Skip to main content

// Compliance

Privacy Policy.

Last updated: July 23, 2026. How we manage client telemetry, vulnerability records, and scoping data.

SDX Shadow Labs ("SDX Shadow Labs," "the Firm," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect through sdxshadowlabs.com (the "Site") and our free tools, how we use it, and the choices available to you. As a security firm, we hold ourselves to a high standard of data protection and expect you to hold us accountable to it.

1. Scope

This Policy applies to information collected through:

  • The public Site (sdxshadowlabs.com)
  • Our contact/inquiry form
  • Our free external exposure scanner tool
  • Any general correspondence with us (email, scoping calls)

This Policy does not cover information handled during a paid Engagement, which is instead governed by the confidentiality provisions of the signed NDA and MSA for that Engagement - a materially stricter standard than this Policy.

Important: this Site does not store client audit or engagement data. The database and infrastructure behind sdxshadowlabs.com (MongoDB Atlas, Vercel, Brevo, as described in Section 5) hold only public inquiry-form submissions and Scanner queries. No source code, credentials, findings, vulnerability reports, scope documents, or any other material arising from a paid Engagement is ever stored on, processed by, or transmitted through the Site's infrastructure. Engagement data is handled exclusively through separate, access-controlled channels agreed with the Client under the relevant NDA and MSA, entirely isolated from the Site's systems.

2. Information We Collect

2.1 Information you provide directly

When you submit our contact/inquiry form, we collect:

  • Company name
  • Your name
  • Business email address (personal email domains such as Gmail, Yahoo, and Hotmail are not accepted)
  • Phone number (optional)
  • Service required and budget range
  • The details of your inquiry, as written by you

2.2 Information collected through the free Scanner

When you use the Scanner, we collect the domain name you submit and generate a report based on publicly available information about that domain (DNS records, HTTP headers, TLS certificate metadata, and public path accessibility). We do not require an account or personal information to use the Scanner.

2.3 Automatically collected information

Like most websites, we may collect standard technical data when you browse the Site, such as IP address, browser type, device type, referring page, and pages visited, typically through privacy-respecting analytics. See Section 9 (Cookies) for details.

3. How We Use Information

We use the information described above to:

  • Respond to and evaluate inquiries submitted through the contact form
  • Send transactional emails, such as inquiry acknowledgment and follow-up correspondence
  • Generate and display Scanner results back to the user who requested them
  • Maintain and improve the Site's security, performance, and content
  • Comply with legal obligations and enforce our Terms of Service

We do not use inquiry or Scanner data for advertising, and we do not sell personal data to third parties, under any circumstances.

4. Legal Basis for Processing

Where applicable data protection law (such as the GDPR, for visitors in the EU/UK) requires a legal basis for processing, we rely on:

  • Consent - for the contact form, by voluntarily submitting your information and agreeing to be contacted.
  • Legitimate interest - for maintaining Site security, preventing abuse of the Scanner, and responding to business inquiries.
  • Legal obligation - where required by applicable law, such as retaining records for tax or compliance purposes.

5. Data Sharing and Third-Party Processors

We use select third-party service providers to operate the Site (including secure cloud database providers, transactional email processors, and cloud hosting infrastructure). Each processes data solely on our behalf and is contractually restricted from using it for any other purpose.

We do not share your information with any other third party except: (a) as required by law, subpoena, or valid legal process; (b) to protect the rights, property, or safety of SDX Shadow Labs, our users, or the public; or (c) in connection with a merger, acquisition, or sale of assets, subject to equivalent confidentiality protection.

6. Client Engagement and Audit Data - Not Held by This Site

To be unambiguous: the Site's technical infrastructure is architected so that it is not capable of holding Client audit, testing, or engagement data.

  • The website's database is scoped strictly to public inquiry submissions and anonymized telemetry from the free public Scanner tool. It has no schema, storage path, or integration for engagement deliverables, deep findings, credentials, or source code.
  • Reports, evidence, proof-of-concept material, and all working documents produced during an Engagement are created, stored, and transmitted through separate, access-restricted systems maintained specifically for that purpose, entirely outside of the Site's hosting and database environment.

This separation is intentional: it ensures that even in the event of a compromise of the public-facing Site, no Client engagement material would be exposed, because none of it is there to begin with.

7. Data Retention

  • Inquiry data is retained for as long as reasonably necessary to evaluate and respond to your inquiry, and for a limited period afterward for business record-keeping, unless you request earlier deletion.
  • Scanner submissions (the domain queried, findings, and the IP address of the request origin) are retained for our internal security analytics, trend analysis, and abuse-prevention purposes. This data is not linked to any personal identity, and we do not sell or share this telemetry with third-party data brokers.
  • Data related to a signed Engagement is retained according to the retention terms specified in the applicable MSA.

8. Data Security Measures

Given our line of work, we apply meaningful safeguards to the data we hold, including encrypted storage, access restricted to authorized personnel only, and use of reputable, security-audited infrastructure providers. No system is completely immune to compromise, and we cannot guarantee absolute security - but we hold our own infrastructure to the same standard we recommend to our clients.

In the unlikely event of a data breach affecting personal information we hold, we will notify affected individuals and relevant authorities as required under applicable law, without undue delay (see Section 13).

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Request access to the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request a copy of your data in a portable format

To exercise any of these rights, contact us at the email address in Section 15. We will respond within a reasonable timeframe, generally within 30 days.

10. Cookies and Tracking

The Site may use minimal, privacy-respecting cookies or similar technologies strictly necessary for site functionality (e.g., remembering your currency preference on the pricing page) and, where used, for aggregate, non-identifying analytics to help us understand site usage. We do not use third-party advertising cookies or cross-site tracking.

11. International Data Transfers

Our infrastructure providers (MongoDB Atlas, Brevo, Vercel) may process data in regions outside your country of residence, including outside India or the EU/UK. Where required, we rely on those providers' standard contractual safeguards for international data transfer.

12. Children's Privacy

The Site and our services are intended for business use by adults and organizations. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected such information, we will delete it promptly.

13. Data Breach Notification

In the event of a security incident affecting personal data collected through the Site, we will assess the scope of the incident, take immediate containment measures, and notify affected individuals and applicable regulators in accordance with applicable law and within legally required timeframes.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The "Last updated" date above reflects the most recent revision. Material changes will be highlighted on this page.

15. Contact Us

For any question about this Privacy Policy, or to exercise your data rights, contact:

SDX Shadow Labs
Email: contact@sdxshadowlabs.com

If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.