Vulnix
Legal

Privacy Policy

Last updated September 14, 2026

1. Who we are

Vulnix ("Vulnix," "we," "us") provides an agentic penetration-testing platform at vulnix.dev. This policy explains what personal information we collect when you use the website, the dashboard and our APIs, how we use it, who we share it with, and the choices you have. For the data you ask us to test (your targets, repositories and findings), we act on your instructions as described in our Terms and Conditions.

2. Information we collect

Account information.Your name, email address and password (stored only as a salted hash), the organizations you belong to and your role in each, and optional details you add such as your organization's name, website, industry, team size, logo and your profile photo.

Information from Google. If you choose Sign in with Google, Google shares your name, email address, whether Google has verified that email, a unique Google account identifier and your profile picture. We request only these basic profile scopes (openid, email, profile) - never access to your Gmail, Drive, contacts or any other Google data.

Data you submit for testing. The domains, applications, APIs and repositories you scope; documents you upload such as API specifications; test-user credentials you provide for authenticated testing; and the results the platform generates - findings, exploit evidence, agent traces and reports. Repository access comes only through the GitHub App you install, and domain testing starts only after you prove you own the domain.

Connected services. If you connect a DNS provider (Cloudflare or Vercel) to verify domains, we store the access token that connection issues, encrypted.

Billing information. Payments are handled by Stripe; your card details go directly to Stripe and never reach our servers. We keep your plan, subscription status, invoices and credit usage.

Usage and technical data. Server logs record request details such as IP address, browser type and timestamps, which we use for security and rate limiting. If you accept analytics cookies, we also record how the product is used (pages visited, features used) against an anonymous identifier - never your name or email - and session recording is switched off.

3. How we use your information

  • To create and secure your account, sign you in, and keep your organization's data separate from every other organization.
  • To run the pentests, PR reviews and fix validations you request, and to show you the results.
  • To send account emails (verification, password reset) and the notifications you enable, such as run completion.
  • To bill you and manage your plan and credits.
  • To prevent abuse, fraud and unauthorized testing, and to investigate security incidents.
  • With your consent, to understand how the product is used so we can improve it.
  • To respond to support requests and to meet legal obligations.

4. Google user data

We use the information Google shares with us only to create your Vulnix account, sign you in, show your name and profile picture in the dashboard, and link your Google sign-in to an existing Vulnix account that uses the same verified email. We copy your profile picture into our own storage so it keeps showing without calling Google again; you can replace it at any time in Settings.

We do not sell Google user data, use it for advertising, share it with third parties except the hosting providers that run Vulnix, or use it to train AI or machine-learning models.

Vulnix's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. AI processing during tests

The testing engine is an AI agent. While it works on a target you scoped, the content it needs to reason about - responses from your application, code from repositories you connected, and its own intermediate notes - is sent to our AI model provider to decide the next testing step. Your account details and billing information are not part of that. We do not use your Customer Data to train AI models; as the Terms describe, we may use de-identified, aggregated usage data to improve the platform.

6. How we share information

We do not sell your personal information. We share it only with the service providers that help us run Vulnix, under contracts that limit their use to providing that service:

ProviderPurposeLocation
Amazon Web ServicesApplication hosting, databases, file and evidence storageEU (Frankfurt)
VercelWebsite and dashboard hostingGlobal edge, EU (Frankfurt) functions
CloudflareDNS and bot protection on sign-up (Turnstile)Global
AI model providerAI model used by the testing engine during pentests and PR reviewsOutside the EU
Temporal TechnologiesOrchestration of pentest and review workflowsUnited States
StripePayments, subscriptions and invoicingUnited States
ResendAccount and notification emailsUnited States
PostHogProduct analytics, only with your consentUnited States
GitHubRepository access through the GitHub App you installUnited States
GoogleSign in with GoogleUnited States

Within your organization, members can see your name, email and role, and the organization's targets and findings according to their permissions. We may also disclose information when required by law, to protect the rights and safety of Vulnix or others, or as part of a merger or acquisition, in which case this policy continues to apply.

7. Cookies and similar technologies

We use a small number of cookies. The ones needed to sign you in are always on; analytics cookies are set only after you accept them in the cookie banner. To change your choice later, clear this site's cookies and storage in your browser and choose again.

NamePurposeDuration
vulnix_sessionKeeps you signed in to the dashboard24 hours
vulnix_staff_sessionKeeps Vulnix staff signed in to the staff portal24 hours
vulnix_google_oauthProtects a Sign in with Google attempt against forgery10 minutes
cookie-consent, cookie-preferencesRemember your cookie choice (browser local storage)Until you clear it
PostHog (ph_*)Product analytics - set only after you acceptUp to 1 year

8. How long we keep information

  • Account and organization data is kept for as long as your account exists.
  • When an owner deletes an organization in Settings, its targets, runs, findings, members and integrations are removed. Exploit evidence files are stored write-once for integrity and may remain for up to 365 days after they were created before they are deleted.
  • Billing records are kept for as long as tax and accounting law requires.
  • Server logs are kept for a limited period for security and troubleshooting.

9. How we protect information

Data is encrypted in transit (TLS) and at rest. Credentials you give us for testing are stored in a dedicated secrets vault and encrypted, and each organization's data is isolated at the database level. Staff access requires multi-factor authentication. No system is perfectly secure, but we work to protect your information and will notify you of a breach that affects it as the law requires.

10. International transfers

Our main infrastructure runs in the European Union (Frankfurt, Germany). Some of the providers listed above process data in other countries, including the United States and other countries outside the EU. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for these transfers.

11. Your rights and choices

Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your profile, photo and organization details in Settings at any time, and an owner can delete an organization there. For anything else, email us and we will respond within 30 days.

If you signed in with Google, you can also remove Vulnix's access from your Google Account connections. You may also complain to your local data protection authority.

12. Children

Vulnix is a business product and is not directed to anyone under 18. We do not knowingly collect information from children.

13. Changes to this policy

We may update this policy as the product changes. We will change the date at the top of the page and, for material changes, notify you in the dashboard or by email before they take effect.

14. Contact

Questions or requests about your personal information can be sent to support@vulnix.dev.