1. About AegisBreach
AegisBreach is a cybersecurity service being developed and operated under the AegisBreach brand by Mladen Stanković in Pirot, Serbia.
For questions about this Privacy Policy or requests concerning personal data, contact:
In this Privacy Policy, “AegisBreach”, “we”, “us”, and “our” refer to the operator of the AegisBreach service.
2. Scope of This Privacy Policy
This Privacy Policy explains how AegisBreach collects, uses, stores, shares, and protects personal data when a person:
- visits the AegisBreach website;
- creates or uses an AegisBreach account;
- creates or participates in an organization account;
- verifies a domain;
- requests or runs a security scan;
- views or downloads a scan report;
- purchases or uses package access;
- contacts AegisBreach support; or
- otherwise interacts with the service.
This policy applies to personal data processed through the AegisBreach website, application, API, account area, support channel, and related service operations.
3. Personal Data We Collect
3.1 Account and registration data
When an account is created, we may collect:
- email address;
- password, which is stored as a password hash rather than in readable form;
- full name, when provided;
- organization name, when provided;
- account status;
- organization membership and role information;
- account, organization, and membership identifiers; and
- creation and update timestamps.
3.2 Authentication and session data
We use an essential session cookie to keep users signed in and to protect authenticated access.
The current system uses an HttpOnly session cookie and server-side session records. The current session configuration may keep a session active for up to seven days, unless it expires earlier, is revoked, or the configuration is changed for operational or security reasons.
3.3 Domain and verification data
When a user adds or verifies a domain, we may collect and store:
- the domain name;
- normalized and display versions of the domain;
- domain ownership or authorization verification status;
- verification method;
- verification token;
- verification-check timestamps;
- verification-completion timestamps; and
- related organization and account identifiers.
Users must only submit domains and systems that they own or are authorized to test.
3.4 Scan and report data
When a security scan is requested or performed, we may process:
- the submitted domain;
- scan type;
- scan request parameters;
- scan status;
- technical scan inputs;
- scan findings and result data;
- scan identifiers;
- organization and domain identifiers;
- timestamps;
- generated reports; and
- PDF report downloads.
Scan findings may contain technical information about the submitted website, application, or system. Users should avoid submitting personal data or confidential information that is not necessary for the scan.
3.5 Usage, security, and technical data
To operate and protect the service, we may process:
- IP address;
- request and event timestamps;
- rate-limit information;
- authentication and security events;
- entitlement and quota events;
- scan-credit activity;
- error and diagnostic logs;
- service status information; and
- other technical information reasonably necessary to maintain security, reliability, and availability.
We do not currently use third-party behavioural analytics or advertising-tracking platforms in the initial launch version.
3.6 Package, order, and payment-related data
AegisBreach may process payment-related business records such as:
- selected package;
- order identifier;
- amount;
- currency;
- order status;
- transaction status;
- payment-provider reference;
- package-access start and end dates;
- entitlement status;
- scan-credit allocation; and
- domain-quota allocation.
The planned payment model is a one-time online card payment that provides package access for 31 days and does not automatically renew.
Live card checkout is not currently enabled.
When card payments are enabled, card details are intended to be entered in a bank-hosted or bank-controlled payment environment. AegisBreach does not intend to store:
- the full payment-card number; or
- the CVV, CVC, or other card security code.
The final payment provider and exact payment-processing disclosures will be confirmed after the relevant bank contract and technical documentation are completed.
3.7 Support communications
When a person contacts support, we may process:
- name and email address;
- account email address;
- affected domain;
- scan or report identifier;
- message content;
- screenshots or attachments voluntarily provided;
- support history; and
- information needed to investigate and resolve the request.
Users should not send passwords, session tokens, full card numbers, CVV or CVC codes, secret API keys, or other unnecessary sensitive credentials by email.
4. Data We Do Not Currently Use for Marketing Tracking
At the initial launch, AegisBreach does not intend to use:
- advertising cookies;
- Meta Pixel;
- Google Analytics;
- third-party behavioural analytics;
- cross-site marketing trackers;
- localStorage for tracking;
- sessionStorage for tracking; or
- automated marketing-email campaigns.
If this changes, this Privacy Policy and any required consent controls will be updated before the relevant technology is used.
5. Why We Process Personal Data
We may process personal data for the following purposes:
5.1 Providing the service
To:
- create and manage accounts;
- authenticate users;
- create and manage organizations and memberships;
- verify domains;
- run requested scans;
- generate and provide reports;
- manage package access, quotas, and scan credits;
- process orders and payment status;
- provide support; and
- perform actions requested before or during use of the service.
5.2 Security and abuse prevention
To:
- protect accounts and sessions;
- enforce rate limits;
- prevent unauthorized access, misuse, fraud, and malicious activity;
- investigate security events;
- preserve service integrity; and
- maintain reliable operation of the platform.
5.3 Service administration and improvement
To:
- diagnose errors;
- maintain infrastructure;
- understand operational failures;
- improve performance and reliability;
- manage entitlements and usage limits; and
- develop and improve service features without using advertising-tracking technologies.
5.4 Legal and business obligations
To:
- keep records required by accounting, tax, payment, or other applicable laws;
- respond to lawful requests from courts, authorities, or regulators;
- establish, exercise, or defend legal claims;
- investigate violations of applicable rules; and
- comply with legal obligations.
6. Legal Bases for Processing
Depending on the activity and the law that applies, AegisBreach may rely on one or more of the following legal bases:
6.1 Performance of a contract or steps requested before a contract
This may apply when processing is necessary to:
- create and administer an account;
- verify a domain;
- provide scans and reports;
- provide package access;
- process an order;
- provide requested support; or
- otherwise deliver the service requested by the user.
6.2 Legitimate interests
This may apply when processing is reasonably necessary to:
- secure the service;
- prevent fraud and abuse;
- protect accounts and infrastructure;
- enforce technical limits;
- maintain audit records;
- diagnose operational problems; and
- improve reliability.
Where legitimate interests are relied upon, AegisBreach will consider the nature of the data, the reasonable expectations of users, the purpose of the processing, and the rights and interests of the person concerned. Particular care will be taken where a user is a minor.
6.3 Legal obligations
This may apply where processing is necessary to comply with tax, accounting, payment, regulatory, court, law-enforcement, or other legal requirements.
6.4 Consent
Consent may be used where it is specifically required or voluntarily requested for an optional activity.
AegisBreach does not currently plan to rely on consent for advertising cookies or marketing-email campaigns at the initial launch.
Where processing is based on consent, that consent may be withdrawn, subject to applicable law and without affecting processing that was lawful before withdrawal.
The exact legal bases and wording in this section remain subject to external legal review.
7. Essential Cookies
AegisBreach currently uses an essential session cookie to:
- keep a user signed in;
- connect the browser to the authenticated session;
- protect account access; and
- support security controls.
The cookie is intended to be HttpOnly and configured with appropriate security attributes according to the environment.
Because this cookie is necessary for login and authenticated service functionality, disabling it may prevent account and dashboard features from working correctly.
AegisBreach does not currently use marketing or advertising cookies at the initial launch.
8. Younger Users
AegisBreach is a professional cybersecurity and project-testing service intended for entrepreneurs, developers, business users, students, and other project creators.
AegisBreach does not impose a general product minimum age and is not specifically directed at children.
Younger users may use the service for their own websites, school projects, development projects, or authorized systems, subject to applicable law.
Where applicable law requires the permission or involvement of a parent, guardian, or other legally authorized person, that permission must be obtained.
A person making a paid purchase must have the legal capacity or required authorization to complete the transaction.
AegisBreach does not currently use automatic age-verification technology.
9. How We Share Personal Data
AegisBreach does not sell personal data.
We may share personal data only where reasonably necessary with the following categories of recipients:
9.1 Hosting and infrastructure providers
Providers that support application hosting, databases, caching, storage, networking, security, monitoring, backups, and service availability.
Render is the current hosting candidate, but the final production provider and production region remain subject to infrastructure review. This policy will be updated when the production setup is confirmed.
9.2 Payment and banking providers
When online card payments are enabled, information necessary to create, verify, reconcile, and record a payment may be shared with the contracted bank, payment gateway, acquiring provider, card network, or related financial service provider.
AegisBreach does not intend to receive or store the full card number or CVV/CVC code.
9.3 Professional advisers
Accountants, lawyers, auditors, security consultants, insurers, or other professional advisers where reasonably necessary.
9.4 Authorities and legal recipients
Courts, regulators, law-enforcement authorities, tax authorities, or other recipients where disclosure is required or permitted by law.
9.5 Business restructuring
If the business is reorganized, sold, merged, financed, or transferred, relevant information may be disclosed under appropriate confidentiality and legal safeguards.
10. International Data Transfers
The final production hosting provider, region, payment provider, and supporting infrastructure are still under review.
Some service providers may process data outside Serbia or outside the country in which a user is located.
Where applicable law requires safeguards for an international transfer, AegisBreach will use an appropriate legal mechanism and will update this Privacy Policy with the relevant transfer information before relying on that arrangement for commercial production use.
11. Data Retention
AegisBreach keeps personal data only for as long as reasonably necessary for the purpose for which it was collected, including security, service delivery, dispute resolution, accounting, tax, and legal requirements.
Different categories of data may be retained for different periods.
Current confirmed or intended criteria include:
- session records may currently remain active for up to seven days unless they expire or are revoked earlier;
- account and organization data may be kept while the account is active and for a reasonable period after closure where needed for security, dispute, fraud-prevention, or legal purposes;
- domain, scan, finding, and report data may be kept while needed to provide history, reports, support, and service functionality;
- order, transaction, entitlement, and accounting data may be kept for the period required by applicable legal, accounting, tax, payment, and dispute-resolution requirements;
- security, rate-limit, and audit records may be kept for the period reasonably necessary to protect the service and investigate incidents; and
- support communications may be kept while necessary to resolve the request and maintain an appropriate record of the interaction.
Exact retention periods for each category have not yet been finalized and will be reviewed before final legal approval.
When data is no longer required, it may be deleted, anonymized, or securely isolated, subject to applicable legal and technical requirements.
12. Security
AegisBreach uses technical and organizational measures intended to protect personal data and the service.
These measures may include:
- password hashing;
- server-side sessions;
- HttpOnly session cookies;
- access controls;
- organization-level authorization boundaries;
- domain-verification controls;
- rate limiting;
- logging and audit records;
- encrypted network connections;
- restricted access to infrastructure;
- secure development and review practices; and
- backups and recovery controls where supported by the selected infrastructure.
No internet service can guarantee absolute security. Users are responsible for protecting their credentials and should immediately contact support if they believe their account or data may have been compromised.
13. Personal Data Rights
Depending on the law that applies, a person may have the right to:
- ask whether AegisBreach processes personal data about them;
- request access to and a copy of their personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing;
- request data portability where applicable;
- withdraw consent where processing is based on consent;
- receive information about relevant data processing; and
- submit a complaint to a competent data-protection authority.
These rights may be subject to legal conditions, exceptions, identity verification, and record-retention obligations.
14. How to Submit a Privacy Request
Privacy requests should be sent to:
The request should clearly describe what the person is asking AegisBreach to do.
AegisBreach currently handles privacy requests manually by an authorized person. There is no automated privacy-request portal or automatic account-deletion button at the initial launch.
To protect users and prevent unauthorized disclosure or deletion, AegisBreach may request reasonable additional information when necessary to verify identity or authority.
AegisBreach will respond within the period required by applicable law. Under Serbian data-protection law, information about action taken on a request is generally provided within 30 days, subject to a legally permitted extension where the request is complex or numerous.
15. Account and Data Deletion
A user may request account or personal-data deletion by emailing:
Deletion is currently reviewed and handled manually.
Before deleting data, AegisBreach may:
- verify the identity of the requester;
- confirm the account or organization concerned;
- identify data that must be retained for legal, accounting, security, payment, fraud-prevention, or dispute purposes;
- restrict access while the request is reviewed; and
- explain any lawful reason why certain data cannot be deleted immediately.
Deleting an account may remove access to scan history, reports, domains, package access, and other account features.
16. Third-Party Links and Scanned Systems
The service may contain links to third-party websites or may scan publicly accessible technical properties of domains submitted by users.
AegisBreach does not control the privacy practices of unrelated third-party websites.
Users are responsible for ensuring that they are authorized to submit a domain, website, application, or system for scanning.
17. Changes to This Privacy Policy
AegisBreach may update this Privacy Policy when:
- the service changes;
- new data-processing activities are introduced;
- the production infrastructure is finalized or changed;
- a payment provider is contracted;
- business registration details become available;
- legal or regulatory requirements change; or
- external legal review requires changes.
The updated version will show a revised “Last updated” date.
Material changes may also be communicated through the website, account area, or another appropriate channel.
18. Contact and Complaints
For privacy questions or requests:
A person may also have the right to submit a complaint to the data-protection authority responsible for their location or the processing concerned.
For matters governed by Serbian data-protection law, the competent supervisory authority is the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia.