights regarding your personal information:

Right to Access: Request copies of your processed personal data.
Right to Erasure: Request the deletion ("Right to be forgotten") of your records.
Right to Rectification: Correct inaccurate or incomplete personal information we hold.
Right to Portability: Receive your data in a structured, machine-readable format.

7 Cookies and Tracking Technologies

We use cookies and similar technologies to operate the site, remember preferences, and understand usage:

Cookie Preference Center

Strictly Necessary Cookies

Required for session login, security tokens, and API authentication.

Always Active

Analytics & Performance

Helps us aggregate traffic metrics and feature usage trends.

8 Third-Party Services

Our platform integrates with specialized enterprise software partners to deliver seamless vulnerability management. These partners process data under strict Data Processing Agreements (DPAs):

  • Cloud Compute: Amazon Web Services (US East/West, EU Frankfurt)
  • Payment Gateway: Stripe Inc. (PCI-DSS Level 1 compliant)
  • Security Intelligence: National Vulnerability Database (NVD) sync endpoints

9 Changes to This Policy

We may periodically update this Privacy Policy to reflect advancements in our security technology or changes in regulatory frameworks. Material modifications will be communicated via email alerts to account administrators and highlighted on our homepage prior to taking effect.