Legal

Privacy Policy

Effective Date: August 27, 2026  ·  Last Updated: August 27, 2026

GhostDrill ("we", "us", or "our") is a red team intelligence platform that simulates real-world security findings to understand business impact and prioritize remediation. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the GhostDrill application. This policy is aligned with our detailed Information Disclosure and Privacy Policy, which maps to NIST SP 800-53 and FedRAMP requirements. Please read this policy carefully.

1. Information We Collect

GhostDrill collects information you provide directly when you create an account and use the application: • Account information (full name, email address) — registered via secure identity provider with mandatory multi-factor authentication • Pentest engagement data (engagement name, client, target scope, testing window, rules of engagement) • Contract signing data (legal name, company, job title, LinkedIn URL, electronic signature, signature IP, and timestamp) • Security findings, simulations, and business impact assessments you generate or enter • CVE watchlists and product monitoring preferences • Contact form submissions (name, email, company, subject, message) • Blog posts and community content you author • Technical and usage data (IP address for geo-gating, browser type, access timestamps, session data)

2. How We Use Your Information

We use the information we collect to: • Provide, maintain, and improve the GhostDrill red team intelligence platform • Authenticate your identity, manage sessions, and enforce role-based access • Generate AI-driven attack scenario simulations and business impact assessments from your engagement data • Record authorized testing scope and signer identity for legal accountability (Rules of Engagement, NDA) • Process subscription payments and grant access to paid features • Monitor CVEs and products you watchlist; notify you of relevant changes • Send security notifications (assignments, comments, status changes) • Maintain audit logs for accountability, incident investigation, and regulatory compliance • Restrict access to U.S.-based users via IP geo-gating

3. Data Storage and Security

Your data is stored on AWS GovCloud (U.S.-only) under FedRAMP controls. Security measures include: • Encryption at rest (KMS) and in transit (TLS 1.2+) on all stored data • Multi-factor authentication required for all accounts • Row-level security restricting data access to owners, assignees, and administrators • Continuous security monitoring (GuardDuty, Inspector) and immutable audit logging • Web Application Firewall with OWASP rules and U.S. geo-restriction • Strict boundary protection with network ACLs and security group isolation We do not sell, trade, or rent your personal information to third parties. Access to your data is restricted to authorized personnel and is logged for audit purposes.

4. Third-Party Data Sharing

GhostDrill shares data with third-party service providers only as necessary to deliver the platform: • AWS GovCloud — cloud hosting (FedRAMP High authorization) • Base44 Payments (powered by Wix) — payment processing (PCI-DSS compliant). GhostDrill receives only the checkout session ID, order ID, subscription plan, amount, currency, and buyer email. We never receive or store your full payment card number. • AI/LLM APIs — engagement context is sent for simulation generation (FedRAMP-authorized variants preferred; no client PII beyond what is necessary) • National Vulnerability Database (NVD) — public vulnerability data retrieval (no user data sent) We do not share your personal information for advertising purposes.

5. Data Retention

We retain your data based on its type and legal obligations: • User accounts: duration of engagement + 90 days, then anonymized • Pentest sessions, findings, and simulations: duration of engagement + 1 year • Engagement contracts and identity verification records: 7 years (legal/ROE requirements) • Payment and subscription records: 7 years (financial recordkeeping) • Audit logs: 365 days minimum, with long-term archive up to 7 years • Contact form submissions: 90 days • CVE database records: indefinite (public data) You may request deletion of your account and associated data at any time via the in-app Delete Account feature. Data retained for legal obligations (contracts, audit logs, financial records) is excluded from deletion until the retention period expires.

6. Your Rights

You have the right to: • Access the personal data we hold about you • Correct inaccurate or incomplete data • Request deletion of your data (self-service via the Delete Account page) • Export your data in a machine-readable format (JSON) • Object to processing for direct communications • Request human review of any automated identity verification decision To exercise these rights, submit a request via the Contact page with subject "Privacy Request," or use the self-service Delete Account feature. We respond to requests within 30 days.

7. Automated Decision-Making

GhostDrill uses AI-assisted processing in two areas: • Identity verification for contract signers: LinkedIn profile and AI analysis produce a risk level (low/medium/high). You may request human review of this decision. • Pentest simulation generation: AI produces advisory attack scenarios, business impact assessments, and remediation roadmaps. Final security decisions are made by human analysts. You have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects, with the right to obtain human intervention.

8. Cookies and Tracking

GhostDrill uses essential cookies and local storage to maintain your session and preferences. We do not use third-party advertising or tracking cookies.

9. Children's Privacy

GhostDrill is a professional security platform intended for authorized security professionals and organizations. It is not directed at individuals under 16, and we do not knowingly collect personal information from children. If you believe a child has provided information, contact us for immediate deletion.

10. International Data Transfers

GhostDrill is hosted on AWS GovCloud (U.S.-only) with geo-restriction to U.S.-based users. Data is stored and processed within the United States. The only international transfers are to LLM API providers, handled under their data processing agreements. GDPR-compliant data processing applies for EU users (lawful basis: contract performance and legitimate interest for security operations).

11. Breach Notification

In the event of a confirmed data breach, we will notify affected individuals within 72 hours and regulatory authorities as required by applicable law (GDPR Articles 33-34 and state breach notification laws). Notifications will include the nature of the breach, data categories affected, mitigation steps, and contact information.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy within the app and via email. Continued use of GhostDrill after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or privacy requests regarding this Privacy Policy, please contact us: • Submit via the Contact page with subject "Privacy Request" • Application: GhostDrill — Red Team Intelligence Platform A full detailed Information Disclosure and Privacy Policy document, aligned with FedRAMP and NIST SP 800-53 controls, is available upon request for compliance verification.

© 2026 GhostDrill. All rights reserved.