These policies play an important role to maintain a positive experience for everyone that uses EdgeWatch.
For the purposes of data protection laws, we are the “Data Processor” in respect of the personal information collected through our website located at https://edgewatch.com/ (“Site”).
- THE PII AND OTHER SENSITIVE DATA WE COLLECT We automatically collect the following PII from users that visit our Site:
- IP address
- web browser type and version
- operating system
- a list of URLs starting with a referring site, your activity on Our Site, and the site you exit to
- email address
- company name
- VAT number
- Target URL and settings (including testing credentials if provided)
- Vulnerability details including Requests/Responses for each vulnerability found
- Product logs, including the URLs tested and full requests (temporarily, up to 60 days)
- you have given consent to the processing of your personal data for one or more specific purposes;
- processing is necessary for the performance of a contract to which you are a party or in order to take steps at the request of you prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which we are subject;
- processing is necessary to protect the vital interests of you or of another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
- _ga Used by Google Analytics to distinguish users (2 yrs)
- _gid Used by Google Analytics to distinguish users (1 day)
- _gat Used by Google Analytics to throttle request rate (1 min)
- _gcl* Used by Google Adsense (3 mo)
- NID; DV; 1P_JAR Used by Google to store preferences (6 mon)
- __stripe_* Used by Stripe to provide fraud prevention
- PROTECTION OF PII AND OTHER SENSITIVE DATA As owners of a security product, we take PII security very seriously. The following list is a non-exhaustive list of security controls we implemented to protect our infrastructure, our product, and your PII:
- We only allow communications to our servers, that host our product and site, through a secure channel (HTTPS) using TLS. HTTPS allows for the authentication of the visited website and protection of the privacy and integrity of the exchanged data.
- All of our infrastructure is hosted in a top-tier cloud provider, where security has been scrutinized. We use managed services supplied by the cloud provider to the highest possible extent. We also use their security features and controls, to segregate and monitor our service networks, for audit logs, and for security event management. The frontend, backend, and database servers use private and segregated networks controlled by security groups.
- We also follow the best security practices, including (but not limited to):
- Principle of the least privilege (to access our systems and data),
- Encryption of sensitive data at rest,
- Server hardening and security updates,
- Requiring 2-factor authentication to access our systems,
- Central logging
- Secure Software Development Life cycle, including periodic security assessments (manual and using Edgewatch)
- THIRD-PARTY ACCESS TO YOUR PII We give or may give in the future certain independent contractors access to PII (“Data Processors”). No Data Processor will be retained without first entering into contracts in which they agree to protect PII using procedures reasonably similar to ours and will only process PII in accordance with our instructions. We may also disclose PII to attorneys and investors bound to confidentiality restrictions and to law enforcement authorities, courts, and public regulators, whenever such is required by applicable legislation. Finally, we may share PII in connection with a transaction of all or substantially all of our assets. To provide the services, we rely on different data subprocessors, which process different categories of data. Processors never store data outside of the scope of their specific purpose. These subprocessors are listed below, with a description of the service and the location where data is hosted. This list may be updated by Edgewatch from time to time:
- Stripe, Inc.
- Payment processing
- Analytics, Tag Manager, Workspace
- Stripe, Inc.
- WHERE WE STORE YOUR PII AND FOR HOW LONG Unless expressly agreed or contracted otherwise, all the PII regarding our users is stored on secure servers located within the European Union. We will inform our users should we eventually change our policy. Our objective is that our users have a long-lasting relationship with our Site, even if visits are not very frequent. We will store your PII and your account will continue to be active for three years following your last interaction with our Site. Prior to closing your account, we will notify you asking whether you wish to maintain your account active. After a deletion request, your PII will be retained for up to 3 months as part of backup procedures.
If you believe that someone is violating the policies, please report abuse immediately. To report copyright infringement or other pressing legal issues, please use our abuse report form.
If you fall victim to cybercrime, notify your local authorities immediately to file a complaint. Preserve and document all evidence related to the incident and any potential sources. Avoid attack, responding or retaliating on your own or using Edgewatch.
The tools and services of the Edgewatch platform are designed to be complementary and defensive; while they are used by law enforcement agencies, they are not intended to replace or supplant the investigative and enforcement efforts of the authorities in response to a criminal offense.
Report Trademark Infringement
If you suspect that someone is misusing our trademark, please alert us promptly. To address trademark infringement or other pertinent legal concerns, kindly utilize our abuse report form.