Privacy Policy

Coastline Cyber Security · Last updated 4 August 2026
The most sensitive data we hold is not personal data — it is your vulnerabilities. Scan findings describe exploitable weaknesses in your systems. Section 4 explains how we protect and retain them, and Section 9 explains how to have them deleted.

1. Who we are

Coastline Cyber Security ("Coastline", "we") is a security testing company based in the Commonwealth of Massachusetts, United States. This policy explains what we collect when you use the Coastline autonomous penetration testing platform, why, and what rights you have. It forms part of our Terms of Service.

2. What we collect

2.1 Account information

Your name, email address, organization name, and authentication identifiers. If you sign in through an identity provider, we receive the profile fields that provider releases.

2.2 Billing information

Payments are processed by Stripe. We do not receive or store your full card number. We retain a customer identifier, plan and credit balance, and transaction metadata sufficient to operate billing and meet tax and accounting obligations.

2.3 Engagement data

The scope you submit — domains, IP ranges, rules of engagement, and any prompt text — together with any test credentials you choose to supply.

2.4 Scan output

Discovered hosts and endpoints, tool output, request and response evidence, findings, and the reports generated from them. This material can incidentally include personal data present in your systems, and may include data relating to third parties where your application exposes it.

2.5 Operational data

Logs, timestamps, token and credit consumption, error traces, and standard web server data such as IP address and user agent, used to run, secure, and bill the Service.

3. Why we process it, and our legal bases

PurposeDataBasis (GDPR, where applicable)
Provide the ServiceAccount, engagement, scan outputPerformance of a contract
Billing and tax recordsBilling, operationalContract; legal obligation
Security, abuse prevention, debuggingOperationalLegitimate interests
Service notificationsAccountContract
Product improvementAggregate/operationalLegitimate interests

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

3.1 Automated processing by AI models

The Service uses a large language model to plan testing and interpret results. That model — Qwen 3.6 27B — runs on infrastructure Coastline operates directly. Your scope, prompt text, and scan output are not sent to any third-party AI provider, are not used to train any model, and do not leave our environment for inference. For a security product this is deliberate: your vulnerabilities are the last thing that should be sitting in someone else's inference logs.

4. How we protect it

Data is encrypted in transit using TLS and at rest by our infrastructure providers. Access to production systems and customer findings is restricted to personnel who need it. Reports are stored in per-tenant isolated storage paths, and the application enforces tenant separation on every read.

We do not collect the categories of data that Massachusetts regulation 201 CMR 17.00 defines as personal information — a resident's name combined with a Social Security number, driver's licence or state ID number, or a financial account or payment card number. Card details are handled entirely by Stripe and never reach our systems. Should we begin holding such data, we will implement and maintain a Written Information Security Program as that regulation requires.

No system is perfectly secure, and we do not claim otherwise.

5. Sub-processors

We use the following providers to deliver the Service. Each is bound by confidentiality and data-protection obligations.

ProviderFunctionData reaching them
Cloudflare, Inc.Application hosting, database, report storage, CDNAccount, engagement, scan output, operational
Stripe, Inc.Payment processingBilling and contact details
Resend, Inc.Transactional email deliveryEmail address, message content

Model inference is deliberately absent from this list: it runs on Coastline-operated infrastructure, so no AI provider is a sub-processor of your data.

We will post material changes to this list here before they take effect. Customers requiring notice of sub-processor changes as a contractual term should contact us.

6. International transfers

We operate in the United States and our providers may process data in the United States and other countries. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

7. How long we keep it

CategoryRetention
Account informationFor the life of the account, then up to 12 months
Engagement data and findingsRetained while the account is active, so you can compare scans over time; deletable on request at any time
Generated reportsAs above; deleted with the engagement
Test credentials you supplyDeleted at engagement close or on request
Billing and tax recordsAs required by law, typically 7 years
Operational logsTypically 90 days

Because findings describe live weaknesses in your systems, we encourage you to delete engagements you no longer need. We will do so promptly on request.

8. Data breach notification

If we become aware of a breach of security involving personal information as defined by Massachusetts General Laws Chapter 93H, we will notify affected individuals, the Massachusetts Attorney General, and the Director of Consumer Affairs and Business Regulation as and when that statute requires, and will meet any other notification obligations that apply, including under GDPR where relevant. We will notify affected customers without undue delay.

9. Your rights

Subject to applicable law, you may request access to the personal information we hold about you; correction of inaccurate information; deletion; a portable copy; restriction of or objection to certain processing; and withdrawal of consent where processing relies on it.

If you are a California resident, you have the rights described in the CCPA/CPRA, including the right to know, delete, correct, and to opt out of sale or sharing — we do neither. If you are in the EEA or UK, you have the rights described in the GDPR, including the right to lodge a complaint with your supervisory authority.

To exercise any of these, or to have an engagement and its findings deleted, contact us using Section 11. We will not discriminate against you for exercising a right.

10. Cookies

We use only cookies and local storage that are necessary to operate the portal — keeping you signed in, preserving your session, and remembering interface preferences. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics that profile you.

11. Contact

Coastline Cyber Security, Massachusetts, United States.
Privacy requests and questions: coastlinecyber.com/contact-us

To report a security issue in Coastline itself, see /.well-known/security.txt.

12. Changes

We will post any change here with a revised date, and will notify you of material changes where we have your email address.