aegisbreach
Free ScanPricingAboutBlogSign in
Run free scan

On this page

  1. 1. About AegisBreach
  2. 2. Scope of This Privacy Policy
  3. 3. Personal Data We Collect
  4. 4. Data We Do Not Currently Use for Marketing Tracking
  5. 5. Why We Process Personal Data
  6. 6. Legal Bases for Processing
  7. 7. Essential Cookies
  8. 8. Younger Users
  9. 9. How We Share Personal Data
  10. 10. International Data Transfers
  11. 11. Data Retention
  12. 12. Security
  13. 13. Personal Data Rights
  14. 14. How to Submit a Privacy Request
  15. 15. Account and Data Deletion
  16. 16. Third-Party Links and Scanned Systems
  17. 17. Changes to This Privacy Policy
  18. 18. Contact and Complaints
On this page
  1. 1. About AegisBreach
  2. 2. Scope of This Privacy Policy
  3. 3. Personal Data We Collect
  4. 4. Data We Do Not Currently Use for Marketing Tracking
  5. 5. Why We Process Personal Data
  6. 6. Legal Bases for Processing
  7. 7. Essential Cookies
  8. 8. Younger Users
  9. 9. How We Share Personal Data
  10. 10. International Data Transfers
  11. 11. Data Retention
  12. 12. Security
  13. 13. Personal Data Rights
  14. 14. How to Submit a Privacy Request
  15. 15. Account and Data Deletion
  16. 16. Third-Party Links and Scanned Systems
  17. 17. Changes to This Privacy Policy
  18. 18. Contact and Complaints

Legal

Privacy Policy

Draft — Pending Legal Review

Last updated: 24 July 2026

This Privacy Policy is a working draft published for transparency while AegisBreach completes business registration, production infrastructure review, payment-provider contracting, and external legal review.

Important notice

Draft publication status

This page reflects the current working draft. It does not represent final legal approval.

This Privacy Policy is a working draft published for transparency while AegisBreach completes business registration, production infrastructure review, payment-provider contracting, and external legal review.

The registered business name, registered address, registration number, tax identification number, final production hosting details, and final payment-provider disclosures will be added or confirmed before the commercial paid launch.

This draft does not represent final legal approval.

Policy document

AegisBreach Privacy Policy

The full draft text below describes how personal data is collected, used, stored, shared, and protected.

1. About AegisBreach

AegisBreach is a cybersecurity service being developed and operated under the AegisBreach brand by Mladen Stanković in Pirot, Serbia.

For questions about this Privacy Policy or requests concerning personal data, contact:

support@aegisbreach.com

In this Privacy Policy, “AegisBreach”, “we”, “us”, and “our” refer to the operator of the AegisBreach service.

2. Scope of This Privacy Policy

This Privacy Policy explains how AegisBreach collects, uses, stores, shares, and protects personal data when a person:

  • visits the AegisBreach website;
  • creates or uses an AegisBreach account;
  • creates or participates in an organization account;
  • verifies a domain;
  • requests or runs a security scan;
  • views or downloads a scan report;
  • purchases or uses package access;
  • contacts AegisBreach support; or
  • otherwise interacts with the service.

This policy applies to personal data processed through the AegisBreach website, application, API, account area, support channel, and related service operations.

3. Personal Data We Collect

3.1 Account and registration data

When an account is created, we may collect:

  • email address;
  • password, which is stored as a password hash rather than in readable form;
  • full name, when provided;
  • organization name, when provided;
  • account status;
  • organization membership and role information;
  • account, organization, and membership identifiers; and
  • creation and update timestamps.

3.2 Authentication and session data

We use an essential session cookie to keep users signed in and to protect authenticated access.

The current system uses an HttpOnly session cookie and server-side session records. The current session configuration may keep a session active for up to seven days, unless it expires earlier, is revoked, or the configuration is changed for operational or security reasons.

3.3 Domain and verification data

When a user adds or verifies a domain, we may collect and store:

  • the domain name;
  • normalized and display versions of the domain;
  • domain ownership or authorization verification status;
  • verification method;
  • verification token;
  • verification-check timestamps;
  • verification-completion timestamps; and
  • related organization and account identifiers.

Users must only submit domains and systems that they own or are authorized to test.

3.4 Scan and report data

When a security scan is requested or performed, we may process:

  • the submitted domain;
  • scan type;
  • scan request parameters;
  • scan status;
  • technical scan inputs;
  • scan findings and result data;
  • scan identifiers;
  • organization and domain identifiers;
  • timestamps;
  • generated reports; and
  • PDF report downloads.

Scan findings may contain technical information about the submitted website, application, or system. Users should avoid submitting personal data or confidential information that is not necessary for the scan.

3.5 Usage, security, and technical data

To operate and protect the service, we may process:

  • IP address;
  • request and event timestamps;
  • rate-limit information;
  • authentication and security events;
  • entitlement and quota events;
  • scan-credit activity;
  • error and diagnostic logs;
  • service status information; and
  • other technical information reasonably necessary to maintain security, reliability, and availability.

We do not currently use third-party behavioural analytics or advertising-tracking platforms in the initial launch version.

3.6 Package, order, and payment-related data

AegisBreach may process payment-related business records such as:

  • selected package;
  • order identifier;
  • amount;
  • currency;
  • order status;
  • transaction status;
  • payment-provider reference;
  • package-access start and end dates;
  • entitlement status;
  • scan-credit allocation; and
  • domain-quota allocation.

The planned payment model is a one-time online card payment that provides package access for 31 days and does not automatically renew.

Live card checkout is not currently enabled.

When card payments are enabled, card details are intended to be entered in a bank-hosted or bank-controlled payment environment. AegisBreach does not intend to store:

  • the full payment-card number; or
  • the CVV, CVC, or other card security code.

The final payment provider and exact payment-processing disclosures will be confirmed after the relevant bank contract and technical documentation are completed.

3.7 Support communications

When a person contacts support, we may process:

  • name and email address;
  • account email address;
  • affected domain;
  • scan or report identifier;
  • message content;
  • screenshots or attachments voluntarily provided;
  • support history; and
  • information needed to investigate and resolve the request.

Users should not send passwords, session tokens, full card numbers, CVV or CVC codes, secret API keys, or other unnecessary sensitive credentials by email.

4. Data We Do Not Currently Use for Marketing Tracking

At the initial launch, AegisBreach does not intend to use:

  • advertising cookies;
  • Meta Pixel;
  • Google Analytics;
  • third-party behavioural analytics;
  • cross-site marketing trackers;
  • localStorage for tracking;
  • sessionStorage for tracking; or
  • automated marketing-email campaigns.

If this changes, this Privacy Policy and any required consent controls will be updated before the relevant technology is used.

5. Why We Process Personal Data

We may process personal data for the following purposes:

5.1 Providing the service

To:

  • create and manage accounts;
  • authenticate users;
  • create and manage organizations and memberships;
  • verify domains;
  • run requested scans;
  • generate and provide reports;
  • manage package access, quotas, and scan credits;
  • process orders and payment status;
  • provide support; and
  • perform actions requested before or during use of the service.

5.2 Security and abuse prevention

To:

  • protect accounts and sessions;
  • enforce rate limits;
  • prevent unauthorized access, misuse, fraud, and malicious activity;
  • investigate security events;
  • preserve service integrity; and
  • maintain reliable operation of the platform.

5.3 Service administration and improvement

To:

  • diagnose errors;
  • maintain infrastructure;
  • understand operational failures;
  • improve performance and reliability;
  • manage entitlements and usage limits; and
  • develop and improve service features without using advertising-tracking technologies.

5.4 Legal and business obligations

To:

  • keep records required by accounting, tax, payment, or other applicable laws;
  • respond to lawful requests from courts, authorities, or regulators;
  • establish, exercise, or defend legal claims;
  • investigate violations of applicable rules; and
  • comply with legal obligations.

6. Legal Bases for Processing

Depending on the activity and the law that applies, AegisBreach may rely on one or more of the following legal bases:

6.1 Performance of a contract or steps requested before a contract

This may apply when processing is necessary to:

  • create and administer an account;
  • verify a domain;
  • provide scans and reports;
  • provide package access;
  • process an order;
  • provide requested support; or
  • otherwise deliver the service requested by the user.

6.2 Legitimate interests

This may apply when processing is reasonably necessary to:

  • secure the service;
  • prevent fraud and abuse;
  • protect accounts and infrastructure;
  • enforce technical limits;
  • maintain audit records;
  • diagnose operational problems; and
  • improve reliability.

Where legitimate interests are relied upon, AegisBreach will consider the nature of the data, the reasonable expectations of users, the purpose of the processing, and the rights and interests of the person concerned. Particular care will be taken where a user is a minor.

6.3 Legal obligations

This may apply where processing is necessary to comply with tax, accounting, payment, regulatory, court, law-enforcement, or other legal requirements.

6.4 Consent

Consent may be used where it is specifically required or voluntarily requested for an optional activity.

AegisBreach does not currently plan to rely on consent for advertising cookies or marketing-email campaigns at the initial launch.

Where processing is based on consent, that consent may be withdrawn, subject to applicable law and without affecting processing that was lawful before withdrawal.

The exact legal bases and wording in this section remain subject to external legal review.

7. Essential Cookies

AegisBreach currently uses an essential session cookie to:

  • keep a user signed in;
  • connect the browser to the authenticated session;
  • protect account access; and
  • support security controls.

The cookie is intended to be HttpOnly and configured with appropriate security attributes according to the environment.

Because this cookie is necessary for login and authenticated service functionality, disabling it may prevent account and dashboard features from working correctly.

AegisBreach does not currently use marketing or advertising cookies at the initial launch.

8. Younger Users

AegisBreach is a professional cybersecurity and project-testing service intended for entrepreneurs, developers, business users, students, and other project creators.

AegisBreach does not impose a general product minimum age and is not specifically directed at children.

Younger users may use the service for their own websites, school projects, development projects, or authorized systems, subject to applicable law.

Where applicable law requires the permission or involvement of a parent, guardian, or other legally authorized person, that permission must be obtained.

A person making a paid purchase must have the legal capacity or required authorization to complete the transaction.

AegisBreach does not currently use automatic age-verification technology.

9. How We Share Personal Data

AegisBreach does not sell personal data.

We may share personal data only where reasonably necessary with the following categories of recipients:

9.1 Hosting and infrastructure providers

Providers that support application hosting, databases, caching, storage, networking, security, monitoring, backups, and service availability.

Render is the current hosting candidate, but the final production provider and production region remain subject to infrastructure review. This policy will be updated when the production setup is confirmed.

9.2 Payment and banking providers

When online card payments are enabled, information necessary to create, verify, reconcile, and record a payment may be shared with the contracted bank, payment gateway, acquiring provider, card network, or related financial service provider.

AegisBreach does not intend to receive or store the full card number or CVV/CVC code.

9.3 Professional advisers

Accountants, lawyers, auditors, security consultants, insurers, or other professional advisers where reasonably necessary.

9.4 Authorities and legal recipients

Courts, regulators, law-enforcement authorities, tax authorities, or other recipients where disclosure is required or permitted by law.

9.5 Business restructuring

If the business is reorganized, sold, merged, financed, or transferred, relevant information may be disclosed under appropriate confidentiality and legal safeguards.

10. International Data Transfers

The final production hosting provider, region, payment provider, and supporting infrastructure are still under review.

Some service providers may process data outside Serbia or outside the country in which a user is located.

Where applicable law requires safeguards for an international transfer, AegisBreach will use an appropriate legal mechanism and will update this Privacy Policy with the relevant transfer information before relying on that arrangement for commercial production use.

11. Data Retention

AegisBreach keeps personal data only for as long as reasonably necessary for the purpose for which it was collected, including security, service delivery, dispute resolution, accounting, tax, and legal requirements.

Different categories of data may be retained for different periods.

Current confirmed or intended criteria include:

  • session records may currently remain active for up to seven days unless they expire or are revoked earlier;
  • account and organization data may be kept while the account is active and for a reasonable period after closure where needed for security, dispute, fraud-prevention, or legal purposes;
  • domain, scan, finding, and report data may be kept while needed to provide history, reports, support, and service functionality;
  • order, transaction, entitlement, and accounting data may be kept for the period required by applicable legal, accounting, tax, payment, and dispute-resolution requirements;
  • security, rate-limit, and audit records may be kept for the period reasonably necessary to protect the service and investigate incidents; and
  • support communications may be kept while necessary to resolve the request and maintain an appropriate record of the interaction.

Exact retention periods for each category have not yet been finalized and will be reviewed before final legal approval.

When data is no longer required, it may be deleted, anonymized, or securely isolated, subject to applicable legal and technical requirements.

12. Security

AegisBreach uses technical and organizational measures intended to protect personal data and the service.

These measures may include:

  • password hashing;
  • server-side sessions;
  • HttpOnly session cookies;
  • access controls;
  • organization-level authorization boundaries;
  • domain-verification controls;
  • rate limiting;
  • logging and audit records;
  • encrypted network connections;
  • restricted access to infrastructure;
  • secure development and review practices; and
  • backups and recovery controls where supported by the selected infrastructure.

No internet service can guarantee absolute security. Users are responsible for protecting their credentials and should immediately contact support if they believe their account or data may have been compromised.

13. Personal Data Rights

Depending on the law that applies, a person may have the right to:

  • ask whether AegisBreach processes personal data about them;
  • request access to and a copy of their personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • receive information about relevant data processing; and
  • submit a complaint to a competent data-protection authority.

These rights may be subject to legal conditions, exceptions, identity verification, and record-retention obligations.

14. How to Submit a Privacy Request

Privacy requests should be sent to:

support@aegisbreach.com

The request should clearly describe what the person is asking AegisBreach to do.

AegisBreach currently handles privacy requests manually by an authorized person. There is no automated privacy-request portal or automatic account-deletion button at the initial launch.

To protect users and prevent unauthorized disclosure or deletion, AegisBreach may request reasonable additional information when necessary to verify identity or authority.

AegisBreach will respond within the period required by applicable law. Under Serbian data-protection law, information about action taken on a request is generally provided within 30 days, subject to a legally permitted extension where the request is complex or numerous.

15. Account and Data Deletion

A user may request account or personal-data deletion by emailing:

support@aegisbreach.com

Deletion is currently reviewed and handled manually.

Before deleting data, AegisBreach may:

  • verify the identity of the requester;
  • confirm the account or organization concerned;
  • identify data that must be retained for legal, accounting, security, payment, fraud-prevention, or dispute purposes;
  • restrict access while the request is reviewed; and
  • explain any lawful reason why certain data cannot be deleted immediately.

Deleting an account may remove access to scan history, reports, domains, package access, and other account features.

16. Third-Party Links and Scanned Systems

The service may contain links to third-party websites or may scan publicly accessible technical properties of domains submitted by users.

AegisBreach does not control the privacy practices of unrelated third-party websites.

Users are responsible for ensuring that they are authorized to submit a domain, website, application, or system for scanning.

17. Changes to This Privacy Policy

AegisBreach may update this Privacy Policy when:

  • the service changes;
  • new data-processing activities are introduced;
  • the production infrastructure is finalized or changed;
  • a payment provider is contracted;
  • business registration details become available;
  • legal or regulatory requirements change; or
  • external legal review requires changes.

The updated version will show a revised “Last updated” date.

Material changes may also be communicated through the website, account area, or another appropriate channel.

18. Contact and Complaints

For privacy questions or requests:

support@aegisbreach.com

A person may also have the right to submit a complaint to the data-protection authority responsible for their location or the processing concerned.

For matters governed by Serbian data-protection law, the competent supervisory authority is the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia.

Before final approval

19. Pending Items Before Final Legal Approval

The following items must be completed or confirmed before this Privacy Policy is treated as final.

  • exact registered business name;
  • registered business address;
  • registration number;
  • tax identification number;
  • final production hosting provider;
  • final production hosting region;
  • final infrastructure and subprocessor list;
  • final payment provider and payment-processing disclosures;
  • exact category-specific retention periods where legally or operationally required;
  • final legal bases and legal wording;
  • final treatment of younger users and paid purchases under applicable law;
  • external legal review; and
  • owner approval following legal review.
aegisbreach

Passive security scanning for agencies and SMB teams. Know your posture before attackers do.

Product

  • Free Scan
  • Pricing

Company

  • About Us
  • Contact
  • Privacy
  • Terms

© 2026 AegisBreach. All rights reserved.

Passive checks only · No intrusive testing