Pentest Today.
Legal

Privacy Policy

This explains what Pentest Today collects, why, who else processes it, and how to get it out or have it deleted. Security testing data is sensitive by nature, so the specifics matter more here than in most privacy policies.

Effective 2026-08-11·Version 1.1·Crucible Fund LLC

What this covers

This policy covers Pentest Today, operated by Crucible Fund LLC. It applies to the marketing site, the application, and the testing that runs on your behalf.

Two kinds of data run through this product. There is ordinary account data, and there is security data about the systems you ask us to test. The second kind is more sensitive than the first, and it is treated accordingly.

Information we collect

CategoryWhat it includesWhy we have it
AccountYour name, email address, and either a password or, for Google sign-in, the account identifier together with the OAuth tokens and profile image URL that the sign-in library stores.To create your account and sign you in.
SessionThe IP address and browser user agent recorded against each session.To keep you signed in and to help you spot unfamiliar sign-ins.
Website usagePages viewed, interactions, referral source, and device or browser information collected through Google Analytics. Google may derive approximate location from the IP address used to make the request.To understand how the site and application are used and improve them.
BillingA Stripe customer identifier and your subscription status. Card details go to Stripe directly and never reach our servers.To take payment and decide what your account can access.
Engagement and scan dataThe domains and targets you enter, raw scan output, findings, generated documents and reports, and any test-account credential you choose to supply for authenticated testing.To run the testing you asked for and produce your results.
Security documentation inputsWhat you enter into the document generator about your organization or your client: company and project details, the intake questionnaire, scan notes you paste in, pentest findings you record, and questionnaire answers.To generate your policies, diagrams, questionnaire responses, and packet.
Contacts you enterNames and email addresses you supply for other people, such as a security contact for a target or a primary contact on a project.To identify who to reach about an engagement, and to print the contact on generated documents.
Run activityThe pentest run log, including the agent's tool activity, plus token counts and the model cost of the run.To show you what the agent did, and to meter usage.
SupportMessages you send through the in-app support widget, where that widget is enabled, and, when you are signed in, your name and email address so the widget can identify you.To answer your questions.

How we use it

  • To provide the service: running scans and pentests, producing findings, and generating documents.
  • To operate accounts, take payment, and enforce subscription entitlements.
  • To send transactional email such as email verification and password resets.
  • To keep the service secure and to investigate abuse or violations of our Acceptable Use Policy.
  • To understand product usage and improve the site and application.
  • To meet legal obligations.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

AI processing

The product's AI features send data to third-party model providers. Depending on the feature, that can include target details, scan output, findings, and the facts you entered about your company for document generation.

Most requests are routed through OpenRouter. Scan and retest triage, the security document generator, and the pentest execution engine carry a provider-routing instruction requiring a zero-data-retention provider and denying provider-side data collection.

Being precise about the limit of that, because it is the kind of claim people assume covers everything. The report writer does not carry the instruction, so retention there follows the setting on the provider account rather than the request. If you need zero retention contractually across every path, talk to us before you buy.

A deployment can also be configured to call Anthropic or OpenAI directly. On that configuration the direct provider serves the pentest agent and scan triage as well as report writing, under that provider's own retention terms.

Sub-processors

We use the following processors to run the service. Where a row is marked as conditional, that processor is involved only when the corresponding feature is switched on.

We will update this list here, and email account owners, at least 30 days before a new sub-processor starts handling customer data, so you have time to object.

Sub-processorWhat it doesWhen it is involved
RenderHosts the web application, the testing worker, and the Postgres database.Always.
ResendSends transactional email such as verification and password reset.Always in production.
StripeProcesses subscription payments and stores payment methods.When billing is configured.
GoogleProvides optional sign-in with a Google account.When Google sign-in is configured.
Google AnalyticsMeasures visits and interactions across the marketing site and application.When you use the site or application.
OpenRouter, and the model provider it routes toRuns the AI features under a zero-data-retention routing instruction.When AI features are configured.
Anthropic, OpenAIOptional direct model access for report writing.Only when configured for direct use.
Manager AI support deskReceives messages you send through the in-app chat widget.Conditional: only when the support widget is switched on.

How we protect it

Traffic to the application is encrypted in transit with TLS. Exactly two categories of stored data get an additional layer of AES-256 encryption applied by the application before they reach the database: the raw output of an automated scan run, and any test-account credential you supply for authenticated testing. Other data, including findings, generated documents, and the pentest run activity log, relies on the database and hosting controls rather than that extra layer.

One honest caveat. Credential encryption was added after the feature shipped, and values stored before that change are readable until they are next written. If you supplied a test credential early on, rotate it and re-enter it, or ask us to remove it.

A fuller description of our security controls, and how to report a vulnerability, is on the security page.

Cookies and tracking

We set strictly necessary cookies to keep you signed in and protect the sign-in flow. Google Analytics may also set analytics cookies, including identifiers used to distinguish visits and measure how the site and application are used.

We use Google Analytics for product and website measurement, not for selling personal information or cross-context behavioural advertising. You can block or clear analytics cookies in your browser, or use Google's Analytics opt-out browser add-on.

The Google Analytics tag loads on every page. The support chat widget also loads on every page where it is switched on rather than only where you open a conversation. When you are signed in, the support widget receives your name and email address so a conversation can be attributed to you.

Retention

We keep account and engagement data for as long as your account exists, because your findings, reports, and generated documents are the product you paid for and deleting them would delete your history. Billing records are kept for seven years to satisfy tax and accounting rules.

When you ask us to delete your data we confirm receipt within five business days and complete the deletion within 30 days. Copies inside routine infrastructure backups are overwritten as those backups rotate rather than being extracted individually.

One carve-out, and it exists because of what this product does. We keep a minimal record of testing activity, meaning the account identifier, the targets, and the timestamps, for 24 months after an account is deleted. If somebody points this tool at a system they did not own, that record is how the target owner or a court gets an answer, and it is not something a deletion request can erase.

Your rights and choices

You can ask us for a copy of your data, to correct it, or to delete it. Email scott@manager.ai from the address on your account. We confirm receipt within five business days, complete the request within 30 days, and email you when it is done. The testing-activity records described above are the one thing a deletion request does not remove.

To be straightforward about it: there is no self-serve delete-my-account button in the app today. Deletion is a request by email, handled by a person. We would rather tell you that than imply a control that does not exist.

If something goes wrong

If we determine that a security incident has affected your data, we will notify the account email without undue delay and in any event within 72 hours of confirming it. The notice will say what we know, what we are doing about it, and what, if anything, you should do.

International users

Crucible Fund LLC is a Delaware company and the service runs on Render infrastructure. If you are outside the United States, using the service means your data is transferred to and processed in the United States, or in whichever region our hosting provider operates the deployment you are using. Ask us and we will tell you the current region.

A Data Processing Addendum incorporating the EU Standard Contractual Clauses, and the UK International Data Transfer Addendum, is available on request from scott@manager.ai.

If the GDPR or UK GDPR applies to you, our legal bases are the performance of our contract with you for providing the service, our legitimate interests in securing and improving it, your consent where we ask for it, and compliance with legal obligations. You have the rights of access, rectification, erasure, restriction, portability, and objection, and you may complain to your supervisory authority.

If you are a California resident, you have the rights to know, delete, correct, and to opt out of sale or sharing under the CCPA as amended by the CPRA. We do not sell or share personal information as those terms are defined. Exercise any of these rights at scott@manager.ai, and we will not treat you differently for doing so.

Children

The service is for business use by adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will remove it.

Changes to this policy

We will update this policy as the product changes, and material changes will be announced by email or in the app before they take effect. The effective date and version are at the top of this page.

How to reach us

Privacy questions and requests go to scott@manager.ai, addressed to Crucible Fund LLC.