Privacy Policy
Last updated: July 16, 2026
Vulnera helps you find, understand, prioritize, and fix vulnerabilities in your websites, applications, APIs, containers, and cloud environments. To do that, we need to process some data about you, about your organization, and about the assets you authorize us to analyze. This Policy explains what that data is, why we process it, who we share it with, how long we keep it, and what you can require from us. We write in plain language, without unnecessary legalese. Where we don't yet have a confirmed answer, we say so explicitly instead of filling the gap with assumptions.
1. Controller and privacy contact
Vulnera is operated by Osmir Custodio Mariano Tecnologia da Informação Ltda., registered under CNPJ no. 53.636.099/0001-89, with its registered office at Avenida Paulista 1106, sala 01, 16th floor, Bela Vista, São Paulo/SP, 01310-914, Brazil.
For privacy and data protection matters, the contact is contato@vulnera.io. Vulnera qualifies as a small processing agent and, under Brazilian ANPD Resolution CD/ANPD No. 2/2022, does not appoint a Data Protection Officer (DPO). Instead, we keep this communication channel available to data subjects and to the ANPD, with the same commitment to respond.
Depending on the data, we act in different roles:
- As controller, when we decide how account, subscription, billing, support, and platform usage data are processed.
- As processor, when we process assets, scan configurations, technical evidence, and security findings on behalf of and under the instructions of a customer organization.
2. Who this Policy applies to
This Policy applies to:
- Visitors to Vulnera's marketing site.
- People who create an account on the platform.
- Members of customer organizations.
- People invited to collaborate within an organization.
- Anyone who contacts support.
- Anyone who registers assets, configures integrations, or runs security analyses.
3. Data we collect
We collect only what we need to operate the platform. Depending on how you use it, that may include:
- Registration data: name, email, language, organization, and your role within it.
- Authentication and session data: your password stored as a hash, session tokens and, if you sign in with Google, the data Google returns to us on that sign-in.
- Subscription and billing data: plan, status, period, and transaction identifiers. Full card details are handled by the payment processor and do not pass through our servers.
- Support and communication data: the content of the messages you send us.
- Technical access records: IP address, timestamp, browser, device, and application logs.
- Asset information: domains, URLs, IP addresses, APIs, repositories, containers, and cloud resource identifiers you register.
- Ownership or authorization verification data: DNS TXT records, verification tokens, files published on the asset, and your declaration that you are authorized to analyze it.
- Scan configurations and schedules.
- Vulnerability findings: severity, technical evidence, affected resource, remediation status, and scan history.
- Integration metadata, including MCP integrations and OAuth clients you authorize.
- Credentials or secrets you provide for authenticated analyses, where the product offers that feature.
- Content generated by automated analysis or artificial intelligence, such as explanations and remediation suggestions.
- Cookies and local storage used by the platform.
A security scan looks at the real asset. Because of that, it may incidentally process personal data, confidential information, technical identifiers, URLs, headers, response fragments, or any other information the analyzed asset itself exposes. We cannot know in advance what your asset returns. We do not claim that Vulnera never processes sensitive data: choose the scope of your analyses with that in mind.
4. Purposes and legal bases
We process personal data for the purposes below, under the legal bases of the LGPD and, where the GDPR applies, its equivalents. Consent is not our default basis. Most of this processing exists because it is necessary to deliver the service you contracted.
- Creating and maintaining your account and organization. Performance of a contract.
- Providing the contracted security analysis service. Performance of a contract.
- Verifying ownership of or authorization over an asset. Performance of a contract and compliance with a legal obligation, plus our legitimate interest in preventing unauthorized scanning.
- Running and managing scans. Performance of a contract.
- Generating findings, prioritization, and remediation recommendations. Performance of a contract.
- Maintaining scan history and revalidation results. Performance of a contract and our legitimate interest in showing remediation progress.
- Processing subscriptions and payments. Performance of a contract and compliance with a legal (tax) obligation.
- Sending transactional and security communications. Performance of a contract and legitimate interest.
- Providing support. Performance of a contract.
- Preventing fraud, abuse, unauthorized scanning, and attacks. Legitimate interest and compliance with a legal obligation.
- Enforcing rate limits and acceptable use restrictions. Legitimate interest.
- Monitoring reliability and diagnosing errors. Legitimate interest.
- Complying with legal and regulatory obligations and orders from competent authorities. Compliance with a legal obligation.
- Improving the product using aggregated, anonymized, or appropriately protected data. Legitimate interest.
- Sending marketing communications, where applicable. Consent, revocable at any time.
Where we rely on legitimate interest, we assess whether it is overridden by your rights and freedoms. You may object to that processing through the privacy contact.
5. Artificial intelligence and automated processing
Vulnera uses automated systems and, when enabled, artificial intelligence to interpret security findings, classify and prioritize risk, explain technical issues in accessible language, generate remediation suggestions, and correlate or de-duplicate findings.
Today the AI feature is optional in configuration and depends on an OpenAI key being enabled in the environment. When it is enabled, we send OpenAI the title, severity, description, and category of the vulnerabilities found in your assets. We do not send your credentials, your secrets, or the raw technical evidence captured during the scan. This happens when generating a report's executive summary and business-impact explanation, when generating a remediation recommendation, and when you request a recommendation through an MCP integration. When the key is not enabled, the platform uses local text templates and nothing is sent to third parties.
Automated results may be incomplete or inaccurate. They exist to inform your decision, not to replace it. Review any recommendation before applying a change to your system.
Vulnera does not make automated decisions that produce legal effects concerning you or similarly significantly affect you. Risk prioritization is a technical suggestion, not a decision about you as a person.
6. Sharing and subprocessors
Vulnera does not sell personal data.
We share data only with the providers needed to operate the service, listed below. We list only what is actually in use in our infrastructure:
- Amazon Web Services (AWS). Hosting, managed PostgreSQL database (Amazon RDS), cache and queues (Amazon ElastiCache/Redis), and container execution (Amazon ECS).
- Google. Authentication, when you choose to sign in with a Google account.
- Stripe. Payment and subscription processing, when billing is enabled.
- OpenAI. AI-generated explanations and recommendations, when the feature is enabled, as described in section 5.
- Doppler. Secret and environment variable management for our infrastructure.
- Hostinger. Email provider for the vulnera.io domain.
That list contains only what is in use today. We do not use a third-party helpdesk tool, support runs through the email address in section 14, and we have no transactional email provider and no error-monitoring provider in operation. If any of that changes, we will update this list before the provider processes your data.
About the scanners: dynamic analyses use OWASP ZAP and code analyses use Vulnera's own engine. Both run inside our own AWS infrastructure. We do not send your assets, your code, or your findings to a third-party scanning service. ZAP is software we run, not a processor that receives your data.
We may also share information when required by law, court order, or a request from a competent authority, and to exercise or defend rights in legal proceedings. In those cases we assess the legality of the request and, where permitted, inform you.
7. International data transfers
Vulnera's infrastructure is hosted on AWS in the us-east-2 region (Ohio, United States). This means your data, including account data, assets, findings, and evidence, is stored and processed outside Brazil.
Some of the providers in section 6, such as Google, Stripe, and OpenAI, may also process data outside Brazil and the European Union.
The LGPD permits international transfers when supported by adequate safeguards or when necessary for the performance of your contract. We maintain data processing agreements (DPAs) with these providers that incorporate standard contractual clauses, the instrument foreseen by both the LGPD and the GDPR for this kind of transfer.
8. Information security
We treat vulnerability reports, scan evidence, credentials, asset information, and remediation details as sensitive information. In practice, this data describes exactly where a system is weak, so it gets the same care we would give a secret.
The technical and organizational measures we have today:
- Encryption in transit: all public traffic uses HTTPS with a managed certificate, and the Redis connection requires TLS.
- Encryption at rest: the PostgreSQL database and the Redis cache have encryption at rest enabled.
- Organization isolation: every product record is bound to its tenant, and queries are scoped to that boundary.
- Access control: JWT authentication with expiry, passwords stored only as hashes (bcrypt), and OAuth for MCP integrations with short-lived tokens.
- Secret management: environment credentials live in Doppler and are injected at runtime, never committed to the codebase.
- Audit logs: relevant platform actions are recorded with user, organization, action, IP, and timestamp.
- Network restrictions: services run in a VPC, with databases and cache reachable only from authorized security groups.
- Backups: the database has a daily automated backup managed by AWS, with a 1-day retention window.
- Ownership verification before analysis, as described in section 3.
We do not promise absolute security, and you should distrust anyone who does. No system is completely immune to incidents. We work to reduce risk and to respond quickly when something happens, but we cannot guarantee that an incident will never occur.
If we identify a security incident that may pose relevant risk or harm to you, we will notify you and Brazil's National Data Protection Authority (ANPD) within the deadlines set by the LGPD (art. 48) and ANPD Resolution CD/ANPD No. 15/2024.
If you find a vulnerability in Vulnera itself, write to contato@vulnera.io with a subject line starting with "Security", so the message reaches the right people quickly.
9. How long we keep data and when we delete it
We keep each category of data for as long as its purpose requires. The periods below are the ones we apply today:
- Account data: for as long as the account exists. After it is closed, we keep it for up to 1 year. That is the window in which you can still come back and find your history.
- Scan results and security findings: up to 1 year of account inactivity. While you use Vulnera, the history stays: it is what shows your remediation progress.
- Technical evidence: follows the same period as the findings. Evidence is written inside the finding record itself, so it is created and deleted along with it.
- Reports: they live in your account and follow the same period as the findings. There is no report with a public or shared link. You export the report as a PDF, and once downloaded, that copy is in your custody.
- Access and audit logs: 1 year. The Brazilian Internet Civil Framework (art. 15) requires application access records to be kept for at least 6 months; we keep them beyond that minimum.
- Billing records and tax documents: 5 years, per the periods set by Brazilian tax law (CTN, arts. 173 and 174).
- Deletion requests: when you ask us to delete your data, we complete it within 30 calendar days, without waiting out the 1-year period.
- Backups: up to 1 day, which is the database backup retention window. After you delete something from the live environment, a copy may survive in the backup for that period.
- Data needed to prevent abuse or repeat unauthorized scanning, or to comply with a legal obligation: for as long as that purpose requires.
Deletion is not always immediate. When you delete something, we remove it from the live environment, but copies may remain in backups until the retention window expires and the backup is overwritten. We also retain data where the law requires it, or where it is needed to exercise rights in legal proceedings. In those cases, the data is blocked from any other use.
10. Your rights
The LGPD grants you rights over your personal data, and the GDPR grants equivalent rights where it applies. You can request:
- Confirmation that we process your data, and access to it.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed unlawfully.
- Portability of your data to another provider.
- Information about who we share your data with.
- Information about your option to withhold consent and the consequences of doing so.
- Withdrawal of consent, where processing is based on it.
- Objection to processing based on legitimate interest.
- Review of automated decisions, where applicable. See section 5.
To exercise any of these rights, write to contato@vulnera.io. We will need to confirm your identity before acting, so that we don't hand your data to the wrong person. We respond within 15 days, the deadline set by art. 19, II of the LGPD for a complete declaration about your data; anything that can be answered immediately, in simplified form, we answer on the spot.
If you are a member of a customer organization and your request involves that organization's assets, scans, or findings, we may need to route the request to whoever administers the account, since in those cases we act on its instructions.
You may also file a complaint with the ANPD (gov.br/anpd) or, where applicable, with the data protection authority in your country.
11. Cookies and similar technologies
We use only what is described here:
- Strictly necessary: items that make the site and the platform work, including routing and basic request protection.
- Authentication and session: tokens that keep you signed in to the platform. Without them, there is no login.
- Preferences: your theme choice (light/dark) is stored in your browser's local storage. Your language lives in the page address itself (/pt or /en), not in a cookie.
- Analytics: we do not use it. The site has technical support for Google Analytics 4 and Plausible, but neither is enabled. No audience measurement is loaded today.
- Marketing: we do not use marketing or targeted advertising cookies.
If we ever enable analytics, we will update this Policy first. For Google Analytics, which is a non-essential cookie-based technology, that will also require a consent management mechanism before it loads.
12. Minors
Vulnera is a professional product, intended for people who are technically responsible for systems they own or are authorized to test. We do not direct the service to children or adolescents and we do not knowingly collect their data.
You must be 18 or older to create an account. This is not a formality: when you register an asset, you take on legal responsibility for holding authorization to analyze it (section 4 of the Terms of Use), and that is a responsibility a minor cannot take on. If we learn that we created an account for someone under 18, we will close the account and delete the data.
13. Changes to this Policy
This Policy may change as the product evolves, as new providers come into use, or as regulation changes. The last updated date is always at the top of this page.
When a change is material, for example a new processing purpose, a new provider receiving your data, or a significant change to retention, we publish the new version here, with the date at the top updated, before it takes effect. Wording changes and minor corrections take effect on publication.
14. Contact
Get in touch at contato@vulnera.io. This is our single channel today: use it for privacy and data protection, to exercise your rights, to reach whoever answers for data processing at Vulnera, and to report a vulnerability found in the platform itself. Stating the subject on the first line helps us route your request.
- Controller: Osmir Custodio Mariano Tecnologia da Informação Ltda.
- CNPJ: 53.636.099/0001-89
- Address: Avenida Paulista 1106, sala 01, 16th floor, Bela Vista, São Paulo/SP, 01310-914, Brazil
- Email: contato@vulnera.io