Privacy Policy
Effective date: May 30, 2026 · Last updated: May 30, 2026
1. Overview
This Privacy Policy explains how PentestForge collects, uses, stores, protects, shares, and deletes personal data and other information when you access or use our website, platform, APIs, dashboards, paid services, free services, support channels, and related functionality.
This Privacy Policy applies to:
- visitors of the PentestForge website;
- registered users of the PentestForge platform;
- customers who purchase subscriptions, scan credits, AI resources, or other paid services;
- users who initiate vulnerability scans, use Deep Pentest AI, generate reports, or interact with our support team.
By using PentestForge, you acknowledge that your information will be processed as described in this Privacy Policy.
If you do not agree with this Privacy Policy, you must not use the website, platform, or services.
2. Who We Are
Provider: PentestForge
Website: https://pentest-forge.com
Support: [email protected]
Privacy contact: [email protected]
Legal contact: [email protected]
For the purposes of this Privacy Policy, PentestForge may act as a data controller for account, billing, support, security, and platform usage data.
In some cases, where a customer uploads, scans, or processes data relating to third-party systems, PentestForge may act as a service provider or processor acting on the customer's instructions, subject to applicable law and contractual terms.
3. Definitions
For the purposes of this Privacy Policy:
Platform means the PentestForge website, application, APIs, dashboards, infrastructure, and related systems.
Services means vulnerability scanning, penetration-testing assistance, AI-powered triage, security assessment, report generation, asset management, and related digital services.
User, Customer, you, or your means any person or entity accessing or using the Platform or Services.
Personal Data means information that identifies, relates to, or can reasonably be linked to an identifiable individual.
Account Data means information used to create, access, secure, or manage your PentestForge account.
Payment Data means payment-related information processed in connection with purchases, subscriptions, refunds, invoices, disputes, and payment confirmations.
Scan Data means domains, IP addresses, URLs, API endpoints, CIDR ranges, scan configuration, scan metadata, vulnerability findings, generated reports, timestamps, and related technical information.
Deep Pentest AI Data means prompts, inputs, outputs, validation results, AI-generated analysis, AI usage metadata, token usage, AI minutes, and related system logs.
Usage Data means information about how you interact with the website, Platform, features, APIs, scans, reports, dashboards, and support channels.
Cookies means small files or similar technologies stored on your device for authentication, security, analytics, preferences, or functionality.
4. Information We Collect
We collect different categories of information depending on how you use PentestForge.
4.1. Account Data
When you create or manage an account, we may collect:
- name or display name;
- email address;
- password hash;
- account ID;
- organization or company name, if provided;
- billing profile information;
- user role and permissions;
- account settings;
- authentication and session data;
- two-factor authentication status, if enabled;
- API keys or access tokens generated for your account;
- account creation date and activity status.
We do not store your plain-text password.
4.2. Contact and Support Data
When you contact us, we may collect:
- your name;
- email address;
- message content;
- support request details;
- attachments you provide;
- technical logs you choose to share;
- communication history;
- issue resolution status;
- timestamps of correspondence.
4.3. Payment and Billing Data
When you purchase Services, subscribe to a paid plan, request a refund, or interact with payment-related features, we may process:
- account email;
- payment amount;
- currency;
- payment date;
- payment status;
- subscription status;
- invoice ID;
- order ID;
- transaction reference;
- payment provider reference;
- refund status;
- chargeback or dispute status;
- billing country or region, where applicable;
- limited payment method metadata, such as card brand, last four digits, and expiration date, where made available by the payment provider;
- fiscal receipt or payment confirmation metadata, where applicable.
Payments may be processed by third-party payment providers, including Stripe and Monobank acquiring / plata by mono.
We do not store full card numbers, CVV codes, or complete payment card authentication data. Such information is processed by the relevant payment provider.
4.4. Monobank Acquiring / plata by mono Data
When payments are processed through Monobank acquiring / plata by mono, payment data may be processed by АТ «Універсал Банк» and related payment infrastructure.
Depending on the transaction, this may include:
- payment amount;
- payment currency;
- transaction status;
- invoice or payment reference;
- customer email, if provided;
- payment confirmation or fiscal receipt metadata;
- refund status;
- chargeback or dispute-related information;
- technical payment callbacks or webhook data.
We use this data to confirm payments, activate Services, issue refunds, process accounting records, prevent fraud, and resolve payment disputes.
4.5. Stripe Data
When payments are processed through Stripe, payment data is processed by Stripe according to Stripe's own terms and privacy documentation.
Depending on the transaction, Stripe may process:
- payment method information;
- transaction amount;
- transaction date;
- payment status;
- subscription status;
- refund or chargeback information;
- billing information;
- tax information, where applicable;
- fraud prevention data;
- support or dispute-related information.
We receive only the payment data required to provide the Services, confirm payment, manage subscriptions, process refunds, handle disputes, and comply with accounting and legal obligations.
4.6. Scan Data
When you add an asset, start a scan, generate a report, or use security assessment features, we may collect and process:
- domains;
- subdomains;
- IP addresses;
- CIDR ranges;
- URLs;
- API endpoints;
- ports and services detected;
- scan configuration;
- scan start and end times;
- scan status;
- vulnerability findings;
- severity ratings;
- evidence collected during scans;
- screenshots or technical artifacts, where generated;
- generated reports;
- remediation recommendations;
- report exports;
- scan logs;
- asset ownership or authorization metadata;
- proof of authorization, if requested.
You are responsible for ensuring that you have proper authorization to scan any asset submitted to the Platform.
4.7. Deep Pentest AI Data
When you use Deep Pentest AI or other AI-powered features, we may process:
- AI prompts;
- scan findings sent to AI features;
- AI-generated analysis;
- validation results;
- exploitability reasoning within permitted boundaries;
- report drafts;
- remediation suggestions;
- token usage;
- AI minutes;
- AI output timestamps;
- AI system logs;
- abuse detection metadata.
Deep Pentest AI outputs may contain technical information about vulnerabilities, systems, endpoints, and remediation steps. You should not submit sensitive secrets, passwords, private keys, personal data, or confidential third-party information unless strictly necessary and legally permitted.
4.8. Technical and Security Logs
For security, fraud prevention, diagnostics, abuse prevention, and service operation, we may collect:
- IP address;
- user agent;
- browser type;
- operating system;
- device type;
- approximate location based on IP address;
- login timestamps;
- failed login attempts;
- session identifiers;
- API request logs;
- rate-limit events;
- error logs;
- audit logs;
- security alerts;
- abuse detection signals;
- access logs;
- system performance metrics.
4.9. Website Usage and Analytics Data
When you visit our website or use the Platform, we may collect:
- pages viewed;
- referral source;
- links clicked;
- time spent on pages;
- feature usage;
- conversion events;
- device and browser information;
- cookie identifiers;
- analytics events;
- approximate geographic region.
We use this data to improve the Platform, understand product usage, detect abuse, measure performance, and improve user experience.
4.10. Data You Choose to Provide
You may choose to provide additional information, including:
- company details;
- tax or billing details;
- comments;
- files;
- screenshots;
- vulnerability descriptions;
- support attachments;
- security authorization documents;
- feedback;
- survey responses.
You should not provide unnecessary personal data, sensitive personal data, passwords, secrets, private keys, or confidential third-party information.
5. Information We Do Not Intentionally Collect
We do not intentionally request or require you to provide:
- government-issued identification documents, unless required for a specific legal, fraud, payment, or compliance reason;
- full payment card numbers;
- CVV codes;
- bank login credentials;
- passwords for third-party systems;
- private cryptographic keys;
- unnecessary sensitive personal data;
- health data;
- biometric data;
- information about children.
PentestForge is not intended for use by children. If we become aware that we have collected personal data from a child without proper legal basis, we will take reasonable steps to delete it.
6. How We Use Information
We use collected information for the following purposes:
6.1. To Provide the Services
We use data to:
- create and manage accounts;
- authenticate users;
- provide access to paid and free features;
- process scans;
- generate reports;
- provide Deep Pentest AI functionality;
- display dashboards;
- manage assets;
- store scan history;
- provide downloads and exports;
- manage API access;
- provide technical support.
6.2. To Process Payments and Subscriptions
We use payment and billing data to:
- process purchases;
- activate subscriptions;
- confirm payments;
- manage renewals;
- issue invoices or receipts;
- process refunds;
- handle chargebacks;
- prevent payment fraud;
- comply with accounting and tax obligations.
6.3. To Ensure Security and Prevent Abuse
We use data to:
- detect unauthorized access;
- prevent account takeover;
- detect suspicious activity;
- prevent unauthorized scanning;
- detect abusive usage;
- enforce rate limits;
- investigate security incidents;
- protect the Platform and other users;
- comply with security obligations.
6.4. To Communicate With You
We may use your contact data to:
- send account notifications;
- send payment confirmations;
- send subscription updates;
- respond to support requests;
- send security alerts;
- notify about material changes to legal documents;
- notify about service availability or maintenance;
- send administrative messages.
6.5. To Improve the Platform
We may use data to:
- debug errors;
- analyze feature usage;
- improve scan accuracy;
- improve AI-assisted analysis;
- improve performance;
- improve user experience;
- develop new functionality;
- measure service reliability.
6.6. To Comply With Legal Obligations
We may use data to:
- comply with tax and accounting rules;
- respond to lawful requests;
- resolve legal claims;
- enforce contracts;
- prevent fraud;
- comply with sanctions, cybersecurity, payment, and consumer protection rules;
- keep records required by law.
7. Legal Bases for Processing
Where applicable, we process personal data under one or more of the following legal bases:
7.1. Performance of a Contract
We process data when necessary to provide the Services, manage accounts, process payments, provide support, generate reports, and fulfill our obligations under the Public Offer Agreement, Terms of Service, Refund Policy, and related agreements.
7.2. Legitimate Interests
We process data based on legitimate interests, including:
- securing the Platform;
- preventing fraud and abuse;
- preventing unauthorized scanning;
- improving the Services;
- debugging and diagnostics;
- enforcing legal terms;
- resolving disputes;
- protecting our rights and the rights of users.
7.3. Legal Obligation
We process data where required for:
- tax compliance;
- accounting;
- payment records;
- legal claims;
- regulatory compliance;
- lawful government or court requests.
7.4. Consent
We may rely on consent for:
- non-essential cookies;
- optional marketing communications;
- optional analytics where required;
- certain data processing activities where consent is legally required.
You may withdraw consent where applicable.
7.5. Vital or Public Interest
In rare cases, we may process information where necessary to protect users, third parties, infrastructure, or the public from serious cybersecurity threats, abuse, fraud, or illegal activity.
8. Cookies and Similar Technologies
We may use cookies, local storage, pixels, tags, and similar technologies for:
- authentication;
- session management;
- security;
- fraud prevention;
- remembering preferences;
- analytics;
- performance monitoring;
- product improvement;
- payment flow functionality;
- marketing, where applicable and consented to.
8.1. Essential Cookies
Essential cookies are required for login, account security, payment flow, fraud prevention, and basic Platform functionality. These cookies cannot be disabled through our systems because the Services may not work without them.
8.2. Analytics Cookies
Analytics cookies help us understand how users interact with the website and Platform. Where required by law, we use analytics cookies only with your consent.
8.3. Marketing Cookies
Marketing cookies may be used to measure campaigns or show relevant content. Where required by law, marketing cookies are used only with your consent.
8.4. Cookie Controls
You can manage cookies through your browser settings. Disabling some cookies may affect Platform functionality, authentication, payments, or security features.
9. How We Share Information
We do not sell your personal data.
We may share information with the following categories of recipients where necessary.
9.1. Payment Providers
We share payment-related information with payment providers, including Stripe and Monobank acquiring / plata by mono, to process payments, subscriptions, refunds, fraud checks, disputes, and chargebacks.
9.2. Hosting and Infrastructure Providers
We may use third-party infrastructure providers to host the website, Platform, databases, logs, storage, backups, APIs, and security systems.
9.3. AI and Security Service Providers
We may use AI, security, logging, monitoring, vulnerability analysis, abuse detection, or infrastructure providers to support Platform functionality, Deep Pentest AI, security operations, and diagnostics.
Where possible, we limit the data shared with such providers to what is necessary for the relevant service.
9.4. Email and Communication Providers
We may share contact information with email, support, and notification providers to send transactional emails, support replies, payment confirmations, service notices, and security alerts.
9.5. Analytics Providers
We may share limited website and usage data with analytics providers to understand and improve the Platform, subject to applicable consent requirements.
9.6. Legal, Accounting, and Compliance Providers
We may share information with lawyers, accountants, auditors, tax advisors, compliance consultants, and other professional advisors where necessary.
9.7. Banks, Card Networks, and Dispute Participants
In case of refunds, chargebacks, payment disputes, fraud investigations, or unauthorized payment claims, we may share:
- payment records;
- account activity;
- usage logs;
- scan activity;
- generated report records;
- IP logs;
- support communications;
- subscription status;
- refund records.
9.8. Authorities and Legal Requests
We may disclose information where required by law, court order, government request, regulatory obligation, or to protect rights, safety, infrastructure, users, or the public from illegal or harmful activity.
9.9. Business Transfers
If PentestForge is involved in a merger, acquisition, restructuring, financing, sale of assets, or transfer of business, information may be transferred as part of that transaction, subject to appropriate confidentiality and legal safeguards.
10. International Data Transfers
PentestForge may use service providers located in different countries. As a result, your information may be processed outside your country of residence.
Where required by applicable law, we use appropriate safeguards for international transfers, such as:
- contractual protections;
- data processing agreements;
- standard contractual clauses;
- technical and organizational security measures;
- access restrictions;
- encryption where appropriate.
By using the Services, you understand that your data may be processed in countries where data protection laws may differ from those in your country.
11. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law, accounting rules, tax rules, dispute resolution, security, fraud prevention, or legal claims.
11.1. Account Data
Account data is retained while your account is active and for a reasonable period after account closure, unless deletion is requested and legally permitted.
11.2. Scan Data and Reports
Scan results, reports, and related technical data may be retained for up to 90 days after subscription expiry, account inactivity, or cancellation, unless:
- you delete the data earlier;
- a longer retention period is required for legal, security, fraud prevention, or dispute resolution purposes;
- the data is anonymized or aggregated;
- another retention period is specified in your plan or agreement.
11.3. Payment and Billing Data
Payment, invoice, refund, chargeback, and accounting records may be retained for the period required by tax, accounting, payment, fraud prevention, and legal rules.
11.4. Security Logs
Security logs, access logs, API logs, and abuse prevention records may be retained for a reasonable period necessary to detect, investigate, and prevent security incidents, unauthorized scanning, fraud, and abuse.
11.5. Support Communications
Support communications may be retained to provide customer service, resolve disputes, improve support quality, and maintain legal records.
11.6. Backups
Deleted data may remain in encrypted or protected backups for a limited period until the backup is overwritten or deleted according to our backup lifecycle.
12. Data Deletion
You may request deletion of your account or personal data by contacting:
We will delete or anonymize your personal data where required and technically feasible, unless retention is necessary for:
- payment records;
- invoices;
- tax or accounting obligations;
- fraud prevention;
- security investigations;
- dispute resolution;
- legal claims;
- compliance with law;
- enforcement of our agreements;
- prevention of unauthorized scanning or abuse.
Deleting your account may result in permanent loss of access to scan history, reports, credits, AI resources, settings, and other account data.
13. Your Rights
Depending on your location and applicable law, you may have the following rights:
13.1. Right of Access
You may request confirmation of whether we process your personal data and request a copy of that data.
13.2. Right to Rectification
You may request correction of inaccurate or incomplete personal data.
13.3. Right to Deletion
You may request deletion of your personal data, subject to legal, security, payment, accounting, and contractual retention requirements.
13.4. Right to Restriction
You may request restriction of processing in certain circumstances.
13.5. Right to Object
You may object to certain processing based on legitimate interests, including certain analytics or marketing processing.
13.6. Right to Data Portability
You may request a copy of certain personal data in a structured, commonly used, machine-readable format, where applicable.
13.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.
13.8. Right to Complain
You may have the right to lodge a complaint with a competent data protection or consumer protection authority.
To exercise your rights, contact:
We may need to verify your identity before processing your request.
14. Security Measures
We use reasonable technical and organizational measures to protect information, including:
- encryption in transit where appropriate;
- access controls;
- authentication controls;
- password hashing;
- audit logs;
- rate limits;
- abuse detection;
- monitoring;
- network security controls;
- least-privilege access;
- restricted administrative access;
- backup protection;
- vulnerability management;
- incident response procedures.
No system is completely secure. We cannot guarantee absolute security of data transmitted or stored through the Platform.
You are responsible for:
- using a strong password;
- keeping credentials confidential;
- protecting API keys;
- enabling available security features;
- restricting access to your account;
- ensuring that only authorized users access your organization account;
- promptly notifying us of suspected unauthorized access.
15. Security Incident Response
If we become aware of a security incident affecting personal data, we will take reasonable steps to:
- investigate the incident;
- contain and mitigate the issue;
- assess the affected data;
- restore service security;
- notify affected users or authorities where required by law;
- improve controls to reduce future risk.
Notifications may be sent by email, in-account notice, website notice, or other reasonable means.
16. Customer Responsibilities for Scan Data
PentestForge is a security testing platform. The Customer is responsible for ensuring that any Scan Data submitted to the Platform is lawful and authorized.
The Customer must not submit or process:
- assets without authorization;
- stolen data;
- illegally obtained data;
- unnecessary personal data;
- credentials that are not required for the Service;
- secrets, tokens, private keys, or passwords unless strictly necessary and legally permitted;
- third-party confidential data without permission.
If Scan Data includes personal data or third-party confidential information, the Customer is responsible for having the required legal basis, permissions, notices, and safeguards.
17. AI Processing
Deep Pentest AI and other AI-powered features may process Scan Data, prompts, findings, reports, and technical context to generate analysis, validation, remediation suggestions, and other outputs.
We may use AI-related data to:
- provide AI-powered functionality;
- generate security reports;
- validate findings;
- improve output quality;
- prevent abuse;
- detect unsafe or unauthorized use;
- monitor performance;
- debug errors.
Unless otherwise stated in a separate agreement, you should not submit sensitive personal data, secrets, passwords, private keys, confidential third-party data, or regulated data to AI features.
AI outputs may be inaccurate, incomplete, or contain false positives or false negatives. You are responsible for reviewing and validating outputs before relying on them.
18. Marketing Communications
We may send marketing communications only where permitted by law or with your consent where required.
You may unsubscribe from marketing emails using the unsubscribe link in the email or by contacting:
Transactional emails, security alerts, payment confirmations, legal notices, and service-related messages are not marketing communications and may still be sent when necessary.
19. Do Not Track
Some browsers provide “Do Not Track” signals. Because there is no uniform industry standard for responding to these signals, we may not respond to them in a specific way.
You can control cookies and tracking technologies through browser settings and, where available, our cookie preferences tools.
20. Third-Party Links
The website or Platform may contain links to third-party websites, services, payment pages, documentation, or integrations.
We are not responsible for the privacy practices, security, content, or policies of third parties. You should review their privacy policies before providing information to them.
21. Data of Business Customers and Team Members
If you use PentestForge on behalf of an organization, your organization may control access to your account, scans, reports, billing, and related data.
Organization administrators may be able to:
- add or remove team members;
- view account activity;
- view scan history;
- access reports;
- manage billing;
- manage assets;
- manage API keys;
- configure security settings.
If your account is managed by an organization, direct privacy requests relating to organization-controlled data may need to be handled through that organization.
22. Payment Disputes and Chargebacks
If you initiate a payment dispute, chargeback, refund request, or bank investigation, we may process and share relevant information with payment providers, banks, card networks, dispute processors, legal advisors, and competent authorities.
This information may include:
- account information;
- payment records;
- subscription status;
- refund history;
- scan usage;
- AI resource usage;
- generated report records;
- login logs;
- IP logs;
- support communications;
- acceptance of legal terms.
We process this data to defend against fraud, resolve disputes, comply with payment provider rules, and enforce our agreements.
23. Fraud, Abuse, and Unauthorized Use
We may process account, technical, payment, and usage data to detect and prevent:
- unauthorized scanning;
- fraudulent payments;
- chargeback abuse;
- account takeover;
- credential misuse;
- API abuse;
- excessive automated traffic;
- attempts to bypass billing or usage limits;
- violations of Terms of Service;
- illegal or harmful activity.
If we detect abuse or unauthorized use, we may suspend or terminate access and preserve relevant records for investigation, dispute resolution, legal compliance, or enforcement.
24. Aggregated and Anonymized Data
We may create aggregated or anonymized data that does not reasonably identify you.
We may use such data for:
- analytics;
- product improvement;
- benchmarking;
- security research;
- service performance monitoring;
- business reporting;
- public statistics;
- model and detection improvement.
Aggregated or anonymized data is not treated as personal data where it cannot reasonably identify an individual.
25. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we may notify you by:
- email;
- in-account notice;
- website notice;
- other reasonable means.
The updated Privacy Policy becomes effective on the date stated as “Last updated” unless otherwise specified.
Your continued use of the Platform after the updated Privacy Policy becomes effective means that you acknowledge the updated terms.
26. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or how your data is processed, contact us at:
Privacy: [email protected]
Support: [email protected]
Legal: [email protected]
Website: https://pentest-forge.com
