Privacy Policy
Protecting the data you entrust
Last Updated: 18-01-2026 · Effective Date: 18-01-2026
ExploitFrontier ("ExploitFrontier", "we", "us", "our") respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, share, store, and protect information when you visit exploitfrontier.com, use our services, contact us, or interact with our research content.
This Policy is intended to meet applicable data protection requirements, including India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2026. View the official reference
1. Who We Are
- ●Company: ExploitFrontier
- ●Location: Chandigarh, India
- ●Email (Privacy/Grievance): privacy@exploitfrontier.com
For certain services, we may act:
- •As a service provider / processor when we test systems on behalf of a client.
- •As a controller / fiduciary for data collected from visitors to our website and our own operations. Read the framework
2. Scope of This Policy
This Policy applies to:
- •Website visitors and people who contact us.
- •Prospective customers and clients who request VAPT or related services.
- •Individuals who submit content or interact with our Research & Insights section.
- •Applicants and collaborators (if you apply for roles).
Note: If you are a client, your contract and rules of engagement (RoE) may include additional data-handling terms. Where there is a conflict, the contract/RoE will govern for client work.
3. Information We Collect
A) Information you provide directly
- •Contact information: name, email, phone number, organization, role.
- •Inquiry details: message content, service requirements, scope requests.
- •Application details (if applicable): resume/CV, portfolio links, experience details.
- •Research submissions (if applicable): article content, tags, uploaded images/files.
B) Information we collect automatically (website usage)
- •Device and usage data: IP address (may be logged), browser type, pages visited, timestamps, referral URLs, approximate location (derived from IP).
- •Cookies/trackers: necessary cookies and (if enabled) analytics cookies (see Section 10).
C) Information processed during VAPT / security engagements
Depending on scope and authorization, we may process:
- •Target system identifiers (domains, IPs, endpoints).
- •Application logs, error messages, request/response samples (to validate findings).
- •User roles/permissions, session artifacts, configuration details.
- •Vulnerability evidence (screenshots, PoCs, payload samples).
- •Credentials or test accounts only if provided/authorized by the client.
- •Limited personal data that may exist within client systems (e.g., test user data).
We request clients to use test accounts and non-production personal data where feasible.
4. Why We Collect Information (Purposes)
- •Respond to inquiries and provide consultations/quotes.
- •Deliver VAPT, security testing, assessments, reporting, and retesting.
- •Maintain secure operations (access control, auditing, preventing abuse).
- •Improve our website, documentation, and user experience.
- •Publish research content (only with appropriate redaction and permissions).
- •Manage applications/collaborations and internal administration.
- •Comply with legal obligations and handle grievances.
5. Legal Basis for Processing
Where applicable, we process personal data based on:
- •Your consent (e.g., submitting an inquiry form, subscribing, or opting into analytics).
- •Performance of a contract (to deliver requested services).
- •Legitimate interests (security, fraud prevention, service improvement), balanced against your rights.
- •Legal obligation (compliance, lawful requests, tax/accounting as required).
6. Sharing and Disclosure
We do not sell personal data.
We may share information with:
- •Service providers (hosting, email, analytics, security tools) that process data on our behalf under confidentiality and security obligations.
- •Clients (for VAPT reporting and debriefs), limited to what is necessary.
- •Professional advisors (legal/accounting) when necessary.
- •Law enforcement / regulators where required by law or valid legal process.
If you are a VAPT client, any sharing beyond delivery needs is governed by your contract/RoE and confidentiality commitments.
7. International Transfers
Your data may be processed on servers or by providers located outside India depending on our infrastructure (e.g., cloud hosting, email services). When we transfer data internationally, we take reasonable steps to ensure appropriate safeguards and contractual protections consistent with applicable law. Learn more
8. Security Measures
We use reasonable and appropriate safeguards to protect information, which may include:
- •Access control and least-privilege permissions.
- •Encryption in transit (HTTPS/TLS) and, where feasible, encryption at rest.
- •Secure secret management practices.
- •Audit logging and monitoring.
- •Controlled retention and secure deletion.
No system is 100% secure; however, we continuously improve our safeguards in line with industry practices.
9. Data Retention
We retain personal data only as long as necessary for the purposes described:
- •Inquiries: typically retained for business follow-up and record-keeping.
- •Client engagement data (evidence, reports): retained for a defined period (commonly 6–24 months) or as agreed in contract/RoE.
- •Research content: retained until removed by us or the author (subject to moderation and legal requirements).
- •Security logs: retained for operational security and abuse prevention for a limited period.
We may retain certain data longer where required for legal compliance or dispute resolution.
10. Cookies and Analytics
We may use:
- •Strictly necessary cookies for basic website functionality and security.
- •Analytics cookies (if enabled) to understand traffic and improve usability.
You can control cookies via browser settings. If we implement a cookie banner/consent tool, you can manage preferences there.
11. Your Rights
Depending on your jurisdiction and applicable law, you may have rights to:
- •Access and obtain a summary of your personal data.
- •Correct inaccurate personal data.
- •Request deletion/erasure (subject to lawful retention needs).
- •Withdraw consent (where processing is based on consent).
- •Grievance redressal and complaint escalation mechanisms under applicable law.
To exercise rights, contact us at privacy@exploitfrontier.com
12. Children's Privacy
Our website and services are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can take appropriate steps.
13. Research & Responsible Disclosure
We publish research and insights to improve security awareness. We aim to:
- •Avoid publishing sensitive personal data.
- •Remove or redact client-identifying details unless explicitly permitted.
- •Follow responsible disclosure practices where vulnerabilities affect third parties.
If you believe any published content exposes sensitive or personal data, contact us immediately at privacy@exploitfrontier.com
14. Third-Party Links
Our website may contain links to third-party websites (e.g., LinkedIn, tools, references). We are not responsible for the privacy practices of those third parties. Please review their privacy policies.
15. Grievance Redressal and Contact
For privacy questions, requests, or complaints, contact:
- ●Email: privacy@exploitfrontier.com
- ●Location: Chandigarh, India
We will acknowledge and respond within a reasonable timeframe consistent with applicable requirements. Reference the grievance requirements
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Last Updated" date and, where appropriate, provide additional notice on the website.