Privacy
What we hold for a retest, and how to have it removed.
Written as a document you can answer a client questionnaire from rather than as decorative legal copy. The operational security posture, meaning what the agent is permitted to reach and what refuses it, is on the trust page.
Data, at a glance
What we hold
The target URL, the steps to reproduce, the reported finding class, and the evidence a retest produced against them.
What we never do with it
None of it is used as training data, and nothing is shared with any party outside the account it belongs to. The four companies that do sit in the path are named on the subprocessor page.
How long
A retest's evidence is held for 365 days from the run, then deleted rather than archived.
Getting it removed
Deletion and export requests go to privacy@riftx.io and are actioned against the whole account, not per artifact.
In effect since
3 August 2026. This date moves whenever the document does.
Three parties, and only one of them is our customer
Most privacy documents assume a vendor and a user. A retest has your firm, your client, and us, so the first question is which of the three decides what.
Your consultancy
Our customer, and the controller
You decide which findings get retested, against which targets, and who on your team can read the result. We act on your instruction and hold nothing you did not submit. If your client asks you what is held about their systems, the answer is whatever you sent plus whatever the retest captured.
Your client
Owns the target, and authorizes the test
We have no relationship with them and never contact them. Their authorization reaches us through you, which is why the scope clause we provide is bounded to the findings you already reported rather than to the host generally.
RiftX
Processor, and nothing more
We process what you submit in order to run the retest you asked for, and for no other purpose. We do not sell data and we do not build a cross-customer dataset out of it. What happens to it at the model is set out under Model usage below.
What is actually collected
Split by where it came from, because the two halves are governed differently from here on.
If you use this website
Demo request
Work email, company name, and how many engagements you run a month.
So we can reply to you, and so the conversation starts at the right plan.
Blog subscription
Email address only.
To send you new posts. Unsubscribe at any time by replying to one.
Server logs
The ordinary request records our host keeps, including IP address and browser type.
Keeping the site up and defending it from abuse.
If you run a retest
Account
The identity your API key resolves to, and the retests booked against it.
Authenticating your requests and counting them against your allowance.
Retest inputs
The target URL, your steps to reproduce, the reported finding class, and any supporting context you attach.
They are the retest. Without them there is nothing to run.
Evidence
The network captures, browser artifacts and reasoning trail the run produced, sealed into one bundle.
So the verdict can be checked and defended by a pentester after the fact.
Bounded retesting, not loose data collection.
11 topics, and a pointer to where the security posture is documented.
Why we process any of it
For retest data, the purpose is the retest and there is no second purpose. We process what you submit because you asked for a verdict on a finding, and the processing stops when the verdict is delivered and the retention window closes.
For website data, the purpose is replying to you. A demo request is processed because you asked us to get in touch, a blog subscription because you asked for the posts, and logs because a public site that keeps no records cannot be defended from the traffic it attracts.
We do not profile you, we do not advertise, and there is no third party buying any of this. If you are in a jurisdiction that asks us to name a lawful basis, the basis is the contract we are performing for retest and account data, your consent for the blog list, and our legitimate interest in operating and defending the website for logs.
What a captured bundle contains
A retest drives a real browser against a live target, so the evidence it captures is real traffic rather than a synthetic transcript. A bundle can therefore contain request and response bodies, headers, cookies and session tokens issued during the run, screenshots of pages as they rendered, and whatever those pages happened to show.
That makes a bundle roughly as sensitive as the target it was captured against, and it is worth treating it that way inside your own firm. Who can open it is decided by your account rather than by us, and the enforcement behind that is documented on the trust page.
Credentials in a submission
Steps to reproduce are free text, and anything you put there, including a test account, is stored as submitted and reaches the model prompt and the finished report. There is no vault and no masking on that field, so treat it as plain text.
Use an account scoped to the finding at the lowest privilege that still reproduces it, and rotate it after the retest. If that is not possible for a given engagement, tell us before you submit rather than after.
The same care applies to what the run captures afterwards. A bundle can hold session tokens issued during the retest, and the trust page sets out why a downloaded one should be handled as though those are live.
Model usage
LLM reasoning is part of how a verdict is reached, and the reasoning is returned to you rather than hidden. Reasoning runs on Anthropic's API under our account, and those terms exclude training on inputs and outputs, so the guarantee is Anthropic's to publish and yours to check rather than ours to assert.
No other model provider is in the path, and your data is not used to improve RiftX's own behaviour. There is no opt-out to find because there is no opt-in.
Where it is held, and where it goes
The server RiftX runs on is in Austria, and the application, the account database and the evidence store are all on it. Evidence is encrypted at rest under AES-256 and never rests on the machine that produced it.
Three things leave that machine and no others: the reasoning, which reaches the United States, traffic in transit, which crosses a global edge network, and account email, which is sent from the United States. Each is listed on the subprocessor page with what specifically reaches it.
Storage region is not something we can offer a choice of, and the trust page lists that alongside the other assurances we do not yet have.
How long we keep things
The window on a retest's evidence is 365 days from the run, and it exists so a verdict stays defensible for as long as an engagement is likely to be argued over. At the end of it the bundle is deleted rather than archived.
Account records are kept while the account is open and are deleted when it closes. A demo request is kept until the conversation ends or you ask us to drop it. A blog subscription lasts until you unsubscribe. Server logs roll off on the ordinary schedule our host keeps.
Deletion means deletion. We do not move artifacts to cold storage and call it deleted.
What you can ask us to do
You can ask what is held about you, ask for a copy of it, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to a particular use, or withdraw consent where consent is what we relied on. Where your jurisdiction gives you a right to complain to a data protection authority, using it does not require going through us first.
Requests go to privacy@riftx.io. We answer within 30 days, we confirm in writing what was done, and there is no charge. A deletion request is actioned across the whole account rather than per artifact, so tell us if that is not what you meant.
If your client wants something erased and their relationship is with you rather than with us, send the request through and we will action it against your account. We will not act on an instruction from someone we cannot tie to a customer, because that is itself an attack.
If something goes wrong
If a breach affects your data we will tell you inside 72 hours of becoming aware of it, in writing, with what we know at that point rather than after the investigation concludes. That message will say what was reached, when, what we have done, and what we are asking you to do.
Be clear about what that is and is not: it is how we intend to operate, not a contractual window, because there is no data processing agreement yet to carry one. If your client needs the commitment on paper rather than on a page, that is a gap and it is worth raising early.
We would rather send you an early message that turns out to be smaller than it looked than a tidy one a fortnight late.
Children
This is a product sold to security consultancies and nothing on it is directed at children. We do not knowingly collect data about anyone under 16. If you believe we have, write to privacy@riftx.io and it will be deleted.
Changes to this page
The effective date at the top of this page moves whenever the document does. Material changes, meaning anything that alters what we hold, how long we hold it, or who else sees it, are announced on the subprocessor page's update feed as well, so a change is visible without re-reading the whole document.
We will not make a change retroactive. Data collected under an earlier version stays governed by the version it was collected under.
Who is responsible for this data
RiftX is operated by its founder and is not yet incorporated, so there is no registered company name or company number to give you here. This page will name both the day there are. Everything below describes how the product actually handles data today, and the two addresses at the foot of the page reach a person rather than a queue.
Contact
Privacy requests
privacy@riftx.io. Deletion, export, and questions about what is held on your account. Answered within 30 days and confirmed back in writing, at no charge.
Security issues
security@riftx.io. If you have found something in RiftX itself, this reaches the person who built it. Reports are acknowledged within 48 hours, and we aim to have a fix or mitigation within 14 days depending on severity.
Execution isolation, target validation, tenant separation, evidence sealing and the ceilings that bound every retest are on Trust and security. Every party that can reach any of it is named on Subprocessors, with what specifically reaches each of them.
