CHELYS SECURITY

Privacy Policy

Chelys Security, Inc. · Last updated: May 4, 2026 · Version 1.0

Summary

We collect only what we need to operate the platform. We do not sell your data. We do not share your vulnerability findings with other customers. We disclose all third-party services that receive any portion of your data below.

1. Who We Are

Chelys Security, Inc. ("Chelys", "we", "us") operates the Chelys Security platform — an autonomous penetration testing SaaS service. This Privacy Policy explains how we collect, use, store, and protect information when you use our Service.

For GDPR purposes, Chelys Security, Inc. is the data controller for your account data. For scan data collected about your customers' systems, you are the data controller and Chelys acts as a data processor on your behalf.

2. Data We Collect

Data Purpose Retention
Email address, password hashAccount authenticationUntil account deletion
Organization name, billing infoAccount management, invoicing7 years (tax law)
IP address, browser user agentAudit log, abuse prevention2 years
Scan targets (IPs, domains)Job execution90 days after job deletion
Vulnerability findings + evidenceSecurity reportingUser-controlled; max 1 year by default
Extracted credentials (NTLM hashes, cracked passwords)Attack path documentation in report30 days after job completion
Cloud / AD credentials (user-supplied)Credentialed scan accessDeleted immediately on job deletion
Audit log eventsSOC 2 compliance, abuse investigation2 years minimum
Agent event logs (tool I/O)Debugging, evidence reconstruction90 days; configurable
PDF reportsCustomer deliverableUser-controlled; accessible until deletion

We do not collect marketing analytics, behavioral tracking, or usage telemetry beyond what is necessary to operate the platform and detect abuse.

3. Third-Party Services That Receive Your Data

The following external services receive portions of your data. We have evaluated each and confirmed they meet our security standards.

Anthropic (Claude API)

Scan evidence, raw tool output, and vulnerability data are sent to Anthropic's Claude API for analysis, report generation, and agent reasoning. This is a core part of how the Service works. Anthropic does not use API customer data to train models under its enterprise agreement. Data is transmitted over TLS.

Note: Raw vulnerability evidence from your target systems is included in prompts sent to the Claude API. Do not use the Service to test systems containing data subject to export controls or data residency requirements without reviewing Anthropic's data processing terms.

Stripe, Inc.

Payment processing. We pass your email and billing details to Stripe to process subscriptions. We do not store your credit card number. Stripe is PCI-DSS Level 1 certified.

NIST NVD & EPSS API

CVE IDs discovered during scans are sent to the NIST National Vulnerability Database and FIRST.org EPSS API to retrieve CVSS scores and exploitation probability scores. Only the CVE identifier is transmitted — no target data or finding details.

Google LLC (Google Forms)

Our demo request form is hosted by Google Forms. When you submit a demo request, the information you provide (name, email, company, and any other fields in the form) is collected and stored by Google LLC. This data is subject to Google's Privacy Policy. We use this data solely to respond to your demo request.

Vercel, Inc.

This marketing site is hosted on Vercel and uses Vercel Analytics and Vercel Speed Insights. These tools collect aggregate, non-identifiable data: page paths, approximate country, browser type, operating system, device category, and referrer. No cookies are set, no persistent identifiers are stored, and no personally identifiable information is collected. Data is processed by Vercel, Inc. — see Vercel's Privacy Policy.

We do not share your data with advertisers, data brokers, or any other third parties not listed above. We do not sell your data.

4. How We Use Your Data

  • Providing, operating, and improving the Service
  • Authenticating your account and enforcing access controls
  • Processing payments and managing subscriptions
  • Generating security reports and vulnerability findings
  • Detecting and preventing abuse, unauthorized use, and security incidents
  • Complying with legal obligations (e.g., responding to lawful law enforcement requests)
  • Sending transactional emails (account confirmation, password reset, invoice receipts)

We do not use your vulnerability findings or target data for any purpose other than providing the Service to you.

5. Data Security

We implement the following technical controls to protect your data:

  • All data in transit encrypted with TLS 1.3
  • Data at rest encrypted using AES-256
  • Field-level encryption for sensitive credentials (NTLM hashes, cloud API keys, AD passwords) using AES-256-GCM
  • Multi-tenant isolation enforced at the database query level — no org can access another org's data
  • TOTP multi-factor authentication available for all accounts
  • All user actions logged in a tamper-evident audit log with IP and timestamp
  • Role-based access control (Admin / Member / Viewer) limits data exposure

Despite these measures, no system is completely secure. If you believe your account has been compromised, contact us immediately at help@chelys.io.

6. Data Retention and Deletion

You may request deletion of your account and all associated data at any time by contacting help@chelys.io. We will delete your data within 30 days of a verified deletion request, except for:

  • Audit log records required for legal compliance (retained 2 years)
  • Billing records required by tax law (retained 7 years)
  • Data subject to a lawful hold or pending law enforcement request

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate data.
  • Deletion (Right to Erasure) — Request deletion of your data as described above.
  • Portability — Request your data in a machine-readable format.
  • Restriction — Request that we limit processing of your data.
  • Objection — Object to processing based on legitimate interests.

To exercise these rights, email help@chelys.io. We will respond within 30 days. EU/UK users may also lodge a complaint with their local data protection authority.

8. Cookies and Tracking

The Service uses only functional cookies required for authentication (JWT session tokens stored in localStorage). We do not use advertising cookies, third-party tracking pixels, or behavioral analytics.

This marketing site uses Vercel Analytics and Vercel Speed Insights to measure site performance and understand how visitors navigate the site. These tools are privacy-first by design: no cookies are set, no persistent user identifiers are stored, and no cross-site tracking occurs. The data collected is aggregate only — page paths, approximate country, browser type, OS, device category, and referrer.

9. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it promptly.

10. International Data Transfers

Chelys Security, Inc. is based in Utah, United States. Your data is processed and stored in the United States. If you are accessing the Service from the EU, UK, or other regions with data transfer restrictions, your data will be transferred to the US. We rely on Standard Contractual Clauses (SCCs) as the legal basis for such transfers where required.

Enterprise customers requiring a Data Processing Agreement (DPA) for GDPR compliance may request one at help@chelys.io.

11. Changes to This Policy

We may update this Privacy Policy. We will notify you by email or in-app notice at least 14 days before material changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

12. Contact Us

For privacy questions, data requests, or to report a concern:

Chelys Security, Inc.
help@chelys.io
Utah, United States

Terms of Service · ← Back to Home © 2026 Chelys Security, Inc. All rights reserved.