Back to the start

Privacy

This page is short because there is little to say. The product holds a description of where your security controls act and where they do not — which is a genuinely sensitive thing to hold, and the reason the list below is as small as we could make it.

What is never asked for

No scanner credentials, no repository access, no API tokens, no keys, no passwords. The assessment has no field that accepts one, there is no integration that requests one, and the browser is not permitted to talk to any host but this one. Nothing is read from your systems, because nothing can be.

No account is needed

A whole assessment — six steps, the coverage map, the gap list, the report and both exports — runs without registering. An email address is asked for only if you want to keep the result, and only then. There is no password to choose.

If you do make one, the account holds your email address, the assessments you claimed, and a record of each sign-in session — including the IP address and browser user-agent that session was created from, which is what lets a stolen one be recognised. The workspace is named after your address, and a pending sign-in link holds it for the fifteen minutes the link is valid. If you invite someone to a workspace, their address and yours are held for as long as the invitation stands. All of it goes when the account goes.

What is held

What you typed into the six steps, and what is computed from it:

  • the application: its name, what kind of thing it is, whether it faces the internet, how critical it is, and whether you declared that it handles personal or financial data — the declaration, not the data
  • which technologies it is built on, chosen from a fixed list
  • which environments it is deployed to, including any you name yourself
  • which security tools you already own, chosen from a fixed list
  • how those tools run: what they block, what they only warn about, what is automated
  • the remaining capabilities, an optional note of your own against any of them, your remediation deadline, and whether you have an exception process

From those answers the product derives the requirements, the covered and uncovered scopes, three scores and a ranked list of recommendations. That derived result is stored alongside the answers so that a finished assessment stays the assessment you finished.

It is not asked who you are, where you work, or which real systems these answers describe. If you type a real application name, that is the only identifying thing in there, and it is there because you put it there.

How long it is kept

An assessment nobody has claimed is anonymous: it is tied to a cookie in your browser and to nothing else. It is deleted automatically 30 days after it is started, together with everything derived from it.

An assessment you have claimed with an account is kept until you delete it or delete the account. There is no other clock on it.

Deleting all of it

Without an account: the assessment page carries a delete button. It removes the workspace and everything under it — the application, your answers, the requirements, the implementations, the scopes — rather than only your way back to it.

With an account: deleting the account deletes every assessment it owns first, then the account. One dialog, one confirmation, no email round trip to talk you out of it.

Both are immediate and neither is recoverable. That is the intended trade.

Who else sees any of it

One processor, and only when an email has to leave the building:

  • Resend, the transactional mail provider, is sent the recipient address and the plain-text message when you ask for a sign-in link or when you invite somebody to a workspace. An invitation names the person who sent it, so both addresses are in it. Those are the only two messages the product sends, and Resend is not contacted at all if you send neither.
  • The infrastructure this runs on is operated by netcup GmbH, who stores the database and processes requests on our instruction.

There is nothing else. No analytics provider, no tag manager, no session recorder, no advertising network, no error-reporting service, no content delivery network, and no externally hosted fonts — the typefaces are served from this domain. Your browser is told by this site's content security policy to connect to this origin and no other, which is a claim you can check in the response headers rather than take on trust.

Cookies

Four at most, all first-party, none for advertising:

  • dsose_session — names the anonymous organization your assessment belongs to, signed so it cannot be pointed at somebody else's. Strictly necessary; without it the assessment cannot be found again.
  • dsose_assessment — which assessment inside that organization you are working on. Strictly necessary.
  • the sign-in session cookie, set only after you follow a sign-in link, and cleared when you sign out.
  • consent — your answer to the measurement question above. Set only once you answer it.

Your measurement choice

Stored in a first-party cookie named “consent” on this device. Change it whenever you like; deleting the cookie puts it back to no.

Rate limiting, and the IP addresses it sees

A few actions — starting an assessment, asking for a sign-in link — are rate limited, so that the product cannot be turned into a mail relay. Every one of them, including the sign-in endpoints the identity library protects, is counted against a keyed hash of your IP address: the stored row answers “has this caller been here in the last minute” and cannot be read back into an address or joined against anything. Signing in does record the address and browser of the session itself, as above, so that a stolen session can be recognised and ended. Nothing else in the product sees, logs or stores your IP address.

Your rights, and what serves them

The GDPR gives you these. Where the product already does the job, use the product — it is faster than writing to us and the answer is the same:

  • Access — everything held about an assessment is on screen in the coverage map, and the JSON export is the same data in machine-readable form. Ask for anything held beyond that and we will send it.
  • Portability — the JSON and CSV exports of an assessment. No account required, no request to make, and the file is yours to take anywhere. For what an account holds about you, rather than about your application, ask us and we will send it.
  • Erasure — the delete button on the assessment, or account deletion. Both purge rather than hide.
  • Rectification — an answer that is wrong can be corrected by running the assessment again; write to us if something else is wrong.
  • Objection and withdrawal — refuse measurement above, or withdraw a yes you already gave. Neither changes what the product does for you.

You may also complain to a data protection supervisory authority.

Who to write to

The controller is Maximilian Dörr, Backenfeldsteig 28, 91126 Schwabach. Data protection enquiries: mxdoerr@chacha.charity. The full company details are in the imprint.

Read the imprint