Trust & Compliance
Privacy Policy (Public Template, Version 1.0)
This Privacy Policy describes how IntegSec LLC (“IntegSec,” “we,” “us”) collects, uses, shares, and protects information in connection with the TurboPentest platform and related websites (the “Service”). This Policy is effective as of 2026-05-03.
For procurement teams: this Policy is published at /privacy and should be reviewable inline as part of vendor onboarding. For broader IntegSec consultancy services, see integsec.com/privacy-policy.
1. Overview
TurboPentest is an AI-powered penetration testing platform operated by IntegSec LLC, a Delaware limited liability company. We provide automated security testing, findings reports, and compliance attestation artifacts to organizations testing assets they own or are authorized to test.
At a high level, we collect information you give us (account, billing, target metadata, authentication data) and information generated by your use of the Service (logs, findings, AI agent reasoning traces, analytics events). We use that information to deliver the Service, support customers, improve the product in aggregate, and meet legal obligations. We do not sell personal data.
2. Information we collect
Account information
Name, work email, organization name, role/title, and similar professional contact information you provide when you register, invite teammates, or contact support.
Authentication data
Hashed credentials (we never store passwords in plaintext) and OAuth access/refresh tokens for third-party services you connect with explicit consent (e.g., GitHub for repository scanning). Tokens are scoped to the minimum permissions required to deliver the requested feature and are encrypted at rest.
Pentest target metadata
Fully qualified domain names (FQDNs), IP addresses, and URLs you submit as in-scope targets; GitHub repository metadata (org name, repo name, default branch, file tree, commit hashes) when you connect a repository for code-aware testing.
Pentest output
Findings, scan results, evidence captures (screenshots, request/response pairs, payload traces), AI agent reasoning logs, and generated reports and attestation letters. This content may include incidental personal data present on the in-scope target (e.g., test account names, exposed contact information surfaced by scans).
Operational data
IP address, user agent, browser and device characteristics, session tokens, request timestamps, error logs, and analytics events generated by your interactions with the Service. This data is used for security, reliability, abuse prevention, and aggregate product analytics.
Billing data
Payment processing is handled by Stripe, Inc. We do not store full payment card numbers; we receive billing metadata (last four digits, card brand, billing country, charge ID, invoice status) from Stripe to reconcile your subscription. See Stripe's privacy policy at stripe.com/privacy.
3. How we use information
- Delivering the Service: running pentests on targets you submit, storing reports and findings, generating attestation letters, orchestrating AI agents, and sending operational notifications.
- Customer support and operational communications: responding to support requests, security advisories, billing notices, and material changes to the Service.
- Service improvement: aggregated, non-identifying analytics on feature usage, performance, and reliability. We do not use Customer pentest content (findings, scan output, reports) to train generally available AI models.
- Legal compliance and security: meeting regulatory obligations, responding to lawful requests, enforcing our Terms of Use, detecting fraud and abuse, and protecting the rights, property, and safety of IntegSec, our customers, and the public.
4. Sharing
Sub-processors
We engage a small set of vetted sub-processors to deliver the Service (cloud infrastructure, transactional email, error monitoring, analytics, AI inference). The current list is published at /subprocessors, which is updated when our sub-processor list changes (with at least 14 days' advance notice for new sub-processors, per the DPA).
Anthropic Claude API (AI agent reasoning)
TurboPentest's AI agents run on Anthropic's Claude API. Per Anthropic's commercial terms, workforce and customer data submitted via the API is not used to train Anthropic's models. Data transmitted to Anthropic is limited to the prompts and tool inputs required to execute agent reasoning (target metadata, scan output excerpts, prior tool results) and is governed by Anthropic's privacy and data handling commitments.
Service providers
We share information with service providers acting on our behalf and bound by written data processing terms - including Stripe (billing), Mailgun (transactional email), Microsoft Azure (cloud hosting), Anthropic (AI inference), and analytics/monitoring tools. See /subprocessors for the current list.
Legal compliance
We may disclose information when required by law - including in response to court orders, valid subpoenas, lawful requests by public authorities (including for national security or law enforcement purposes), or when necessary to protect rights, property, or safety. Where legally permitted, we will notify the affected customer before disclosure.
Mergers and acquisitions
If IntegSec is involved in a merger, acquisition, financing, reorganization, or sale of assets, customer information may be transferred as part of that transaction. We will notify customers of any such change in ownership or control of personal data and ensure that any successor entity is bound by terms at least as protective as this Policy.
We do not sell personal data
We do not sell personal data and we do not share personal data for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA). See the California Notice at Collection in section 13 below.
5. International transfers
IntegSec LLC is a Delaware limited liability company and processing primarily occurs in the United States, with select sub-processors operating in other regions (see /subprocessors). Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country not deemed adequate, the transfer is governed by:
- The European Commission's Standard Contractual Clauses (SCCs), Module Two (Controller-to-Processor), as referenced in our DPA;
- The UK International Data Transfer Addendum (IDTA) for transfers from the UK; and
- The Swiss Federal Data Protection Act (FADP) amendments for transfers from Switzerland.
Customers wishing to execute the SCCs / UK IDTA on Controller's paper can request a counter-signed DPA at [email protected].
6. Data retention
- Active customers: we retain account data, pentest output, and operational logs for the duration of the active subscription relationship.
- Post-termination: we delete or return Customer Data within 90 days of termination of the Service, consistent with our published auditor-facing policy at /for/auditors and the DPA, except where retention is required by law.
- Backups: backup deletion follows our documented retention schedule; encrypted backups containing residual Customer Data age out of rotation in due course and are not restored to live systems.
- Aggregated/anonymized data: non-identifying metrics derived from your usage (counts, performance statistics, error rates) may be retained indefinitely to operate and improve the Service.
7. Your rights
Subject to applicable law, you have rights regarding personal data we hold about you. These commonly include:
- Access - request a copy of your personal data.
- Correction - ask us to correct inaccurate or incomplete data.
- Deletion - ask us to delete your personal data, subject to legal retention obligations.
- Portability - request a machine-readable copy of data you provided.
- Objection / restriction - object to or restrict certain Processing activities.
- Withdraw consent - where Processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior Processing.
EU/EEA residents (GDPR): you have the rights described in Articles 15–21 of the GDPR (access, rectification, erasure, restriction, portability, and objection), as well as the right to lodge a complaint with your supervisory authority.
UK residents (UK GDPR):equivalent rights apply under the UK GDPR; your supervisory authority is the Information Commissioner's Office (ICO).
California residents (CCPA/CPRA): you have the right to know what personal information we collect and how we use it; the right to request deletion or correction; the right to opt out of sale or sharing of personal information (we do not sell or share, but the right exists); the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising any of these rights. See section 13 for the California Notice at Collection.
Canadian residents (PIPEDA): you have rights of access, correction, and to challenge our compliance with PIPEDA. The Office of the Privacy Commissioner of Canada is the federal supervisory authority.
How to exercise your rights: contact [email protected] or [email protected]. We will acknowledge your request promptly and respond substantively within 30 days(extendable as permitted by law for complex or numerous requests). We may need to verify your identity before acting on certain requests. If you are submitting a request on behalf of a Customer's data subject (i.e., we act as a processor for that Customer), we will direct your request to the Customer.
8. Cookies and tracking
We use cookies and similar technologies for the following purposes:
- Strictly necessary: session cookies, CSRF tokens, and authentication cookies required for the Service to function. These cannot be disabled.
- Analytics: PostHog and Google Tag Manager (loaded via Partytown for performance) collect aggregated usage data. These are disabled when a user opts out via the cookie preferences UI or sends a Global Privacy Control (GPC) signal where applicable.
- Affiliate tracking: Rewardful sets a referral cookie when you arrive via an affiliate link, so we can credit the referring partner if you become a customer.
- Marketing tracking: HubSpot tracking is used on certain marketing pages to attribute inbound interest to campaigns. Marketing tracking is not present on the authenticated product surface.
A cookie preferences UI is available from the footer of the marketing site (the “Settings” / “Privacy choices” control); a granular consent banner is on the public roadmap. In the meantime, you can manage cookies through your browser settings. Honoring Global Privacy Control (GPC) signals is treated as a valid opt-out of sharing for cross-context behavioral advertising under the CCPA/CPRA.
9. Children's privacy
The Service is intended for B2B / enterprise use and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact [email protected] and we will take appropriate steps to delete it.
10. Security
We protect personal data using industry-standard technical and organizational measures, including:
- TLS 1.2+ encryption in transit, AES-256 (or equivalent) at rest.
- Role-based access control with least-privilege defaults and audit logging.
- Quarterly self-pentest of the TurboPentest platform performed by IntegSec's security team using the same methodology we deliver to customers.
- SOC 2 Type II program in progress; current controls are documented at the trust portal.
- Vendor security review and ongoing monitoring of sub-processors.
- Annual security training for personnel with access to Customer Data.
- Vulnerability management program with documented response timelines.
See /security and trust.integsec.com for the full security program and controls catalog. No system is perfectly secure; if you believe you have found a vulnerability in TurboPentest, please coordinate disclosure with us under our Safe Harbor at /security.
11. Changes to this Policy
We may update this Privacy Policy from time to time. For material changes that negatively affect your rights, we will notify customers by email (to the administrator of record) or by an in-app notice at least 14 days beforethey take effect. Non-material updates (typo fixes, additional examples, clarifying wording, sub-processor list refreshes) take effect when posted, with the “Last updated” date at the top of this page reflecting the change.
12. Contact
- DPO inquiries: [email protected]
- Privacy inquiries: [email protected]
- General legal: [email protected]
- Phone: +1 (207) 200-3288
- Postal: IntegSec LLC, 5305 Limestone Road, Suite 200, Wilmington, DE 19808
13. California Notice at Collection (CCPA/CPRA)
This section provides the disclosures required of businesses subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”).
Categories of personal information collected (last 12 months)
- Identifiers: name, email, IP address, account identifiers.
- Customer records: billing contact, employer and role.
- Internet activity: browsing and interaction data with the Service, log data.
- Geolocation: approximate location derived from IP address (city/region; we do not collect precise GPS).
- Professional information: employer, role/title, organizational context.
- Inferences: aggregate inferences drawn from the foregoing for product analytics.
Categories disclosed for business purposes
We disclose the categories above to the service providers identified in section 4 and at /subprocessors. Each is bound by written terms restricting use of personal information to providing services to us.
Sensitive personal information
We collect a limited category of sensitive personal information - account login credentials (in hashed form) - solely to authenticate users and provide the Service. We do not use sensitive personal information to infer characteristics about consumers.
Sale or sharing of personal information
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. California residents may exercise their “Do Not Sell or Share My Personal Information” right by contacting [email protected]; we will confirm in writing.
Retention periods
See section 6 for retention practices. We retain each category of personal information for the shortest period necessary to fulfill the purpose for which it was collected, or as required by law.
14. GDPR / EEA / UK Notice
This section provides the disclosures required by the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the UK GDPR.
Controller
For data we process in connection with delivering the Service to you (your account, billing, telemetry), IntegSec LLC is the Controller. For Customer Data you submit through the Service (pentest targets, scan output, content of reports), IntegSec acts as a Processor on your behalf, governed by our DPA.
Lawful bases for processing
- Contract (Art. 6(1)(b)): processing necessary to perform our agreement with you (delivering the Service, billing).
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, abuse detection, product analytics, and operating our business - balanced against your rights and interests.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing communications, and where consent is otherwise required.
- Legal obligation (Art. 6(1)(c)): compliance with applicable laws (tax, accounting, lawful requests).
Data subject rights (Articles 15–21)
EEA, UK, and Swiss residents have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). You also have the right not to be subject to a decision based solely on automated processing (Art. 22). To exercise any right, contact [email protected].
DPO and EU/UK representative
IntegSec's Data Protection Officer can be reached at [email protected]. We do not currently have an establishment in the EU or UK; customers requiring an Article 27 representative arrangement should contact [email protected].
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority - your local Data Protection Authority in the EEA, the UK Information Commissioner's Office (ICO), or the Swiss Federal Data Protection and Information Commissioner (FDPIC). We encourage you to contact us first so that we can try to resolve your concern directly.
Status: Public template - Version 1.0 - 2026-05-03.
Counsel review: this template is substantively complete for self-serve onboarding. For a counter-signed bespoke version, email [email protected].
Related trust documents
For IntegSec's broader privacy policy (covering the full IntegSec security consultancy), see integsec.com/privacy-policy.