Legal
Privacy Policy
Last updated: September 2026
1. Information We Collect
Account information
We may collect your email address, an account identifier, and, where provided, a display name. Passwords are stored in hashed form and are not stored in plaintext. One-time verification and password-reset codes are stored in protected form and expire after a limited period.
Payment information
Purchases are processed by third-party payment providers. We may receive limited transaction information, such as the amount, currency, date, and payment status. We do not receive or store your full payment card number unless expressly stated otherwise at checkout.
Technical and log data
We may collect IP addresses, timestamps, request metadata, authentication and security events, browser or device information, and similar technical information for security, fraud and abuse prevention, service operation, troubleshooting, and rate limiting.
Assessment inputs and results
We collect the domain, website, or other target you submit for assessment, together with assessment metadata, scan results, supporting evidence, findings, observations, controls, and reports generated by the Service.
Communications
We collect information contained in messages and requests you send to us, including support, privacy, authorization, removal, and legal requests.
2. How We Use Information
We use personal information to:
- provide, operate, maintain, and secure the Service;
- create and manage user accounts;
- perform requested security assessments and generate reports;
- process payments and manage subscriptions or assessment allowances;
- send transactional and service-related communications, including verification codes, password-reset messages, receipts, account notices, security notices, and material changes to our policies;
- prevent fraud, abuse, unauthorized use, and security incidents;
- respond to support, privacy, authorization, and other requests;
- troubleshoot, maintain, and improve the Service;
- comply with applicable laws, regulations, legal processes, and lawful requests; and
- protect the rights, safety, security, and property of Soryvex, our users, and others.
We do not use personal information for cross-context behavioral advertising, and we do not sell personal information.
3. Legal Bases for Processing in the EEA and UK
Where the GDPR or UK GDPR applies, we process personal data on one or more of the following legal bases, as applicable:
- Performance of a contract — to provide the Service you request and manage your account, purchases, subscriptions, and assessments;
- Legitimate interests — including operating and improving the Service, maintaining security, preventing fraud and abuse, protecting our systems and users, and enforcing our agreements;
- Legal obligations — where processing is necessary to comply with applicable law or legal requirements; and
- Consent — where consent is required and we rely on it for a particular processing activity.
Where processing is based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Assessment Data and Reports
When you request an assessment, the Service processes information that is publicly reachable and externally observable from the target, which may include DNS records, email-security configuration, TLS information, HTTP response headers, cookies, publicly exposed technologies, subdomains, endpoints, files, and related security signals.
Publicly available information may occasionally contain personal information relating to individuals, such as contact details or other identifiers appearing in public records or publicly accessible services. We process such information only as reasonably necessary to perform the requested assessment, generate the report, maintain the Service, protect against abuse, and comply with applicable law.
Assessment results are generated using automated scanning and analysis tools. The Service may also use machine-learning-assisted tools to help organize, classify, validate, or explain results. Where such tools are used, assessment data is processed on infrastructure controlled by or operated for Soryvex. We do not send assessment data to third-party AI providers for model training.
Reports are stored on our servers and are accessible only to the account or other users authorized by Soryvex to access the relevant assessment. We do not publicly publish or intentionally make assessment reports searchable or indexable by search engines.
5. Cookies and Similar Technologies
We use cookies and similar technologies that are reasonably necessary to operate and secure the Service, including authentication-session and CSRF-protection cookies.
Our authentication-related cookies may be configured with security attributes such as HttpOnly and SameSite restrictions.
We do not use cookies for advertising or cross-site behavioral tracking.
Our third-party payment provider may use cookies or similar technologies on its checkout or payment pages. Those technologies are governed by the provider's own privacy policy and terms.
6. How We Share Information
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
We may disclose information to:
- Service providers. Third parties that provide services necessary to operate the Service, such as hosting, infrastructure, email delivery, payment processing, security, monitoring, or other business services. These providers may process information only as necessary to provide services to us and subject to applicable confidentiality and data-protection requirements.
- Legal and safety purposes. Authorities, courts, regulators, professional advisers, or other parties where disclosure is required by applicable law, legal process, or is reasonably necessary to protect the rights, safety, security, or property of Soryvex, our users, or others, or to investigate fraud, abuse, or security incidents.
- Business transfers. Information may be disclosed as part of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate confidentiality and data-protection requirements.
We do not otherwise disclose personal information except as permitted or required by applicable law.
7. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain account and assessment history, protect the Service, prevent abuse and fraud, comply with legal, tax, accounting, and regulatory obligations, resolve disputes, and enforce our agreements.
Assessment data and reports may be retained while an account remains active and for a reasonable period afterward where necessary for legitimate operational, security, legal, or business purposes.
Technical and security logs are retained for a limited period based on operational and security needs and may be retained longer where reasonably necessary to investigate security incidents, fraud, abuse, or other unlawful activity.
When personal information is no longer reasonably necessary for these purposes, we delete it, de-identify it, or otherwise dispose of it in accordance with applicable law and our retention practices. Information contained in backups may remain until the applicable backup is securely overwritten or otherwise removed through normal backup rotation.
8. Security
We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, or destruction. These measures may include password and one-time-code hashing, access controls, encrypted connections, authentication protections, rate limiting, logging, and other security controls appropriate to the nature of the information and the Service.
No method of transmission, storage, or security control can guarantee absolute security. We therefore cannot guarantee that personal information or the Service will never be compromised.
Where required by applicable law, we will provide notifications regarding qualifying security incidents or breaches to affected individuals and relevant authorities.
9. Your Rights and Choices
Depending on where you live and the laws that apply to you, you may have rights regarding your personal information, including rights to access, obtain a copy of, correct, delete, restrict, or object to certain processing of your personal information, as well as other rights provided by applicable law.
You may submit a privacy request by contacting [email protected].
We may take reasonable steps to verify your identity before completing a request, particularly where the request concerns access, deletion, correction, or disclosure of personal information.
We will respond to privacy requests within the time required by applicable law.
EEA and UK
Where GDPR or UK GDPR applies, you may have rights including access, rectification, erasure, restriction of processing, objection to certain processing, data portability, and the right to withdraw consent where processing is based on consent, subject to the conditions and limitations provided by applicable law.
You may also have the right to lodge a complaint with the data protection authority in your country or jurisdiction.
Israel
Under the Israeli Privacy Protection Law, as amended from time to time, you may have rights relating to personal information held about you, including rights of access and, where applicable, correction of inaccurate, incomplete, unclear, or outdated information.
You may exercise applicable rights by contacting [email protected].
United States and U.S. State Privacy Laws
Depending on your state of residence and whether the applicable law covers Soryvex, you may have rights concerning your personal information, which may include rights to know or access personal information collected about you, correct inaccurate information, request deletion, obtain information about certain disclosures, and opt out of certain sales, sharing, or targeted advertising.
Soryvex does not sell personal information and does not share personal information for cross-context behavioral advertising.
Where applicable, you may submit a privacy request using [email protected]. We will handle requests in accordance with the requirements and deadlines of the applicable law.
We will not discriminate against you for exercising privacy rights granted to you by applicable law.
10. International Transfers
Soryvex is based in Israel. We and our service providers may process and store personal information in Israel, the United States, and other countries in which we or our service providers operate.
Where applicable law requires safeguards for international transfers of personal data, we use appropriate legal, contractual, or other safeguards required by that law.
11. Children
The Service is not directed to children, and use of the Service requires the user to be at least 18 years old.
We do not knowingly collect personal information from individuals under 18 through the Service. If you believe that a person under 18 has provided us with personal information, please contact us at [email protected] so that we can review the situation and take appropriate action.
12. Do Not Track and Global Privacy Control
The Service does not use cross-site behavioral tracking for advertising purposes, and we do not treat a Do Not Track signal as changing our processing practices where no applicable law requires us to do so.
Where applicable law requires recognition of a valid Global Privacy Control or other opt-out preference signal, we will honor it in accordance with that law.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our processing activities, applicable law, or our business practices.
When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice through the Service, by email, or by another legally permitted method.
Your continued use of the Service after an updated Privacy Policy becomes effective will be subject to the updated Policy to the extent permitted by applicable law.
14. Contact
Privacy questions and privacy requests:
General legal and authorization matters: