SEKURA PRIVACY POLICY
Last updated: 14 September 2026
Sekura Inc. ("Sekura," "we," "us") provides an autonomous security validation platform. This policy explains what personal information we collect, why, and what rights you have.
Two distinct roles. Where we collect information about visitors to our website and users of our platform, we act as a controller and this policy applies. Where we process data contained within a customer's systems during a security assessment, we act as a processor on that customer's instructions — that processing is governed by our Data Processing Addendum and our customer's own privacy policy, not this one.
1. INTRODUCTION AND SCOPE
1.1 This Privacy Policy explains how Sekura, Inc., a Delaware corporation ("Sekura," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the Sekura website located at sekura.ai and the Sekura autonomous security-testing platform (together, the "Service").
1.2 This Policy is incorporated by reference into, and should be read together with, our Website Terms of Use. Where a Data Processing Addendum has been executed between Sekura and a customer, that Data Processing Addendum governs Sekura's processing of personal data on that customer's behalf to the extent it conflicts with this Policy.
1.3 Two distinct roles: This is the single most important distinction in this Policy, and it applies throughout. Where Sekura collects information about visitors to our website, individuals who create an account, and our customers' billing and business contacts, Sekura acts as a controller (or a "business" under California law), and this Policy describes that processing directly. Where Sekura's platform reads source code, configuration, logs, findings, or other content located within a customer's own repository or environment in the course of performing a security assessment under the Free or Paid tier, Sekura acts as a processor (or "service provider"/"contractor" under California law) on that customer's instructions. That processing is governed by our Data Processing Addendum and, as to any personal information the customer's own systems may contain, by that customer's own privacy policy — not primarily by this one. Section 9 explains what this means in practice if your personal information appears inside a customer's environment that Sekura has assessed. The free, one-time repository scan tool works differently, as described in Section 2.4 and Section 8 below.
2. INFORMATION WE COLLECT
2.1 Information you or your organization provide to us
- Account information: name, work email address, company name, job title, and authentication credentials, provided when you or your organization creates an account.
- Business and billing contact information: billing contact name, business address, and tax identifiers, provided when your organization subscribes to the Paid tier. Payment card and bank details are collected and processed directly by our payment processor, Stripe; Sekura does not receive or store full payment card numbers.
- Communications: information you provide when you contact support, sales, or another Sekura team, including the content of your message and any attachments.
- Repository connection credentials: OAuth tokens or access credentials you provide to connect a GitHub, GitLab, or Bitbucket account so that the Service can access a repository you have authorized for scanning.
- Marketing preferences: your subscription status and stated interests if you sign up for a newsletter or other content.
2.2 Information collected automatically
- Usage data: features used, scans initiated, and in-product actions taken in connection with your account.
- Device and connection data: IP address, browser type, operating system, and referring page, collected when you visit our website or use the Service.
- Cookies and similar technologies: see Section 7.
2.3 Information within a customer's own environment (Free and Paid tiers)
When the Service performs a scan under the Free or Paid tier, it necessarily reads source code, configuration files, dependency manifests, commit history, logs, and other content located in the repository or environment the customer has submitted. That content may incidentally contain personal information belonging to the customer's own personnel, contributors, or end users — for example, a name or email address in commit history, or a record in test data. Sekura does not solicit, and has no independent purpose for, this incidentally encountered personal information; Sekura processes it solely as necessary to deliver the scan, on the customer's instructions, as described in Section 1.3.
2.4 Information submitted through the free repository scan tool
The free, one-time repository scan tool works differently from the Free and Paid subscription tiers described in Section 2.3. When you submit a public or private repository URL through this tool, the repository content is received and processed within Sekura's own environment — including by a Sekura-operated AI model, as described in Section 8 — in order to generate and deliver your report by email. Unlike the tiered scanning described above, Sekura receives this content directly rather than the content remaining solely within your own environment. Sekura retains the submitted content only for as long as necessary to generate and deliver the report.
2.5 Information processed through our AI Services
Section 8 describes, in detail, the information that is processed by Sekura's own AI model and, where applicable, transmitted to a third-party AI model provider, as part of how the Service generates findings and remediation suggestions.
3. SOURCES OF INFORMATION
We collect information directly from you or your organization (account creation, billing, support), automatically through your use of the website and Service, from your connected source-code platform (GitHub, GitLab, or Bitbucket) once you authorize a connection, from a repository URL you submit through the free scan tool, and, incidentally, from within a repository or environment your organization submits for scanning under a subscription tier.
4. HOW WE USE INFORMATION
We use the information described in Section 2 to:
- provide, operate, secure, and support the Service, including generating and delivering reports through the free repository scan tool;
- authenticate users and administer accounts and subscriptions;
- process payments and maintain financial and tax records;
- respond to support and sales inquiries;
- send service communications, including security notices, changes to this Policy, and availability updates;
- send marketing communications where you have opted in, or otherwise as permitted by applicable law, with an unsubscribe mechanism in every such message;
- detect, investigate, and prevent fraud, abuse of the Service, and security incidents;
- generate Aggregated Data as described in Section 6, to improve the accuracy and coverage of our detection and validation capability; and
- comply with legal obligations and enforce our Website Terms of Use.
We do not use the personal information described in Section 2.3 (information incidentally present within a customer's own environment under the Free or Paid tier) for any purpose other than delivering the scan on that customer's instructions. We do not use it for our own marketing, analytics, or product-improvement purposes outside the Aggregated Data framework described in Section 6.
Legal bases (where GDPR or UK GDPR applies): We process personal information on the following bases: performance of a contract with you or your organization (account administration, billing, service delivery, including delivering a report through the free scan tool); our legitimate interests in securing, operating, and improving the Service, provided those interests are not overridden by your data protection interests or rights; compliance with a legal obligation; and, for marketing communications where required, your consent, which you may withdraw at any time. Where we act as a processor on a customer's instructions (Section 1.3), the customer, as controller, is responsible for establishing the applicable legal basis for that processing.
5. HOW WE SHARE INFORMATION
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used under the CCPA/CPRA.
We disclose information to the following categories of recipients:
- Service providers and sub processors that host our infrastructure, process payments (Stripe), provide customer support tooling, or provide analogous operational functions on our behalf, currently including;
- professional advisers, including legal, accounting, and insurance advisers, under an obligation of confidentiality;
- government authorities, regulators, or courts, where required by law, regulation, or valid legal process, or where necessary to protect the rights, safety, or property of Sekura, our customers, or others (see Section 13); and
- a successor entity in connection with a merger, acquisition, financing, reorganization, or sale of assets, as described in Section 14.
Service providers and sub processors are contractually restricted to processing personal information only as we instruct and only for the purposes for which we engage them.
6. AGGREGATED AND DE-IDENTIFIED DATA
We may generate aggregated, anonymized, and de-identified data from the operation of the Service — for example, the relative frequency of vulnerability classes across scans, or tool-performance metrics — to operate, secure, and improve the Service and to produce general industry research ("Aggregated Data"). Aggregated Data does not identify any individual or any customer, does not include a customer's source code, credentials, or other confidential information, and does not include Findings specific to an identifiable customer environment. We do not attempt to re-identify Aggregated Data and require the same of any recipient. Because Aggregated Data is not personal information, we may retain and use it after your account is closed.
7. COOKIES AND SIMILAR TECHNOLOGIES
Our website currently uses only cookies that are strictly necessary for authentication, session management, and security, and does not use advertising or cross-site tracking cookies. Where a non-essential cookie is used, we will obtain consent as required by applicable law and provide a mechanism to withdraw it.
8. AI AND MACHINE LEARNING
This Section describes, specifically and without euphemism, how artificial intelligence is used in the Service, because this is one of the most significant data flows in our business.
8.1 How AI is used: The Service uses AI agents, including large language models, to analyze code, generate security Findings, and, on the Paid tier, propose automated remediation pull requests. For the Free and Paid subscription tiers, code excerpts, file paths, diffs, and Findings-related content derived from a customer's repository are transmitted through Sekura's own LLM proxy to the applicable Model Provider, and the resulting output is returned to the Service; the underlying repository content otherwise remains in the customer's own environment, as described in Section 2.3. For the free, one-time repository scan tool, processing occurs directly within Sekura's own environment using a Sekura-operated AI model, as described in Section 2.4. For the Enterprise tier, this processing may instead occur through a private or self-hosted model endpoint configured for that customer.
8.2 Our model providers: We currently use a combination of large language models — including a model Sekura operates itself and models operated by third-party providers — as Model Providers for the Free and Paid tiers, and, for the Enterprise tier, private or self-hosted model endpoints as described in your Enterprise Agreement.
8.3 Sekura does not use your Customer Data — including code, Findings, or content processed through the AI Services, whether by Sekura's own model or a third-party model — to train any AI model that Sekura makes generally available to other customers. The only use we make of platform data for improvement purposes beyond delivering the Service to you is the Aggregated Data use described in Section 6.
8.4 Sensitive content in AI processing. Our scanning tools are designed to detect exposed credentials and secrets as a security finding.
8.5 No automated decision-making about individuals. The AI Services generate security findings about code and systems; they are not used to make, and do not produce, automated decisions that produce legal or similarly significant effects about any individual. If this changes, we will update this Policy and provide any disclosure required by applicable law.
9. CUSTOMER DATA VERSUS SEKURA-CONTROLLED PERSONAL DATA
If you are an individual whose personal information appears within a customer's own repository, configuration, or systems that Sekura has scanned on that customer's behalf under the Free or Paid tier — for example, because your name appears in commit history, or your email address appears in a configuration file — Sekura processes that information solely as a processor on that customer's instructions, as described in Section 1.3. Sekura is not the controller of that information and cannot independently grant or deny a request concerning it. If you wish to exercise a privacy right with respect to information contained in a customer's environment, please direct your request to that customer directly; Sekura will provide reasonable assistance to our customer in responding to your request, consistent with our Data Processing Addendum. This Section does not apply to information submitted through the free repository scan tool described in Section 2.4, where Sekura receives the content directly and acts as described in that Section.
10. DATA RETENTION
- Scan reports and proof-of-exploit artifacts: retained for 60 days after the scan completes, then deleted; a findings summary (severities, how the scan was billed, and the authorization reference) persists after the report is deleted. Enterprise-tier retention is as specified in the applicable Enterprise Agreement. On account deletion, stored reports and artifacts are deleted as part of that deletion, subject to routine encrypted-backup rotation.
- Repository content submitted through the free, one-time scan tool: retained only for as long as necessary to generate and deliver the report, consistent with Section 2.4 and Section 4.3 of the Website Terms of Use.
- AI prompts and responses processed to generate Findings: not retained by Sekura as a separate store beyond what is needed to generate and return your report, and never used to train any model Sekura makes generally available to other customers (Section 8).
- Authorization and consent records: retained indefinitely, including after account deletion, as evidentiary records — the record that you were entitled to have a repository tested and that you accepted the Terms.
- Account information: for the duration of your account, then for 12 months to allow for account recovery and legal recordkeeping.
- Billing and tax records: 7 years, consistent with standard U.S. tax and accounting recordkeeping practice.
- Support and sales correspondence: 3 years from the date of last contact, unless a longer period is required to resolve an open matter.
- Marketing contact information: until you unsubscribe, after which we retain your contact information only on a suppression list to honor that request.
- Aggregated Data: retained indefinitely, as it is not personal information.
We retain personal information only for as long as necessary for the purposes described in this Policy, taking into account the criteria above, and delete or de-identify it thereafter except where a longer period is required by law or to establish, exercise, or defend legal claims.
11. DATA SECURITY
We maintain administrative, technical, and physical safeguards designed to protect personal information and Customer Data against unauthorized access, use, or disclosure, including encryption of data in transit and, where applicable, at rest, access controls limiting internal access on a need-to-know basis, and a documented process for responding to a suspected security incident. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a security incident involving unauthorized access to personal information in our possession, we will notify affected individuals and, where legally required, the appropriate regulator, within the timeframe required by applicable law. Where the affected information resides within a customer's environment that we process as a service provider, our notification and cooperation obligations to that customer are governed by our Data Processing Addendum, and any notification to individuals is generally the responsibility of that customer as controller.
12. INTERNATIONAL DATA TRANSFERS
We are based in the United States, and our infrastructure is currently hosted in the United States. Where we transfer personal information originating in the European Economic Area, the United Kingdom, or Switzerland to the United States or another country that has not been recognized as providing an adequate level of data protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, for transfers from the United Kingdom, the UK International Data Transfer Addendum, together with any additional technical and organizational measures reasonably necessary. A copy of the applicable transfer mechanism is available on request.
13. LEGAL DISCLOSURES
We may disclose personal information where we have a good-faith belief that disclosure is necessary to comply with a legal obligation, court order, or valid legal process; to enforce our Website Terms of Use; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Sekura, our users, or the public, as permitted or required by applicable law.
14. CORPORATE TRANSACTIONS
If Sekura is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be disclosed to the parties involved and their advisers in connection with the diligence, negotiation, and closing of that transaction, and may be transferred to a successor entity as part of that transaction, subject to this Policy (or a successor policy providing materially equivalent protections) continuing to apply to that information.
15. YOUR PRIVACY RIGHTS
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; delete your information; receive a portable copy of your information; object to or restrict certain processing; withdraw consent where processing is based on consent; opt out of marketing communications at any time; and not be discriminated against for exercising a privacy right.
California residents: In addition to the rights above, under the CCPA/CPRA you have the right to know what personal information we have collected, used, disclosed, and (where applicable) sold or shared about you in the preceding 12 months; the right to delete personal information we hold about you, subject to certain exceptions; the right to correct inaccurate personal information; and the right to limit the use and disclosure of sensitive personal information, to the extent we process any. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, so no opt-out of sale or sharing is required. You may designate an authorized agent to submit a request on your behalf, subject to our ability to verify that agent's authority.
Other U.S. states: If you reside in a state with a comprehensive privacy law that applies to Sekura's processing of your personal information, you may have rights materially similar to those described above for California residents.
European Economic Area, United Kingdom, and Switzerland: If GDPR or UK GDPR applies to our processing of your personal information, you have the rights described above, and you have the right to lodge a complaint with your local supervisory authority — though we would appreciate the opportunity to address your concern directly first.
How to exercise your rights. Submit a request to help@sekura.ai. We will take reasonable steps to verify your identity before responding, and will respond within the timeframe required by applicable law (generally 30 days under GDPR/UK GDPR, and 45 days, extendable once by an additional 45 days, under the CCPA/CPRA). We may decline or limit a request to the extent permitted by applicable law, including where the request cannot be verified or where an exception applies.
Information within a customer's environment: As described in Section 9, if your request concerns personal information located within a customer's own environment that we have processed as a service provider under the Free or Paid tier, we will direct you to that customer and will assist them in responding, but we cannot independently fulfill the request ourselves.
16. CHILDREN'S PRIVACY
The Service is directed to professional software developers and organizations, is not directed to children, and we do not knowingly collect personal information from individuals under the age of 18. If you believe a child has provided us with personal information, please contact us at help@sekura.ai and we will take steps to delete it.
17. THIRD-PARTY SERVICES AND LINKS
The Service may link to, or integrate with, third-party websites, platforms, and services, including GitHub, GitLab, Bitbucket, our third-party AI model providers, our payment processor, Stripe, and communication tools you configure such as Slack or Microsoft Teams. Those third parties process information under their own privacy policies, which we encourage you to review; we are not responsible for their privacy practices.
18. CHANGES TO THIS POLICY
We may update this Policy from time to time. If we make a material change, we will provide notice by email or an in-product notice before the change takes effect. The "last updated" date above reflects the date of the current version.
19. CONTACT US
Sekura, Inc.
6044 Kingsmill Terrace, Suite #100, Dublin, CA 94568, United States
General and privacy inquiries: help@sekura.ai
