Legal

Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how RedStrike handles personal data when you visit our website, evaluate our platform, or use our continuous security testing services. We designed our practices around data minimization and transparency, and we treat the trust you place in us as a core part of the product.

Introduction

Encyfr Technologies Private Limited (“RedStrike”, “we”, “us”, or “our”) provides an AI-driven continuous penetration testing and cloud security posture management platform. This Privacy Policy applies to personal data we process about visitors to our websites, prospective customers, and the authorized users of our platform. It does not describe how we process data on behalf of our customers as a processor — that relationship is governed by our Data Processing Addendum.

We believe a security company should hold itself to a higher standard for handling data. Wherever practical we collect the minimum information required to operate, we keep it only as long as we need it, and we are clear about who can access it. If anything in this policy is unclear, please reach out using the contact details at the end.

Information we collect

We collect information in three broad ways: information you provide, information we generate, and information collected automatically.

  • Account and contact data. Your name, work email, company, role, and any details you submit when you create an account, request a demo, or contact our team.
  • Billing data. Company billing address and plan details. Card payments are handled by our payment processor; we do not store full card numbers on our systems.
  • Platform usage data. Configuration, scan schedules, target scopes you authorize, findings, reports, and activity logs generated as you use the service.
  • Technical data. IP address, device and browser type, and diagnostic logs used to keep the service secure and reliable.
  • Cookies and similar technologies. As described in our Cookie Policy.

How we use information

We use personal data to deliver, secure, and improve the service, and to communicate with you. Specifically, we use it to:

  • Provision accounts, authenticate users, and operate scans and reporting you request.
  • Provide support, respond to inquiries, and send service and security notices.
  • Monitor performance, detect abuse, and protect the integrity of our platform.
  • Process payments, manage subscriptions, and meet accounting obligations.
  • Improve features and models using aggregated or de-identified data where possible.
  • Send product updates and marketing you can opt out of at any time.

Sharing & subprocessors

We do not sell personal data. We share it only with service providers who help us run the business under contractual confidentiality and data-protection commitments. These subprocessors include cloud hosting, analytics, payment processing, customer support, and email delivery providers.

We may also disclose information when required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will notify affected customers. A current list of subprocessors is available on request and referenced in our Data Processing Addendum.

Data retention

We keep personal data for as long as needed to provide the service and for legitimate business or legal purposes. Account data is retained for the life of your account; scan results and reports are retained according to your plan and configuration. When data is no longer required, we delete or de-identify it.

Backups and logs are kept for limited, rolling windows for reliability and security, after which they are overwritten. If you close your account, we delete or anonymize your personal data within a commercially reasonable period, except where retention is required by law.

Security

We apply administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit and at rest, least-privilege access controls, network segmentation, and continuous monitoring. Our own platform is subject to the same testing discipline we deliver to customers.

You can learn more about our program, certifications, and shared-responsibility model on our Trust & security page. No method of transmission or storage is perfectly secure, but we work continuously to reduce risk.

Your rights (GDPR & CCPA)

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Residents of California and similar U.S. states may request disclosure of the categories of data we collect and ask us not to “sell” or “share” personal data — which we do not do for cross-context behavioral advertising.

To exercise any right, email hello@encyfr.ai. We will verify your request and respond within the timeframes required by law. You also have the right to lodge a complaint with your local data protection authority, though we hope you will contact us first.

International transfers

We operate globally, so personal data may be processed in countries other than your own, including the United States. Where we transfer data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum.

We take additional measures — including encryption and access controls — to protect data during international transfers. You may request more detail about the safeguards we use by contacting us.

Children's privacy

RedStrike is a business-to-business service intended for organizations and their authorized personnel. It is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. If we learn that we have collected such data, we will delete it promptly.

Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “last updated” date above and, where appropriate, provide additional notice. Your continued use of the service after an update constitutes acceptance of the revised policy.

Contact us

If you have questions about this Privacy Policy or how we handle your data, contact Encyfr Technologies Private Limited at hello@encyfr.ai or through our contact page. For security-specific concerns, see our responsible disclosure policy.

Questions about our policies?

Our team is happy to walk security and legal reviewers through how RedStrike handles data.