Privacy Policy
Table of Contents
1. Introduction
PentestOps ("we," "our," or "us") is a product of Extranet Systems Pty Ltd, an Australian registered company (ABN 29 632 743 189) with global operations in Bahrain, Egypt, Sydney, and Wollongong. We are committed to protecting your privacy and handling your data with transparency and care.
This Privacy Policy explains how we collect, use, store, and protect information when you use our penetration testing platform and related services. By using PentestOps, you agree to the practices described in this policy.
Company Information
Extranet Systems Pty Ltd
Website: pentestops.com
Global Offices:
Bahrain (Middle East Operations) | Egypt (North Africa Hub) | Wollongong, Australia (Asia-Pacific Headquarters) | Sydney, Australia (Sales & Operations)
2. Data We Collect
We collect the following categories of information:
2.1 Account Information
- Registration Data: Name, email address, company name, job title
- Authentication Data: Encrypted passwords, MFA tokens (if enabled)
- Billing Information: Payment details (processed by secure third-party providers)
2.2 Technical Data
- IP Addresses: Your IP address when accessing the platform
- Browser Information: Browser type, version, and user agent
- Device Information: Operating system, device type
- Session Data: Login times, session duration, pages accessed
2.3 Scan Configuration Data
- Target Information: Domains, IP addresses, and URLs you specify for scanning
- Scan Parameters: Scan types, intensity settings, scheduling preferences
- Authorisation Records: Consent forms, Rules of Engagement agreements
3. Scan Data & Results
When you perform security scans, we collect and store the following:
| Data Type | Description | Storage Location |
|---|---|---|
| Scan Results | Vulnerability findings, severity ratings, CVE references | Encrypted database |
| Port Scan Data | Open ports, service banners, protocol information | Encrypted database |
| SSL/TLS Analysis | Certificate details, cipher suites, security grades | Encrypted database |
| Web Application Data | HTTP responses, headers, detected technologies | Encrypted database |
| Generated Reports | PDF/HTML reports with findings and remediation | Encrypted file storage |
Important Notice
Scan results may contain sensitive information about your infrastructure vulnerabilities. We strongly recommend limiting access to scan results and reports to authorised personnel only.
4. System Logs
We maintain the following logs for security, compliance, and troubleshooting purposes:
| Log Type | Retention Period | Purpose |
|---|---|---|
| Access Logs | 90 days | Security monitoring, compliance |
| Audit Logs | 365 days | Audit trail, compliance |
| System Logs | 30 days | Troubleshooting, performance |
| Security Logs | 2 years | Incident investigation, forensics |
5. Data Retention Policy
We retain your data only for as long as necessary to provide our services and comply with legal obligations. Below are our standard retention periods:
| Data Category | Retention Period | Notes |
|---|---|---|
| Account Data | Duration of account + 30 days | Deleted 30 days after account closure |
| Assessment Findings | Starter 1 year; Professional 3 years; Enterprise and MSP 7 years | Automatically deleted after your plan's window; findings on legal hold are preserved |
| Generated Reports | Retained for the life of your account | Kept even after the underlying findings are deleted, so your report history survives |
| Authorisation Records | 7 years | Required for legal compliance |
| Billing Records | 7 years | Australian tax law requirement |
| Audit Logs | 365 days | Compliance and security |
| Contact / Enquiry Data | 90 days | Submissions via our contact form, then deleted |
Tiered Retention and Legal Hold
Assessment findings are retained for your plan's window (Starter 1 year, Professional 3 years, Enterprise and MSP 7 years) and then automatically deleted. Your exported reports, signed authorisation records and legal documents are kept and are never removed by this process. Findings tied to an active legal matter can be placed on legal hold so they are preserved beyond the standard window.
6. Data Deletion Policy
You have the right to request deletion of your personal data. Here's how our deletion process works:
6.1 Self-Service Deletion
- Individual Scans: Delete specific scan results from your dashboard
- Reports: Delete generated reports at any time
- Targets: Remove saved targets and configurations
6.2 Account Deletion Request
- Submit a deletion request via email to privacy@pentestops.ai
- We will verify your identity within 2 business days
- Your data will be deleted within 30 days of verification
- You will receive confirmation once deletion is complete
Deletion is Permanent
Once data is deleted, it cannot be recovered. Please ensure you have exported any required reports or data before requesting deletion.
7. Data Security
We implement comprehensive security measures to protect your data:
7.1 Technical Safeguards
- Encryption at Rest: AES-256 encryption for all stored data
- Encryption in Transit: TLS 1.3 for all data transmission
- Access Controls: Role-based access control (RBAC)
- Multi-Factor Authentication: Available for all accounts
- Network Security: Firewalls, intrusion detection, DDoS protection
7.2 Compliance
- Australian Privacy Principles (APP)
- GDPR compliance for EU customers
- ISO/IEC 27001:2022 certified; built to SOC 2-aligned controls
Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified (independently audited by Atom Assurances); SOC 2 attestation is on our roadmap. For more detail on our security controls, hosting and data-residency arrangements, see our Security page.
8. Cookies & Local Storage
We keep our use of cookies and browser storage to the minimum needed to run the platform. We do not use third-party advertising or cross-site tracking cookies, and we do not sell or share your browsing activity with advertising networks.
- Session cookies: A secure, HTTP-only session cookie keeps you signed in while you use the platform. It is removed when you sign out or when the session expires.
- Theme preference: Your light/dark theme choice is stored in your browser's local storage so the interface matches your preference on return visits.
- Session state: Limited interface state (such as recently viewed views and dismissed notices) may be held in your browser to improve usability.
You can clear cookies and local storage at any time through your browser settings. Clearing them will sign you out and reset your saved preferences.
9. Data Sharing & Sub-processors
We do not sell your personal data. We may share data only in the following circumstances:
9.1 Service Providers & Sub-processors
We use trusted third-party providers (sub-processors) for specific services, such as payment processing and cloud hosting. These providers are contractually bound to protect your data and to process it only on our instructions. The current categories of sub-processors and the regions in which your data is hosted are described on our Security page.
9.2 Legal Requirements
We may disclose data if required by law, court order, or government request, or to protect our legal rights.
9.3 With Your Consent
We may share data with third parties if you explicitly consent to such sharing.
10. International Data Transfers
Extranet Systems Pty Ltd is an Australian company, and customer data for Asia-Pacific customers is primarily hosted in Australia. Our teams in Bahrain and Egypt may access personal data to operate, support and secure the platform, which can involve transferring or accessing data outside the country where it was collected.
Where personal data is transferred across borders, including access from our Egypt and Bahrain offices, we put appropriate safeguards in place. For transfers of data originating in the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) as the cross-border transfer mechanism. Details of where data is hosted and processed are set out on our Security page.
11. Data Processing Addendum
Where we process personal data on your behalf as a processor, our Data Processing Addendum (DPA) applies and forms part of your agreement with us. The DPA sets out the security measures, sub-processor commitments, breach notification obligations and cross-border transfer safeguards (including the Standard Contractual Clauses) that govern how we handle your data.
Customers who require a signed copy of the DPA can request one by contacting privacy@pentestops.ai.
12. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (see Section 6)
- Portability: Request your data in a portable format
- Restriction: Request restriction of processing
- Objection: Object to certain types of processing
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@pentestops.ai. We will respond within 30 days.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Extranet Systems Pty Ltd - Privacy Team
Email: privacy@pentestops.ai
Website: pentestops.com
Response Time: Within 5 business days
For complaints about our handling of your personal information, you may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.