Privacy Policy

510sec · Last updated 2026-09-22

The short version. We never read your source code. Your device specification is used only to generate your documents. We do not sell your data, we do not use it to train models, and AI polish runs on a local model by default — cloud AI is off unless you switch it on.

1. What we collect

CategoryWhatWhy
AccountName, email, hashed passwordTo give you a login and support you
Readiness-check leadsName, work email, company, device description, role, stage, answers, scoreTo deliver your gap report and follow up about it
Device specificationsComponents, interfaces, dataflows, dependency manifests or an SBOM you uploadTo generate your pack — this is the product
Generated packsThe documents produced for youSo you can return and download them
PurchasesOrder records, amounts, discount codes usedReceipts, accounting, support
Operational logsAudit events (sign-in, generation, admin actions), error logsSecurity and debugging

2. What we never collect

Source code. The uploader reads dependency manifests and SBOM files only; when you upload a project ZIP it is scanned in memory for known manifest filenames and nothing else is opened or written to disk. We also do not collect payment card numbers — Square handles those and we receive only a payment status and reference.

The service is not intended to process protected health information (PHI) or patient data. Please do not enter PHI into device descriptions.

3. AI processing

Document generation is performed by a deterministic rule engine on our servers — no AI is involved. The optional "polish" feature rewrites wording only and is off by default. When it is enabled, the default backend is a local model and your text does not leave the machine. Cloud AI providers are used only if an administrator of your instance explicitly selects one; in that case threat-description text is sent to that provider. Providers are listed on the Subprocessors page.

4. How we use it

To provide and support the service, process payments, send transactional messages (verification codes, receipts), and — where you gave us your details through the readiness check — to contact you about your results and our product. You can opt out of non-essential contact at any time by replying or emailing us.

We do not sell personal information, and we do not use customer device data to train machine-learning models.

5. Retention

Account, device and pack data are retained while your account is active. Readiness-check leads are retained for up to 24 months. Order records are retained as long as tax and accounting law requires. You can request deletion at any time (section 7).

6. Sharing

Only with the subprocessors that operate the service (hosting, payments, email — see Subprocessors), and where legally compelled. No advertising networks, no data brokers.

7. Your rights

Email support@510sec.com to access, correct, export, or delete your data, or to object to processing. We honour requests from residents of any jurisdiction, regardless of whether a specific statute applies to us, and respond within 30 days.

8. International

The service is hosted in the United States. If you use it from elsewhere, your data is processed in the US.

9. Children

The service is for businesses and is not directed to anyone under 18.

10. Changes

Material changes will be announced in the application and reflected in the date above.