Privacy

Privacy Policy

This policy explains how VefaSec protects data processed through the client area, package-based security measurement, ownership verification, report delivery and contact flows.

Last updated: May 17, 2026

Data categories

Account data: full name, email, phone, password hash, session records and verification timestamps.

Website and scope data: domain, DNS/meta verification status, package selection, advanced test permissions, billing/commercial details and operation notes.

Report and tracking data: report URL, access duration, report email delivery records, customer action notes and panel activity history.

Technical security records: IP, device/browser signals, rate-limit records, error logs and system logs required to investigate security events.

Purposes

Creating accounts, verifying phone numbers and providing secure access to the client panel.

Verifying website ownership, managing authorized measurement scope and forwarding package purchase requests to operations.

Planning security measurement, delivering reports, managing post-report action tracking and communicating with customers.

Preventing abuse, unauthorized access, fraudulent requests and security incidents.

Service providers

Third-party providers may be used for SMS verification, email delivery, hosting, database, security monitoring and payment infrastructure.

When Shopier is enabled, payment and commercial approval data may be processed under payment infrastructure requirements.

For security reasons, report links are not shared directly in email; access is handled through the client panel.

Retention and security

Data is retained while the service relationship, legal obligations, security evidence or operational need continues.

Account, request, report and admin activity records are protected with access control, secure sessions, CSRF checks, rate limits and audit logs.

Report links may be time-limited; the access duration set in the admin panel is shown in the client panel.