Legal
Privacy Policy
Last updated: 1 January 2026 · Effective date: 1 January 2026
InfoSecGRC is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding your personal information.
1. Who We Are
InfoSecGRC ("we", "us", "our") operates the AI-powered information security assessment platform accessible at infosecgrc.io and its subdomains. We provide enterprise-grade security assessment tools powered by artificial intelligence.
For privacy-related inquiries, contact us at: privacy@infosecgrc.io
2. Information We Collect
2.1 Account Information
When you register, we collect:
- Full name and email address
- Password (stored as a cryptographic hash — we never store your plaintext password)
- Organization name (if provided)
- Google account information (if you sign in with Google)
2.2 Assessment Data
When you use our assessment tools, we process:
- Form inputs you provide (organization details, system descriptions, policy text, etc.)
- Files you upload (PDFs, documents, images) for analysis
- Assessment results generated by the AI
Important: Assessment inputs are processed by the Anthropic API in real-time. We do not retain your assessment content after the session ends. Files uploaded for analysis are processed in memory and not stored on our servers.
2.3 Usage Analytics
We collect anonymized usage statistics including:
- Which assessment modules are used
- Response times and success rates
- Number of assessments per account
- Timestamps of activity
This data does not include the content of your assessments.
2.4 Technical Data
- IP address (for security and abuse prevention)
- Browser and device type
- Login timestamps
3. How We Use Your Information
- Account management: To create and maintain your account, authenticate you, and manage your subscription.
- Service delivery: To process your security assessment requests and return results.
- Security: To detect and prevent fraudulent or abusive activity, and to enforce our Terms of Service.
- Analytics: To understand platform usage and improve our services.
- Communications: To send account-related notifications (password resets, approval notifications). We do not send marketing emails without your explicit consent.
4. Data Sharing
We do not sell, rent, or trade your personal information. We share data only in the following circumstances:
4.1 Service Providers
- Anthropic: Your assessment inputs are sent to the Anthropic API to generate AI-powered analysis. Anthropic's privacy policy governs their handling of this data.
- Hosting provider: Our servers are hosted on infrastructure that stores your account data securely.
4.2 Legal Requirements
We may disclose your information if required by law, court order, or to protect the rights and safety of our users or the public.
4.3 White-Label Tenants
If you access InfoSecGRC through a white-label instance operated by a third party, that operator has access to your account data and usage within their instance. Review the operator's privacy policy for details.
5. Data Retention
- Account data: Retained for as long as your account is active. Deleted within 30 days of account closure upon request.
- Assessment content: Not retained after the session. Results displayed to you are not stored server-side.
- Usage analytics: Anonymized aggregates retained for up to 12 months.
- Security logs: IP addresses and login records retained for up to 90 days for security purposes.
6. Security
We implement industry-standard security measures including:
- HTTPS encryption for all data in transit
- Multi-factor authentication (MFA) required for all accounts
- Passwords stored using cryptographic hashing
- JWT tokens with short expiry periods
- Regular security assessments of our own infrastructure
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Portability: Request your data in a machine-readable format.
- Objection: Object to processing of your data for certain purposes.
To exercise these rights, contact us at privacy@infosecgrc.io. We will respond within 30 days.
8. Cookies
We use the following cookies:
- Authentication cookie: A secure, httpOnly JWT token to keep you logged in. This is essential for the service to function.
- Session storage: Temporary data stored in your browser for the current session only.
We do not use advertising cookies or third-party tracking cookies.
9. Children's Privacy
Our platform is intended for professional use by adults. We do not knowingly collect personal information from anyone under the age of 16. If you believe a minor has provided us with personal information, contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes by email and update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions or to exercise your rights: