SecRecon
Scanner Dashboard
Capabilities How It Works
Security Researchers Penetration Testers Universities MSPs
Docs API Community Vulnerability Research
Pricing Try Demo Admin
BETA You're in the SecRecon Beta — all features unlocked, 2 free scans/month, no payment required. View Plans →

Checking your session…

🔒

Authentication Required

Please sign in to access this page.

Privacy Policy

Last updated: August 2026

Data Controller: Lokesh Lalwani, operating as SecRecon (not currently a registered legal entity), based in Texas, USA. [Registered business address — fill in once available; a physical or registered agent address is expected here for full compliance, not just a contact form.] For any privacy inquiry, contact us via the Contact page.

1. Information We Collect

We collect information you provide when creating an account (email address, name), scan targets you submit, and usage data such as scan counts and timestamps. If you contact us or submit a form (e.g. demo request, enterprise inquiry), we collect what you provide there (name, email, company, message).

Scan target data: Running a scan can incidentally surface information about the target system that is not yours — for example, a misconfigured server may expose email addresses, names, or other data belonging to third parties who are not SecRecon users. We do not use this incidentally-discovered data for any purpose beyond generating your scan report, and it is subject to the same retention limits as the rest of your scan data (Section 7). You are responsible for having proper authorization to scan any target, per our Terms of Service.

2. How We Use Your Information

We process your information to: provide and operate the scanning service, generate reports, respond to support requests, maintain account security, and improve the platform. Our legal basis for this processing is performance of the contract with you (providing the service you signed up for), our legitimate interest in operating and securing the platform, and — where applicable — your consent (e.g., for optional communications).

3. Authentication

We use Clerk for authentication. Your login credentials are managed by Clerk's secure infrastructure. We do not store passwords directly.

4. Scan Data

Scan targets, results, and generated reports are stored temporarily. PDF reports are automatically deleted after 24 hours. Scan metadata (target domain, timestamp, status, findings) is retained in your account history so you can track scan history over time.

5. Community Posts

Posts and comments in the community forum are stored with your display name and may be visible to other users. Flagged content is reviewed by administrators.

6. AI Processing

Scan data and community posts are processed by AI models (Anthropic Claude and OpenAI) to generate analysis, reports, and automated responses. This data is sent to these providers for processing and is not used by us to train models. Each provider processes data under its own terms — see Anthropic's and OpenAI's privacy policies.

7. Data Retention

Account data is retained while your account is active. Scan reports (PDFs) are automatically purged after 24 hours; scan metadata and findings are retained as part of your account history until you delete your account or request deletion. Audit logs of administrative actions are retained for security and accountability purposes. You may request deletion of your account data by contacting us — see Section 12 for how to exercise this and other rights.

8. Cookies & Tracking

We use strictly necessary cookies for authentication and session management (via Clerk) and to keep you signed in between visits. We do not use third-party advertising or cross-site tracking cookies.

9. Data Security

We use industry-standard security measures including encrypted connections (HTTPS), secure authentication tokens, and database encryption at rest. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. International Data Transfers

Our infrastructure is hosted in the United States. If you access the Platform from outside the United States, including from the European Economic Area or United Kingdom, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.

11. Third-Party Services

We use the following third-party services, each of which processes data under its own privacy policy: Clerk (authentication), Anthropic and OpenAI (AI analysis), Sentry (backend error monitoring — technical crash data only, such as stack traces and request paths, not request headers or cookies). Our database and application infrastructure are self-hosted on our own managed servers, not a third-party data-processing service.

12. Your Data Protection Rights

Depending on your location, you may have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data; request a copy of your data in a portable format; object to or restrict certain processing; and lodge a complaint with your local data protection authority. To exercise any of these rights, contact us via the Contact page. We will respond within the timeframe required by applicable law.

13. Regulated Data (HIPAA, FERPA, and Similar Frameworks)

SecRecon is a security testing service provider, not a healthcare provider or educational institution — frameworks like HIPAA and FERPA place compliance obligations directly on covered entities (healthcare organizations, schools), not on their vendors by default. If your organization is subject to HIPAA, FERPA, or a similar regulatory framework and you need SecRecon to support your compliance obligations — for example, executing a Business Associate Agreement or a Data Processing Agreement — contact us via the Contact page before submitting regulated data or systems for scanning. We do not represent that any plan or feature is certified compliant with HIPAA, FERPA, or any other specific regulatory framework unless confirmed in a signed written agreement.

14. Children's Privacy

The Platform is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above; continued use of the Platform after changes take effect constitutes acceptance of the revised policy.

16. Contact

For privacy-related inquiries, including exercising your data protection rights, please contact us via the Contact page.

Join the Waitlist

Evaluating SecRecon for your team or organization? Join the waitlist and we'll follow up personally.

SecRecon

AI-powered attack surface intelligence — verified findings, not noise.

Product Scanner Pricing How It Works API
Company Community Vulnerability Research Contact
Legal Terms Privacy
© 2026 SecRecon ALL SYSTEMS OPERATIONAL

Challenge Submission

Scanner found the automated results. Now show us what you found. Answer as many as you can — blank is fine, but depth matters.