Skip to main content

Privacy Policy

Last updated: 2026 · GuardianX

1. Data We Collect

  • • Account: name, email, password (bcrypt-hashed)
  • • Client data: company name, target URLs, source code (for SAST)
  • • Scan results: vulnerabilities, HTTP evidence, generated patches
  • • Credentials: Git tokens (AES-256-GCM encrypted, never displayed)

2. Data Security

  • • AES-256-GCM encryption for credentials
  • • TLS 1.3 in transit · bcrypt hashing · JWT auth
  • • 2FA (TOTP) available · Rate limiting
  • • SHA-256 hash-chained attestation ledger

3. Your Rights (DPDPA 2023)

  • • Access, correction, erasure, portability
  • • Objection to AI model training
  • • Breach notification within 72 hours

4. Contact

For privacy concerns: hello@guardianx.in