Umbermark
pricing dashboard sign in

Privacy Policy

Draft. Plain-language starting point, not yet reviewed by a lawyer. Bracketed items must be filled in before launch.

What we collect

  • Email address — only if you sign in; used for the magic-link login and account-related mail. No passwords.
  • Scan reports — the findings and score for a scan. Public share links at /r/<id> are scrubbed: the target host/IP is redacted and sensitive evidence is masked.
  • Abuse-prevention hashes — your IP address and the target you scan are stored only as salted (peppered) SHA-256 hashes for rate limiting, never in the clear and not reversible back to the original.
  • Usage events — anonymous funnel events (e.g. page view, scan started) to understand how the product is used.

SSH keys are never persisted

For the managed (“we connect”) option, the read-only SSH key you paste is passed to the scan worker in memory, spilled to a private owner-only temporary file only for the moment the connection is established, and deleted immediately afterwards. The key is never written to our database, logs, or backups.

Retention

Anonymous and outside-in scan reports expire automatically (24 hours by default) unless you attach them to an account or make one permanent. Account data persists until you ask us to delete it. [[ REVIEW: confirm exact retention windows and a deletion-request path once support email exists. ]]

Sub-processors

We share the minimum necessary with:

  • Postmark — sends login and notification email.
  • Polar.sh — billing and payment (merchant of record).
  • Cloudflare Turnstile — bot/abuse protection on scan submissions.
  • Backblaze B2 — encrypted off-site database backups.

We do not sell personal data.

Contact

[[ REVIEW: data-controller entity and a privacy contact address, pending outbound-email setup. ]]

Last updated: [[ REVIEW: set on publish ]].

Umbermark — Linux server hardening scanner.
pricing terms privacy sign in