PentestOps
  • Home
  • Solutions
    Solutions
    Enterprise Pentesting Continuous Pentesting AI Pentesting Automated Pentesting Web App Pentesting API Pentesting External Network Testing Internal Network Testing
     
    Cloud Pentesting AWS Pentesting Azure Pentesting GCP Pentesting Kubernetes Security Active Directory Security M365 Security EASM Exposure Management Vulnerability Management Integrations MSP Security Platform
    Industries
    Healthcare Financial Services Government Education Manufacturing Retail and eCommerce All industries All solutions
  • Features
  • Agent
  • Pricing
  • Resources
    Knowledge Centre
    What Is Penetration Testing? Continuous Penetration Testing AI in Penetration Testing PTES Explained OWASP Top 10 NIST SP 800-115 All articles
    More
    Methodology Vendor Comparison Release Notes Open-Source Tools
  • Methodology
  • Comparison
  • About
  • Contact
Login Sign Up Free Demo
Legal Document

Privacy Policy

Last updated 1 June 2026 | Effective 1 June 2026

This version supersedes all prior versions of this Privacy Policy.

Table of Contents

  • 1. Introduction
  • 2. Data We Collect
  • 3. Scan Data & Results
  • 4. System Logs
  • 5. Data Retention Policy
  • 6. Data Deletion Policy
  • 7. Data Security
  • 8. Cookies & Local Storage
  • 9. Data Sharing & Sub-processors
  • 10. International Data Transfers
  • 11. Data Processing Addendum
  • 12. Your Rights
  • 13. Contact Us

1. Introduction

PentestOps ("we," "our," or "us") is a product of Extranet Systems Pty Ltd, an Australian registered company (ABN 29 632 743 189) with global operations in Bahrain, Egypt, Sydney, and Wollongong. We are committed to protecting your privacy and handling your data with transparency and care.

This Privacy Policy explains how we collect, use, store, and protect information when you use our penetration testing platform and related services. By using PentestOps, you agree to the practices described in this policy.

Company Information

Extranet Systems Pty Ltd
Website: pentestops.com
Global Offices:
Bahrain (Middle East Operations) | Egypt (North Africa Hub) | Wollongong, Australia (Asia-Pacific Headquarters) | Sydney, Australia (Sales & Operations)

2. Data We Collect

We collect the following categories of information:

2.1 Account Information

  • Registration Data: Name, email address, company name, job title
  • Authentication Data: Encrypted passwords, MFA tokens (if enabled)
  • Billing Information: Payment details (processed by secure third-party providers)

2.2 Technical Data

  • IP Addresses: Your IP address when accessing the platform
  • Browser Information: Browser type, version, and user agent
  • Device Information: Operating system, device type
  • Session Data: Login times, session duration, pages accessed

2.3 Scan Configuration Data

  • Target Information: Domains, IP addresses, and URLs you specify for scanning
  • Scan Parameters: Scan types, intensity settings, scheduling preferences
  • Authorisation Records: Consent forms, Rules of Engagement agreements

3. Scan Data & Results

When you perform security scans, we collect and store the following:

Data Type Description Storage Location
Scan Results Vulnerability findings, severity ratings, CVE references Encrypted database
Port Scan Data Open ports, service banners, protocol information Encrypted database
SSL/TLS Analysis Certificate details, cipher suites, security grades Encrypted database
Web Application Data HTTP responses, headers, detected technologies Encrypted database
Generated Reports PDF/HTML reports with findings and remediation Encrypted file storage

Important Notice

Scan results may contain sensitive information about your infrastructure vulnerabilities. We strongly recommend limiting access to scan results and reports to authorised personnel only.

4. System Logs

We maintain the following logs for security, compliance, and troubleshooting purposes:

Log Type Retention Period Purpose
Access Logs 90 days Security monitoring, compliance
Audit Logs 365 days Audit trail, compliance
System Logs 30 days Troubleshooting, performance
Security Logs 2 years Incident investigation, forensics

5. Data Retention Policy

We retain your data only for as long as necessary to provide our services and comply with legal obligations. Below are our standard retention periods:

Data Category Retention Period Notes
Account Data Duration of account + 30 days Deleted 30 days after account closure
Assessment Findings Starter 1 year; Professional 3 years; Enterprise and MSP 7 years Automatically deleted after your plan's window; findings on legal hold are preserved
Generated Reports Retained for the life of your account Kept even after the underlying findings are deleted, so your report history survives
Authorisation Records 7 years Required for legal compliance
Billing Records 7 years Australian tax law requirement
Audit Logs 365 days Compliance and security
Contact / Enquiry Data 90 days Submissions via our contact form, then deleted

Tiered Retention and Legal Hold

Assessment findings are retained for your plan's window (Starter 1 year, Professional 3 years, Enterprise and MSP 7 years) and then automatically deleted. Your exported reports, signed authorisation records and legal documents are kept and are never removed by this process. Findings tied to an active legal matter can be placed on legal hold so they are preserved beyond the standard window.

6. Data Deletion Policy

You have the right to request deletion of your personal data. Here's how our deletion process works:

6.1 Self-Service Deletion

  • Individual Scans: Delete specific scan results from your dashboard
  • Reports: Delete generated reports at any time
  • Targets: Remove saved targets and configurations

6.2 Account Deletion Request

  1. Submit a deletion request via email to privacy@pentestops.ai
  2. We will verify your identity within 2 business days
  3. Your data will be deleted within 30 days of verification
  4. You will receive confirmation once deletion is complete

Deletion is Permanent

Once data is deleted, it cannot be recovered. Please ensure you have exported any required reports or data before requesting deletion.

7. Data Security

We implement comprehensive security measures to protect your data:

7.1 Technical Safeguards

  • Encryption at Rest: AES-256 encryption for all stored data
  • Encryption in Transit: TLS 1.3 for all data transmission
  • Access Controls: Role-based access control (RBAC)
  • Multi-Factor Authentication: Available for all accounts
  • Network Security: Firewalls, intrusion detection, DDoS protection

7.2 Compliance

  • Australian Privacy Principles (APP)
  • GDPR compliance for EU customers
  • ISO/IEC 27001:2022 certified; built to SOC 2-aligned controls

Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified (independently audited by Atom Assurances); SOC 2 attestation is on our roadmap. For more detail on our security controls, hosting and data-residency arrangements, see our Security page.

8. Cookies & Local Storage

We keep our use of cookies and browser storage to the minimum needed to run the platform. We do not use third-party advertising or cross-site tracking cookies, and we do not sell or share your browsing activity with advertising networks.

  • Session cookies: A secure, HTTP-only session cookie keeps you signed in while you use the platform. It is removed when you sign out or when the session expires.
  • Theme preference: Your light/dark theme choice is stored in your browser's local storage so the interface matches your preference on return visits.
  • Session state: Limited interface state (such as recently viewed views and dismissed notices) may be held in your browser to improve usability.

You can clear cookies and local storage at any time through your browser settings. Clearing them will sign you out and reset your saved preferences.

9. Data Sharing & Sub-processors

We do not sell your personal data. We may share data only in the following circumstances:

9.1 Service Providers & Sub-processors

We use trusted third-party providers (sub-processors) for specific services, such as payment processing and cloud hosting. These providers are contractually bound to protect your data and to process it only on our instructions. The current categories of sub-processors and the regions in which your data is hosted are described on our Security page.

9.2 Legal Requirements

We may disclose data if required by law, court order, or government request, or to protect our legal rights.

9.3 With Your Consent

We may share data with third parties if you explicitly consent to such sharing.

10. International Data Transfers

Extranet Systems Pty Ltd is an Australian company, and customer data for Asia-Pacific customers is primarily hosted in Australia. Our teams in Bahrain and Egypt may access personal data to operate, support and secure the platform, which can involve transferring or accessing data outside the country where it was collected.

Where personal data is transferred across borders, including access from our Egypt and Bahrain offices, we put appropriate safeguards in place. For transfers of data originating in the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) as the cross-border transfer mechanism. Details of where data is hosted and processed are set out on our Security page.

11. Data Processing Addendum

Where we process personal data on your behalf as a processor, our Data Processing Addendum (DPA) applies and forms part of your agreement with us. The DPA sets out the security measures, sub-processor commitments, breach notification obligations and cross-border transfer safeguards (including the Standard Contractual Clauses) that govern how we handle your data.

Customers who require a signed copy of the DPA can request one by contacting privacy@pentestops.ai.

12. Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data (see Section 6)
  • Portability: Request your data in a portable format
  • Restriction: Request restriction of processing
  • Objection: Object to certain types of processing
  • Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at privacy@pentestops.ai. We will respond within 30 days.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Extranet Systems Pty Ltd - Privacy Team

Email: privacy@pentestops.ai

Website: pentestops.com

Response Time: Within 5 business days

For complaints about our handling of your personal information, you may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

PentestOps

Enterprise-grade penetration testing platform by Extranet Systems. Secure your digital assets with advanced security assessments and comprehensive vulnerability testing.

pentestops.com

+61 1300 290 196

info@pentestops.ai

Product

  • Features
  • On-Prem Agent
  • Pricing
  • Comparison
  • API

Solutions

  • Enterprise Pentesting
  • Continuous Pentesting
  • AI Pentesting
  • Automated Pentesting
  • Web App Pentesting
  • API Pentesting
  • All Solutions
  • By Industry

Resources

  • Knowledge Centre
  • Sample Report
  • Methodology
  • PentestOps vs Pentera
  • PentestOps vs Horizon3.ai NodeZero
  • PentestOps vs Cobalt
  • Release Notes
  • Open-Source Tools
  • Support

Company

  • About Us
  • Careers
  • Contact
  • Partners

Legal

  • Privacy Policy
  • Terms of Use
  • Trust Centre
  • DPA
  • Free Demo Scan
Penetration testing across: Australia Sydney Melbourne Brisbane Canberra New Zealand

© 2026 Extranet Systems Pty Ltd (ABN 29 632 743 189), Wollongong NSW, Australia. All rights reserved. | PentestOps is a security platform operated by Extranet Systems.