GomuGuard Pentest · Legal

Privacy Policy

Effective September 27, 2026

This Privacy Policy explains how Xhorizyn ("Xhorizyn," "we," "us," or "our") collects, uses, discloses, and protects information in connection with GomuGuard Pentest (the "Service"). It applies to visitors of our marketing site and to registered users of the Service. It should be read together with our Terms of Service.

1Who This Policy Covers

Xhorizyn is the data controller for the information described in this Policy. If your organization uses the Service, your organization's Account Admin controls the workspace, and we act as a data processor with respect to Customer Data your organization submits to run Assessments and Engagements (Target details, findings, evidence). We act as a data controller with respect to account, billing, and usage information we collect to operate and secure the Service itself.

2Information We Collect

Account & profile information

Name, email address, phone number, organization name, and role, provided when you or your Account Admin create an account or add a Member.

Authentication data

Hashed passwords (never stored in plaintext), session and refresh tokens, and, if you sign in through your organization's identity provider, the identity claims your provider sends us (e.g. email, name). Login sessions record the browser/device (user-agent) and IP address used, so you can review and revoke your own active sessions.

Assessment, Engagement & Target data

The Targets, scope, credentials you choose to provide (for example through the credential-drop flow), conversation transcripts with the AI copilot, uploaded artifacts (such as API specifications or source snippets), and the findings, evidence, screenshots, and captured responses the Service generates while testing a Target you configured. This category can include sensitive technical data about the Target's environment, because that is the nature of a security assessment.

Billing information

Our payment processor handles your card details directly — we do not store full card numbers. We retain billing metadata such as plan, subscription status, and invoice history.

Technical & usage data

IP address, browser type, device information, pages viewed, and similar diagnostic and usage logs, collected automatically to operate, secure, and improve the Service.

Free scan submissions

If you use our free, one-time scan without creating an account, we collect the name, company, email address, phone number, and target (domain or IP) you submit, your approximate IP address (used only to enforce a per-visitor rate limit, never stored as a precise location), and the scan results themselves. We use this to run the scan, prevent abuse of the free offer (one scan per person), and, where you have agreed to be contacted, to follow up about the Service. We do not use free-scan submissions for unrelated marketing without your separate consent. This data is retained for a limited period and then deleted; it is not part of any paid-tenant workspace and no Account Admin controls it.

3Sensitive Data & Secret Redaction

The Service automatically scans messages sent to the AI copilot and looks for likely secrets or credentials (API keys, JWTs, bearer tokens, session cookies, and similar patterns). When one is detected, it is redacted before it is stored in your engagement transcript and before it is ever sent to an AI model — this check runs on our servers, not only in your browser, so it applies even if a client-side check is bypassed.

This reduces, but does not eliminate, the chance that sensitive material reaches our systems — please avoid pasting production secrets into the Service where you can provide them another way (for example, through a scoped, revocable test credential).

4How We Use Information

  • To provide the Service: run the Assessments, Engagements, and Simulations you configure, and generate findings and reports from the results.
  • To operate the AI copilot: our AI features run on infrastructure we operate ourselves, not on a third-party AI vendor's platform, and secrets are redacted before any model sees them (Section 3).
  • To manage your account and workspace: authentication, session management, member/role administration, and communications about your account.
  • To bill you: process subscription payments through our payment processor.
  • To secure the Service: detect and prevent fraud, abuse, and unauthorized access, including rate-limiting and login-lockout protections.
  • To improve the Service: understand aggregate usage patterns, in de-identified or aggregated form wherever practical.
  • To comply with legal obligations and enforce our Terms of Service.

6How We Share Information

We do not sell your personal information. We share information only:

  • with the subprocessors listed below, who process data on our behalf under contract — we do not route AI processing through a third-party AI vendor, since our AI features run on infrastructure we operate ourselves;
  • within your own workspace, where information such as your name and role is visible to other Members and your Account Admin as part of normal workspace administration;
  • if required by law, regulation, legal process, or a valid governmental request; or
  • in connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply to previously collected data.

Subprocessors

Stripe, Inc. — payment processing and billing (card details, subscription and invoice records). Cloudflare, Inc. — edge network and secure tunnel that carries traffic to our servers (connection metadata; Cloudflare does not have access to Customer Data stored in your workspace). We do not currently use a third-party AI model provider or a third-party email-delivery provider for the Service. If that changes, we will update this list and the Section 14 change-notice applies.

7Data Retention

We retain account and billing information for as long as your account is active, and for a limited period afterward as needed for legal, tax, or dispute-resolution purposes. Refresh tokens and login sessions expire on a rolling basis (currently within seven days of inactivity). You control the retention of your own Customer Data — Assessment configurations, Engagement transcripts, findings, and captured evidence — and can delete it at any time through the Service; residual copies may persist briefly in backups before they are purged on our normal backup rotation.

8How We Protect Information

We use industry-standard safeguards, including encrypted transport, hashed password storage, signed access tokens, per-account login-lockout protection against brute-force attempts, and access controls that scope every request to your own tenant. Our infrastructure is operated by us directly rather than outsourced wholesale to a third-party cloud platform, and we run regular backups with periodic restore testing. No system is completely secure, and we cannot guarantee absolute security.

9Your Rights

Depending on where you live, you may have the right to access, correct, delete, or export a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Many of these actions are available directly in the Service (for example, updating your profile, or reviewing and revoking your own active sessions in Settings). For anything else, contact us at [email protected]. If your data is held as Customer Data within an organization's workspace, we may direct your request to that organization's Account Admin, who controls that data.

10International Data Transfers

We may process and store information in a country other than the one where you are located. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers of personal data out of the EEA, UK, or Switzerland.

11Children's Privacy

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

12Cookies & Similar Technologies

We use strictly necessary cookies to keep you signed in and to remember basic preferences (such as light/dark theme). We do not use third-party advertising trackers on the Service.

13Data Breach Notification

If we become aware of a security incident that compromises your personal information in a way that requires notice under applicable law, we will notify affected customers without undue delay and take reasonable steps to investigate and remediate the incident.

14Changes to This Policy

We may update this Policy from time to time. If we make a material change, we will provide notice (for example, by email or an in-product notice) before the change takes effect.

15Contact Us

Questions about this Policy, or requests regarding your personal information, can be sent to [email protected].