swaudit
Privacy Terms Acceptable Use Back to site

Privacy Policy

Version 1.3 — effective July 17, 2026

This Privacy Policy describes how swaudit ("we," "us") collects, uses, and shares information when you use swaudit.net, the hosted swaudit audit service, demo and interactive sessions, and related APIs (together, the "Service"). It does not apply to self-hosted swaudit deployments, which run entirely on the deploying organization's own infrastructure; for those, the deploying organization is responsible for its own privacy practices.

What we collect

Information you give us.

  • Contact and demo-request forms: your email address, and any name, company, area of interest, and message text you choose to provide.
  • Account and access data: when you sign in through your organization's single sign-on or use an access token, we receive an identifier such as your email address, name, and role.

Submissions and audit artifacts. When software is analyzed in the Service — including demo and interactive sessions — we process the analyzed software and generate audit artifacts: process, file, and network event logs; intercepted network traffic of the candidate software inside the sandbox (including decrypted TLS content); planted-credential (honeytoken) hit records; screen recordings of interactive sessions; and the resulting reports. These artifacts describe the behavior of the analyzed software. Do not include personal data in submissions unless you are authorized to share it with us.

Automatic collection. Standard technical data: IP address, browser user-agent, request logs, and a server-side audit log of actions taken in the Service, used for security and accountability.

Cookies and browser storage. We set two essential cookies: swaudit_session, when you sign in (it contains only a random session identifier — never your access token — keeps you signed in until the session expires on our server, and is cleared when you log out), and swaudit_csrf, a security cookie containing a random value used solely to protect signed-in sessions against cross-site request forgery — it identifies no one and tracks nothing. Pages also use your browser's local storage for in-page state (for example, remembering an interactive session's display settings). We do not use advertising cookies, analytics trackers, or any third-party tracking.

Email delivery metadata. If we email you (for example, a demo link you requested), we process delivery, bounce, and complaint signals to keep our sending honest and deliverable.

How we use information

  • To provide the Service: run audits, generate and deliver reports, operate demo and interactive sessions.
  • To respond to your inquiries and demo requests.
  • To secure and operate the Service: abuse prevention, debugging, audit logging, capacity planning.
  • To send you product and commercial communications you have requested, or that we may lawfully send you as a business contact — always with a working opt-out.
  • To comply with legal obligations.

Where the EU/UK GDPR applies, our legal bases are: performance of a contract (providing the Service you request), legitimate interests (securing the Service, business-to-business communications relevant to your role, improving the product), consent where we ask for it, and legal obligation.

What we share

We do not sell personal information, and we do not share it with third parties for their own advertising. We share information only with:

  • Service providers acting on our instructions: cloud infrastructure providers and email delivery providers located in the United States.
  • Integrations you configure (for example Slack, Jira, or webhooks): the Service sends what you configure it to send.
  • Legal process and safety: if required by law, or to protect the Service, our users, or the public — for example, evidence of unlawful use.
  • Business transfers: in a merger, acquisition, or asset sale, information may transfer with appropriate protections; we will notify you of any change in control.

Retention

  • Contact and demo-request records are kept while we have an ongoing business reason to hold them, and deleted on request.
  • Submitted software is used to perform the requested audit and produce its report, and is not used for any other purpose. Submitted binaries are automatically deleted a short, configurable period after their audit completes (unless a legal hold applies), and every deletion is recorded in an append-only deletion log so the removal itself is verifiable.
  • Audit reports, event logs, and session recordings are retained so that audits remain reviewable and verifiable, and are deleted on request where we have no overriding obligation to keep them.
  • Request and security logs are retained for operational and security purposes.

International transfers

We are based in the United States and process data there. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S.

Your rights

Depending on where you live (including under the GDPR and the California CCPA/CPRA), you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to opt out of marketing at any time. To exercise any right, contact us using the details below; we will verify your request and respond within the time required by law. We do not discriminate against you for exercising your rights. California residents: we do not "sell" or "share" personal information as those terms are defined by the CCPA/CPRA.

Security

We use technical and organizational measures appropriate to the data we handle, including role-based access, audit logging, sandbox isolation for analyzed software, and encryption in transit. No system is perfectly secure; we cannot guarantee absolute security.

Children

The Service is a business tool, is not directed to anyone under 16, and we do not knowingly collect their data.

Changes

We will post updates to this policy on this page with a new effective date, and will note material changes prominently.

Contact

Use the contact form on swaudit.net, or email rapidvps@gmail.com.

swaudit · enterprise software-audit platform · contact for licensing

Privacy Policy · Terms of Service · Acceptable Use · Contact