Privacy
How SCARP handles data.
Last updated 30 August 2026
SCARP assesses the externally visible security posture of domains you own or are authorised to assess. Most of what we handle is technical information about internet-facing infrastructure rather than information about people. This page sets out what we collect, who else processes it, where it goes, how long we keep it, and what you can ask us to do.
No advertising or application session cookies
There is no advertising, tracking pixel, session cookie, or consent banner. We record a small set of product-analytics events: an allowlisted event name, a normalized page family, and coarsened page-performance values. The application record contains no visitor identifier, cookie, free-form payload, referrer, or user-agent fingerprint. Our hosting provider necessarily processes network metadata to serve and protect the site; it is not copied into the application analytics record. The contact page separately loads Cloudflare Turnstile, which processes IP and browser or device signals for bot detection as described below.
Who is responsible for what
Two different roles apply, and the distinction matters if you have data protection obligations of your own:
- For assessment data you put into the Service, you are the controller and we act as your processor. You decide which targets are assessed and why; we process on your instructions. Our vendor-review process can provide the applicable data-processing terms for review and confirmation before onboarding.
- For your account, billing, support correspondence, and this website, we are the controller.
What we collect
Account and billing. Name, work email, organisation, role, and authentication material. Payment details are handled by PayPro Global as merchant of record; we do not receive or store card numbers.
Contact requests. The contact form submits your name, work email, company, the person or role who can authorize scanning the domains, and the context you provide. Those fields are submitted to Resend for delivery to the SCARP team at hello@getscarp.com, with your address set as the reply-to. A successful form response means Resend accepted the request; it does not prove inbox delivery or that a reply will follow. The fields are not copied into application-emitted operational event payloads: if Resend does not accept the request or times out, the form reports failure and asks you to email us directly. Email delivery uses Resend, our transactional email provider. A hidden anti-abuse field is also submitted; a non-empty value is treated as suspected automation, is neither logged nor emailed, and is not treated as a lead. To cap submissions per visitor, the server derives a short one-way hash of your connecting IP address and browser User-Agent and holds it in memory with the submission times. The contact application does not put the raw values or derived hash in its operational event payloads or a database. Google Cloud's managed hosting and request logs may independently process and retain network metadata, including IP address and User-Agent, under the 30-day Cloud Logging policy described below. Entries are not consulted after their one-hour or one-day cap window and are pruned on a subsequent request or when the short-lived server instance stops. Application-emitted operational events record only fixed provider-acceptance and configuration outcomes and follow the 30-day Cloud Logging retention. The form is also protected by Cloudflare Turnstile, a bot check that loads from challenges.cloudflare.com and processes your IP address and browser or device signals to produce a challenge result. It does not receive the contents of the contact form and is the only third-party script this site loads. Do not put passwords, API keys, customer records, or other sensitive data in the free-text field. You may skip it entirely and email hello@getscarp.com directly.
Assessment data. The domains and assets you submit, and what our checks observe about them: DNS and certificate records, exposed services and headers, technology fingerprints, and evidence snapshots supporting each finding. This can incidentally include personal data that is already published on your own infrastructure — a name in a WHOIS record, an address in a page, a mailbox in a mail configuration. We do not seek it out and we do not use it for anything beyond producing your assessment.
Operational records. Audit entries for security and administrative events, authentication events, and delivery logs for webhooks and notifications.
Documents you choose to upload. Compliance evidence, where you use that feature.
Active checks send requests to your targets
Passive assessment uses public and third-party sources. Active checks connect to the target itself, so they appear in that target’s own logs as traffic from us. Because of that, active checks require an eligible subscription and an enabled tenant policy. Domain verification and signed approval are enforced where the applicable workflow is configured to require them. You must hold authorisation for every target you submit — see section 2 of our Terms & Conditions.
Who else processes it
We use a deliberately short list of material service providers:
| Service provider | Purpose | Data | Location |
|---|---|---|---|
| Google Cloud Platform | Infrastructure hosting | All application data | US (us-central1) |
| Resend, Inc. | Email notification delivery | Recipient email, notification content | US |
| Cloudflare, Inc. | Turnstile bot protection on the contact form | Visitor IP address and browser or device signals; no contact-form content | Per their notice |
| Anthropic, PBC | Compliance document analysis — opt-in only | Uploaded documents only | US |
| PayPro Global | Reseller and merchant of record for payments | Billing and payment details | Per their notice |
Assessment-data recipients receive only the query inputs needed for the enabled lookup: customer domains, resolved public IPs, ASN and prefix, technology fingerprints, and, for an enabled breach-intelligence lookup, synthesized role-based email addresses at the customer domain. The security page publishes the category-level boundary. The detailed provider matrix, contractual classifications, transfer terms, and change-notice terms can be requested and must be confirmed during vendor review. Document analysis by Anthropic is opt-in and applies only to documents you upload for that purpose.
Where it is stored
Application data is stored and processed in the United States, in Google Cloud’s us-central1 region. If you are subject to the GDPR or an equivalent regime requiring transfer safeguards, the applicable mechanism and data-processing terms must be confirmed during vendor review before onboarding. All external traffic is encrypted in transit with TLS 1.2 or above.
How long we keep it
Retention is enforced by scheduled deletion, not by intention:
| Data | Retention |
|---|---|
| Assessment results — findings, assets, scores | 730 days |
| Scan execution metadata | 90 days |
| Evidence snapshots | 365 days in the database; stored objects up to 180 days |
| Generated reports (PDF/DOCX) | 30 days in the database; stored objects up to 365 days |
| Risk quantification results | 730 days, with the parent assessment |
| Audit log — security, admin and authentication events | 730 days |
| Sessions | 8 hours, or 30 days with remember-me |
| Webhook and notification delivery logs | 90 days |
| Contact-request email and correspondence | 90 days after the last correspondence (manual mailbox control) |
| Customer-uploaded compliance documents and their analysis | 1095 days |
You can request earlier deletion of assessment data at any time. Application deletion honors an applicable legal hold, but independent object-storage lifecycle rules do not; legal-hold or custom-retention requirements must be reviewed and agreed before onboarding.
Your rights
Depending on where you are, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, withdraw consent, and receive it in a portable form. Reach us through our contact page; we aim to respond within 30 days.
If you are an individual whose data appeared in an assessment commissioned by someone else, that organisation is the controller and decides the outcome of your request. Contact us anyway and we will route it to them and support their response.
Security and incidents
Controls are described on our security page. If we become aware of a personal data breach affecting your data, we notify you without undue delay with what we know and what we are doing about it. To report a vulnerability, use the private disclosure address on the security page.
What we do not do
- We do not sell personal data.
- We do not use your assessment findings for advertising.
- We do not publish findings attributable to you without your written consent.
- We do not train models on your data. Document analysis happens only when you opt in, and only on the documents you submit for it.
- We do not set advertising or tracking cookies on this website.
Changes
If we make a material change to this notice we will say so before it takes effect, and the date at the top will change. Questions are welcome through our contact page.