Skip to content
RiftX

Privacy

What we hold for a retest, and how to have it removed.

Written as a document you can answer a client questionnaire from rather than as decorative legal copy. The operational security posture, meaning what the agent is permitted to reach and what refuses it, is on the trust page.

Data, at a glance

What we hold

The target URL, the steps to reproduce, the reported finding class, and the evidence a retest produced against them.

What we never do with it

None of it is used as training data, and nothing is shared with any party outside the account it belongs to. The four companies that do sit in the path are named on the subprocessor page.

How long

A retest's evidence is held for 365 days from the run, then deleted rather than archived.

Getting it removed

Deletion and export requests go to privacy@riftx.io and are actioned against the whole account, not per artifact.

In effect since

3 August 2026. This date moves whenever the document does.

Three parties, and only one of them is our customer

Most privacy documents assume a vendor and a user. A retest has your firm, your client, and us, so the first question is which of the three decides what.

Your consultancy

Our customer, and the controller

You decide which findings get retested, against which targets, and who on your team can read the result. We act on your instruction and hold nothing you did not submit. If your client asks you what is held about their systems, the answer is whatever you sent plus whatever the retest captured.

Your client

Owns the target, and authorizes the test

We have no relationship with them and never contact them. Their authorization reaches us through you, which is why the scope clause we provide is bounded to the findings you already reported rather than to the host generally.

RiftX

Processor, and nothing more

We process what you submit in order to run the retest you asked for, and for no other purpose. We do not sell data and we do not build a cross-customer dataset out of it. What happens to it at the model is set out under Model usage below.

What is actually collected

Split by where it came from, because the two halves are governed differently from here on.

If you use this website

Demo request

Work email, company name, and how many engagements you run a month.

So we can reply to you, and so the conversation starts at the right plan.

Blog subscription

Email address only.

To send you new posts. Unsubscribe at any time by replying to one.

Server logs

The ordinary request records our host keeps, including IP address and browser type.

Keeping the site up and defending it from abuse.

If you run a retest

Account

The identity your API key resolves to, and the retests booked against it.

Authenticating your requests and counting them against your allowance.

Retest inputs

The target URL, your steps to reproduce, the reported finding class, and any supporting context you attach.

They are the retest. Without them there is nothing to run.

Evidence

The network captures, browser artifacts and reasoning trail the run produced, sealed into one bundle.

So the verdict can be checked and defended by a pentester after the fact.

Bounded retesting, not loose data collection.

11 topics, and a pointer to where the security posture is documented.

Why we process any of it

For retest data, the purpose is the retest and there is no second purpose. We process what you submit because you asked for a verdict on a finding, and the processing stops when the verdict is delivered and the retention window closes.

For website data, the purpose is replying to you. A demo request is processed because you asked us to get in touch, a blog subscription because you asked for the posts, and logs because a public site that keeps no records cannot be defended from the traffic it attracts.

We do not profile you, we do not advertise, and there is no third party buying any of this. If you are in a jurisdiction that asks us to name a lawful basis, the basis is the contract we are performing for retest and account data, your consent for the blog list, and our legitimate interest in operating and defending the website for logs.

What a captured bundle contains

A retest drives a real browser against a live target, so the evidence it captures is real traffic rather than a synthetic transcript. A bundle can therefore contain request and response bodies, headers, cookies and session tokens issued during the run, screenshots of pages as they rendered, and whatever those pages happened to show.

That makes a bundle roughly as sensitive as the target it was captured against, and it is worth treating it that way inside your own firm. Who can open it is decided by your account rather than by us, and the enforcement behind that is documented on the trust page.

Credentials in a submission

Steps to reproduce are free text, and anything you put there, including a test account, is stored as submitted and reaches the model prompt and the finished report. There is no vault and no masking on that field, so treat it as plain text.

Use an account scoped to the finding at the lowest privilege that still reproduces it, and rotate it after the retest. If that is not possible for a given engagement, tell us before you submit rather than after.

The same care applies to what the run captures afterwards. A bundle can hold session tokens issued during the retest, and the trust page sets out why a downloaded one should be handled as though those are live.

Model usage

LLM reasoning is part of how a verdict is reached, and the reasoning is returned to you rather than hidden. Reasoning runs on Anthropic's API under our account, and those terms exclude training on inputs and outputs, so the guarantee is Anthropic's to publish and yours to check rather than ours to assert.

No other model provider is in the path, and your data is not used to improve RiftX's own behaviour. There is no opt-out to find because there is no opt-in.

Where it is held, and where it goes

The server RiftX runs on is in Austria, and the application, the account database and the evidence store are all on it. Evidence is encrypted at rest under AES-256 and never rests on the machine that produced it.

Three things leave that machine and no others: the reasoning, which reaches the United States, traffic in transit, which crosses a global edge network, and account email, which is sent from the United States. Each is listed on the subprocessor page with what specifically reaches it.

Storage region is not something we can offer a choice of, and the trust page lists that alongside the other assurances we do not yet have.

How long we keep things

The window on a retest's evidence is 365 days from the run, and it exists so a verdict stays defensible for as long as an engagement is likely to be argued over. At the end of it the bundle is deleted rather than archived.

Account records are kept while the account is open and are deleted when it closes. A demo request is kept until the conversation ends or you ask us to drop it. A blog subscription lasts until you unsubscribe. Server logs roll off on the ordinary schedule our host keeps.

Deletion means deletion. We do not move artifacts to cold storage and call it deleted.

What you can ask us to do

You can ask what is held about you, ask for a copy of it, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to a particular use, or withdraw consent where consent is what we relied on. Where your jurisdiction gives you a right to complain to a data protection authority, using it does not require going through us first.

Requests go to privacy@riftx.io. We answer within 30 days, we confirm in writing what was done, and there is no charge. A deletion request is actioned across the whole account rather than per artifact, so tell us if that is not what you meant.

If your client wants something erased and their relationship is with you rather than with us, send the request through and we will action it against your account. We will not act on an instruction from someone we cannot tie to a customer, because that is itself an attack.

Who else sees it

Every party that can reach any of it is on the subprocessor register, currently four companies, each named with what specifically reaches it and where. Nobody else sees any of it. We do not sell data and there is no advertising network anywhere in this product.

When a subprocessor is added we post it on that page and email account holders, both before the change takes effect and with at least 30 days' notice. You can object by replying to either. If we are ever compelled to hand something over by law, we will tell you unless we are legally barred from doing so.

If something goes wrong

If a breach affects your data we will tell you inside 72 hours of becoming aware of it, in writing, with what we know at that point rather than after the investigation concludes. That message will say what was reached, when, what we have done, and what we are asking you to do.

Be clear about what that is and is not: it is how we intend to operate, not a contractual window, because there is no data processing agreement yet to carry one. If your client needs the commitment on paper rather than on a page, that is a gap and it is worth raising early.

We would rather send you an early message that turns out to be smaller than it looked than a tidy one a fortnight late.

Children

This is a product sold to security consultancies and nothing on it is directed at children. We do not knowingly collect data about anyone under 16. If you believe we have, write to privacy@riftx.io and it will be deleted.

Changes to this page

The effective date at the top of this page moves whenever the document does. Material changes, meaning anything that alters what we hold, how long we hold it, or who else sees it, are announced on the subprocessor page's update feed as well, so a change is visible without re-reading the whole document.

We will not make a change retroactive. Data collected under an earlier version stays governed by the version it was collected under.

Who is responsible for this data

RiftX is operated by its founder and is not yet incorporated, so there is no registered company name or company number to give you here. This page will name both the day there are. Everything below describes how the product actually handles data today, and the two addresses at the foot of the page reach a person rather than a queue.

Contact

Privacy requests

privacy@riftx.io. Deletion, export, and questions about what is held on your account. Answered within 30 days and confirmed back in writing, at no charge.

Security issues

security@riftx.io. If you have found something in RiftX itself, this reaches the person who built it. Reports are acknowledged within 48 hours, and we aim to have a fix or mitigation within 14 days depending on severity.

Execution isolation, target validation, tenant separation, evidence sealing and the ceilings that bound every retest are on Trust and security. Every party that can reach any of it is named on Subprocessors, with what specifically reaches each of them.