Skip to content

Privacy

How SCARP handles data.

Last updated 30 August 2026

SCARP assesses the externally visible security posture of domains you own or are authorised to assess. Most of what we handle is technical information about internet-facing infrastructure rather than information about people. This page sets out what we collect, who else processes it, where it goes, how long we keep it, and what you can ask us to do.

No advertising or application session cookies

There is no advertising, tracking pixel, session cookie, or consent banner. We record a small set of product-analytics events: an allowlisted event name, a normalized page family, and coarsened page-performance values. The application record contains no visitor identifier, cookie, free-form payload, referrer, or user-agent fingerprint. Our hosting provider necessarily processes network metadata to serve and protect the site; it is not copied into the application analytics record. The contact page separately loads Cloudflare Turnstile, which processes IP and browser or device signals for bot detection as described below.

Who is responsible for what

Two different roles apply, and the distinction matters if you have data protection obligations of your own:

  • For assessment data you put into the Service, you are the controller and we act as your processor. You decide which targets are assessed and why; we process on your instructions. Our vendor-review process can provide the applicable data-processing terms for review and confirmation before onboarding.
  • For your account, billing, support correspondence, and this website, we are the controller.

What we collect

Account and billing. Name, work email, organisation, role, and authentication material. Payment details are handled by PayPro Global as merchant of record; we do not receive or store card numbers.

Contact requests. The contact form submits your name, work email, company, the person or role who can authorize scanning the domains, and the context you provide. Those fields are submitted to Resend for delivery to the SCARP team at hello@getscarp.com, with your address set as the reply-to. A successful form response means Resend accepted the request; it does not prove inbox delivery or that a reply will follow. The fields are not copied into application-emitted operational event payloads: if Resend does not accept the request or times out, the form reports failure and asks you to email us directly. Email delivery uses Resend, our transactional email provider. A hidden anti-abuse field is also submitted; a non-empty value is treated as suspected automation, is neither logged nor emailed, and is not treated as a lead. To cap submissions per visitor, the server derives a short one-way hash of your connecting IP address and browser User-Agent and holds it in memory with the submission times. The contact application does not put the raw values or derived hash in its operational event payloads or a database. Google Cloud's managed hosting and request logs may independently process and retain network metadata, including IP address and User-Agent, under the 30-day Cloud Logging policy described below. Entries are not consulted after their one-hour or one-day cap window and are pruned on a subsequent request or when the short-lived server instance stops. Application-emitted operational events record only fixed provider-acceptance and configuration outcomes and follow the 30-day Cloud Logging retention. The form is also protected by Cloudflare Turnstile, a bot check that loads from challenges.cloudflare.com and processes your IP address and browser or device signals to produce a challenge result. It does not receive the contents of the contact form and is the only third-party script this site loads. Do not put passwords, API keys, customer records, or other sensitive data in the free-text field. You may skip it entirely and email hello@getscarp.com directly.

Assessment data. The domains and assets you submit, and what our checks observe about them: DNS and certificate records, exposed services and headers, technology fingerprints, and evidence snapshots supporting each finding. This can incidentally include personal data that is already published on your own infrastructure — a name in a WHOIS record, an address in a page, a mailbox in a mail configuration. We do not seek it out and we do not use it for anything beyond producing your assessment.

Operational records. Audit entries for security and administrative events, authentication events, and delivery logs for webhooks and notifications.

Documents you choose to upload. Compliance evidence, where you use that feature.

Active checks send requests to your targets

Passive assessment uses public and third-party sources. Active checks connect to the target itself, so they appear in that target’s own logs as traffic from us. Because of that, active checks require an eligible subscription and an enabled tenant policy. Domain verification and signed approval are enforced where the applicable workflow is configured to require them. You must hold authorisation for every target you submit — see section 2 of our Terms & Conditions.

Who else processes it

We use a deliberately short list of material service providers:

Service providerPurposeDataLocation
Google Cloud PlatformInfrastructure hostingAll application dataUS (us-central1)
Resend, Inc.Email notification deliveryRecipient email, notification contentUS
Cloudflare, Inc.Turnstile bot protection on the contact formVisitor IP address and browser or device signals; no contact-form contentPer their notice
Anthropic, PBCCompliance document analysis — opt-in onlyUploaded documents onlyUS
PayPro GlobalReseller and merchant of record for paymentsBilling and payment detailsPer their notice

Assessment-data recipients receive only the query inputs needed for the enabled lookup: customer domains, resolved public IPs, ASN and prefix, technology fingerprints, and, for an enabled breach-intelligence lookup, synthesized role-based email addresses at the customer domain. The security page publishes the category-level boundary. The detailed provider matrix, contractual classifications, transfer terms, and change-notice terms can be requested and must be confirmed during vendor review. Document analysis by Anthropic is opt-in and applies only to documents you upload for that purpose.

Where it is stored

Application data is stored and processed in the United States, in Google Cloud’s us-central1 region. If you are subject to the GDPR or an equivalent regime requiring transfer safeguards, the applicable mechanism and data-processing terms must be confirmed during vendor review before onboarding. All external traffic is encrypted in transit with TLS 1.2 or above.

How long we keep it

Retention is enforced by scheduled deletion, not by intention:

DataRetention
Assessment results — findings, assets, scores730 days
Scan execution metadata90 days
Evidence snapshots365 days in the database; stored objects up to 180 days
Generated reports (PDF/DOCX)30 days in the database; stored objects up to 365 days
Risk quantification results730 days, with the parent assessment
Audit log — security, admin and authentication events730 days
Sessions8 hours, or 30 days with remember-me
Webhook and notification delivery logs90 days
Contact-request email and correspondence90 days after the last correspondence (manual mailbox control)
Customer-uploaded compliance documents and their analysis1095 days

You can request earlier deletion of assessment data at any time. Application deletion honors an applicable legal hold, but independent object-storage lifecycle rules do not; legal-hold or custom-retention requirements must be reviewed and agreed before onboarding.

Your rights

Depending on where you are, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, withdraw consent, and receive it in a portable form. Reach us through our contact page; we aim to respond within 30 days.

If you are an individual whose data appeared in an assessment commissioned by someone else, that organisation is the controller and decides the outcome of your request. Contact us anyway and we will route it to them and support their response.

Security and incidents

Controls are described on our security page. If we become aware of a personal data breach affecting your data, we notify you without undue delay with what we know and what we are doing about it. To report a vulnerability, use the private disclosure address on the security page.

What we do not do

  • We do not sell personal data.
  • We do not use your assessment findings for advertising.
  • We do not publish findings attributable to you without your written consent.
  • We do not train models on your data. Document analysis happens only when you opt in, and only on the documents you submit for it.
  • We do not set advertising or tracking cookies on this website.

Changes

If we make a material change to this notice we will say so before it takes effect, and the date at the top will change. Questions are welcome through our contact page.