Privacy Policy
510sec · Last updated 2026-09-22
1. What we collect
| Category | What | Why |
|---|---|---|
| Account | Name, email, hashed password | To give you a login and support you |
| Readiness-check leads | Name, work email, company, device description, role, stage, answers, score | To deliver your gap report and follow up about it |
| Device specifications | Components, interfaces, dataflows, dependency manifests or an SBOM you upload | To generate your pack — this is the product |
| Generated packs | The documents produced for you | So you can return and download them |
| Purchases | Order records, amounts, discount codes used | Receipts, accounting, support |
| Operational logs | Audit events (sign-in, generation, admin actions), error logs | Security and debugging |
2. What we never collect
Source code. The uploader reads dependency manifests and SBOM files only; when you upload a project ZIP it is scanned in memory for known manifest filenames and nothing else is opened or written to disk. We also do not collect payment card numbers — Square handles those and we receive only a payment status and reference.
The service is not intended to process protected health information (PHI) or patient data. Please do not enter PHI into device descriptions.
3. AI processing
Document generation is performed by a deterministic rule engine on our servers — no AI is involved. The optional "polish" feature rewrites wording only and is off by default. When it is enabled, the default backend is a local model and your text does not leave the machine. Cloud AI providers are used only if an administrator of your instance explicitly selects one; in that case threat-description text is sent to that provider. Providers are listed on the Subprocessors page.
4. How we use it
To provide and support the service, process payments, send transactional messages (verification codes, receipts), and — where you gave us your details through the readiness check — to contact you about your results and our product. You can opt out of non-essential contact at any time by replying or emailing us.
We do not sell personal information, and we do not use customer device data to train machine-learning models.
5. Retention
Account, device and pack data are retained while your account is active. Readiness-check leads are retained for up to 24 months. Order records are retained as long as tax and accounting law requires. You can request deletion at any time (section 7).
6. Sharing
Only with the subprocessors that operate the service (hosting, payments, email — see Subprocessors), and where legally compelled. No advertising networks, no data brokers.
7. Your rights
Email support@510sec.com to access, correct, export, or delete your data, or to object to processing. We honour requests from residents of any jurisdiction, regardless of whether a specific statute applies to us, and respond within 30 days.
8. International
The service is hosted in the United States. If you use it from elsewhere, your data is processed in the US.
9. Children
The service is for businesses and is not directed to anyone under 18.
10. Changes
Material changes will be announced in the application and reflected in the date above.