Privacy Policy
This Privacy Policy explains how KvitraX ("KvitraX", "we", "us", or "our") collects, uses, stores, and protects information when customers and authorized users access the KvitraX platform and related services.
1. Information we collect
Depending on how the service is used, we may process:
- account information such as name, email address, organization and role;
- authentication and session information;
- security asset, vulnerability, exposure and configuration data submitted to or generated within KvitraX;
- service usage, security, diagnostic and audit information;
- communications sent to our support team.
2. Google Sign-In
KvitraX supports authentication through Google using OpenID Connect. When a user chooses Sign in with Google, KvitraX requests only the standard identity scopes required for authentication: openid, email, and profile.
KvitraX does not request access to Gmail messages, Google Drive files, Google Calendar data, or other Google Workspace content as part of Google Sign-In.
We may receive and store identity attributes supplied by Google, including a Google account identifier, verified email address and basic profile information, for the purpose of authenticating the user, linking the user to an authorized KvitraX organization, maintaining sessions and supporting security auditing.
3. How we use information
We use information to:
- provide, operate and secure the KvitraX service;
- authenticate users and enforce organization-level access controls;
- correlate security intelligence with customer-authorized assets;
- generate findings, reports, notifications and operational security workflows;
- detect abuse, investigate incidents and maintain audit records;
- provide support and improve service reliability.
4. Customer security data
Customer data submitted to KvitraX remains associated with the applicable customer organization. We do not use one customer's private security data to provide another customer access to that data.
5. Sharing of information
We do not sell personal information. Information may be shared with service providers where necessary to operate, secure or support the service, or when disclosure is required by law.
6. Security
KvitraX applies technical and organizational safeguards intended to protect account information, authentication data and customer security data from unauthorized access, disclosure, alteration or loss.
7. Data retention
Information is retained for as long as reasonably necessary to provide the service, satisfy contractual or legal obligations, maintain security and audit records, and resolve disputes.
8. Account and data requests
Users and customer administrators may contact us to request access, correction or deletion of applicable personal information, subject to contractual, legal, security and retention requirements.
9. Changes to this policy
We may update this Privacy Policy as KvitraX evolves. Material changes will be reflected by updating the effective date on this page.
10. Contact
Privacy questions and requests can be sent to support@kvitrax.com.