NegevSecure
Home Features Pricing Contact
Login Get Started
Login Get Started
Privacy Document

Privacy Policy

Last updated: January 21, 2026 Effective: January 21, 2026

Summary: We collect information to provide our security testing services. We protect your data with industry-standard security measures, never sell your personal information, and give you control over your data. For EU users, see our GDPR Compliance page.

Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing
  5. Information Sharing & Disclosure
  6. Data Security
  7. Data Retention
  8. Your Rights & Choices
  9. International Data Transfers
  10. Cookies & Tracking
  11. Children's Privacy
  12. Third-Party Services
  13. Changes to This Policy
  14. Contact Us

1. Introduction

At Redcliff Technologies LLC ("NegevSecure," "we," "us," or "our"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our penetration testing platform, website at negevsecure.com, APIs, and related services (collectively, the "Services").

This Privacy Policy applies to all users of our Services, including:

  • Visitors to our website
  • Registered users and account holders
  • Enterprise customers and their authorized users
  • Recipients of our communications

By using our Services, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with our practices, please do not use our Services.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when you:

Account Registration

  • Name and email address
  • Password (stored securely hashed)
  • Company/organization name
  • Job title and department
  • Phone number (optional)

Billing Information

  • Billing name and address
  • Payment card information (processed by our payment processor)
  • VAT/Tax identification numbers

Service Usage

  • Project and scan configurations
  • Target URLs and domains you specify
  • Custom scan templates and policies
  • Support tickets and communications

2.2 Information Collected Automatically

When you use our Services, we automatically collect:

Device & Technical Information

  • IP address and geolocation (country/region level)
  • Browser type and version
  • Operating system and device type
  • Screen resolution and language preferences
  • Unique device identifiers

Usage Information

  • Pages visited and features used
  • Time spent on pages
  • Click patterns and navigation paths
  • Search queries within the platform
  • Error logs and performance data

2.3 Scan Data & Security Findings

When you use our security scanning services, we process:

  • Target system information (domains, IPs, URLs)
  • Vulnerability findings and security observations
  • HTTP request/response data from scans
  • Screenshots and evidence artifacts
  • HAR files and network traffic logs
  • Scan configuration and results

Important Note on Scan Data

Scan data may contain sensitive information about vulnerabilities in your systems. We treat all scan data as confidential and apply strict access controls. You are responsible for ensuring you have authorization to scan any targets.

2.4 Information from Third Parties

We may receive information about you from:

  • Single Sign-On Providers: When you authenticate via Google, Microsoft, or other SSO providers
  • Integration Partners: Data from connected services like Jira, Slack, or PagerDuty
  • Business Partners: Referral information from partners
  • Public Sources: Publicly available business information

3. How We Use Your Information

3.1 Providing & Improving Services

  • Operate and maintain the platform
  • Process and execute security scans
  • Generate reports and findings
  • Provide customer support
  • Develop new features and improvements
  • Personalize your experience

3.2 Communication

  • Send service-related notifications
  • Provide security alerts and updates
  • Respond to inquiries and support requests
  • Send marketing communications (with consent)
  • Notify you of policy or service changes

3.3 Security & Compliance

  • Protect against fraud and abuse
  • Monitor for security threats
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Respond to legal requests

3.4 Analytics & Research

  • Analyze usage patterns and trends
  • Measure service performance
  • Conduct aggregated research (anonymized)
  • Improve threat detection capabilities

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), UK, and Switzerland, we process personal data under the following legal bases:

Purpose Legal Basis
Providing our Services Contract performance
Processing payments Contract performance
Security and fraud prevention Legitimate interests
Service improvements Legitimate interests
Marketing communications Consent
Legal compliance Legal obligation

For more details on your rights under GDPR, please see our GDPR Compliance page.

5. Information Sharing & Disclosure

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5.1 Service Providers

We share information with trusted third-party service providers who assist us in operating our Services:

  • Cloud Infrastructure: AWS, Google Cloud Platform
  • Payment Processing: Stripe
  • Email Services: Brevo (Sendinblue)
  • Analytics: Mixpanel, Google Analytics
  • Customer Support: Intercom, Zendesk

All service providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

5.2 Business Transfers

In connection with a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred. We will notify you of any such change and any choices you may have.

5.3 Legal Requirements

We may disclose your information when required by law or to:

  • Comply with legal process or government requests
  • Enforce our Terms of Service
  • Protect our rights, privacy, safety, or property
  • Protect against fraud or security threats

5.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5.5 Aggregated Data

We may share aggregated, anonymized data that cannot identify you for research, analysis, or benchmarking purposes.

6. Data Security

We implement comprehensive technical and organizational measures to protect your information:

6.1 Technical Safeguards

  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Access Control: Role-based access control (RBAC) and least privilege principles
  • Authentication: Multi-factor authentication (MFA) for all accounts
  • Monitoring: 24/7 security monitoring and intrusion detection
  • Firewalls: Web application firewalls and network segmentation

6.2 Organizational Measures

  • Security Training: Regular employee security awareness training
  • Background Checks: Security screening for employees with data access
  • Incident Response: Documented incident response procedures
  • Audits: Regular security audits and penetration testing

6.3 Certifications & Compliance

  • SOC 2 Type II certified
  • ISO 27001 aligned practices
  • GDPR compliant
  • CCPA compliant

Security Incident Notification: In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of becoming aware of the breach.

7. Data Retention

We retain your information only as long as necessary for the purposes described in this Privacy Policy:

Data Type Retention Period
Account information Duration of account + 7 years (legal requirements)
Scan data & findings According to your subscription plan (30-365 days)
Billing records 7 years (tax and accounting requirements)
Support tickets 3 years after resolution
Marketing data Until consent is withdrawn
Server logs 90 days
Analytics data 26 months (anonymized after)

Upon account deletion or request, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes.

8. Your Rights & Choices

8.1 Access & Portability

You can access, download, or export your personal data at any time through your account settings or by contacting us.

8.2 Correction

You can update or correct your personal information through your account settings or by contacting support.

8.3 Deletion

You can request deletion of your personal data. Some data may be retained for legal or legitimate business purposes.

8.4 Marketing Opt-Out

You can opt out of marketing communications at any time by:

  • Clicking "unsubscribe" in any marketing email
  • Updating your preferences in account settings
  • Contacting us at [email protected]

8.5 Cookie Preferences

You can manage your cookie preferences through our cookie consent banner or your browser settings. See our Cookie Policy for more details.

8.6 Do Not Track

We currently do not respond to "Do Not Track" browser signals, but you can opt out of tracking through our cookie settings.

8.7 GDPR Rights (EEA/UK Users)

If you are in the EEA or UK, you have additional rights under GDPR. Please see our GDPR Compliance page for details.

8.8 California Privacy Rights (CCPA)

California residents have specific rights under the CCPA, including the right to know what personal information we collect and the right to request deletion. Contact us at [email protected] to exercise these rights.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our primary servers are located.

9.1 Safeguards

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms with our service providers
  • Adequacy Decisions: Transfers to countries recognized by the EU as providing adequate protection
  • Data Processing Agreements: Binding agreements with all data processors

9.2 EU-US Data Transfers

For transfers from the EU to the US, we rely on Standard Contractual Clauses and implement supplementary measures as required.

10. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience. For detailed information, please see our Cookie Policy.

10.1 Types of Cookies

  • Essential Cookies: Required for the platform to function
  • Performance Cookies: Help us understand how you use our Services
  • Functional Cookies: Remember your preferences
  • Marketing Cookies: Used for advertising (with consent)

10.2 Managing Cookies

You can manage cookies through:

  • Our cookie consent banner
  • Your browser settings
  • Third-party opt-out tools

11. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly.

If you believe we have inadvertently collected information from a child, please contact us immediately at [email protected].

12. Third-Party Services

Our Services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies before providing any personal information.

12.1 Integrations

When you connect third-party services to your account (e.g., Jira, Slack, GitHub), those services may access certain data. You can manage and revoke these connections in your account settings.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Post the updated policy on our website with a new "Last Updated" date
  • Send an email notification to registered users
  • Display a notice within the Services

Your continued use of our Services after changes take effect constitutes acceptance of the updated Privacy Policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Inquiries
[email protected]
Data Protection Officer
[email protected]
Redcliff Technologies LLC
1209 Mountain Road PL NE STE R
Albuquerque, NM 87110
United States
+1 (866) 218-2196
EU Representative
NegevSecure EU Representative
[email protected]

We aim to respond to all privacy-related inquiries within 30 days.

Your privacy matters to us. We are committed to protecting your personal information and being transparent about our data practices.

Terms of Service GDPR Compliance Cookie Policy Contact Us
NegevSecure

Enterprise-grade penetration testing platform powered by AI and cloud-based active testing technology. Protect your applications before vulnerabilities become breaches.

SOC 2 GDPR

Product

  • Features
  • Pricing
  • API Documentation
  • Integrations
  • Changelog
  • Status

Company

  • About Us
  • Blog
  • Careers
  • Press Kit
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • GDPR Compliance
  • Data Processing Agreement
  • Cookie Policy
  • Refund Policy

Resources

  • Security Research
  • Knowledge Base
  • Community
  • Partner Program
  • Report a Vulnerability

Stay updated on security trends

Get the latest security insights, vulnerability alerts, and product updates.

© 2026 Redcliff Technologies LLC. All rights reserved.

1209 Mountain Road PL NE STE R, Albuquerque, NM 87110 | +1 (866) 218-2196

Terms • Privacy • GDPR • Cookies