TheExploitCompany is an independent security research consultancy. We do not sell, rent, or monetize your search queries, email inquiries, or scanned infrastructure telemetry. Our business is securing systems, not harvesting data.
1. Ephemeral Query Processing (Tools)
When you use our free web tools (such as Header Checker, Threat IOC Scanner, or Data Breach Detector):
- Zero Plaintext Credential Storage: We never capture, log, or store passwords, API secrets, or private decryption keys.
- Ephemeral Execution: Queries run transiently in server-side memory to query public DNS or security feeds, and responses are delivered back to your browser with anti-caching HTTP headers.
- No Tracking Cookies for Queries: Interactive tool usage is not linked to cross-site tracking profiles.
2. Information We Collect
We collect only the minimum information necessary to maintain platform uptime, prevent abuse, and respond to commercial audit inquiries:
- Commercial Inquiries: When you submit a scoping request through our Enquiry form, we record your name, work email, organization name, and project scope to respond to your audit request.
- Anti-Abuse Server Telemetry: We temporarily process request IP addresses in an ephemeral sliding-window memory store solely to enforce rate limits and block malicious scraping bots. These temporary counters automatically expire.
3. Security and Technical Safeguards
We implement defense-in-depth technical safeguards to protect all data in transit and at rest:
- Mandatory TLS 1.3 encrypted transport for all visitor interactions.
- Strict Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS).
- Restricted server-side environments with zero external storage of sensitive API credentials.
4. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you have the right to access, rectify, or request deletion of personal information submitted through our commercial inquiry forms. You may exercise these rights at any time by contacting our privacy officer via our contact channels.