Coastline Cyber Security ("Coastline", "we") is a security testing company based in the Commonwealth of Massachusetts, United States. This policy explains what we collect when you use the Coastline autonomous penetration testing platform, why, and what rights you have. It forms part of our Terms of Service.
Your name, email address, organization name, and authentication identifiers. If you sign in through an identity provider, we receive the profile fields that provider releases.
Payments are processed by Stripe. We do not receive or store your full card number. We retain a customer identifier, plan and credit balance, and transaction metadata sufficient to operate billing and meet tax and accounting obligations.
The scope you submit — domains, IP ranges, rules of engagement, and any prompt text — together with any test credentials you choose to supply.
Discovered hosts and endpoints, tool output, request and response evidence, findings, and the reports generated from them. This material can incidentally include personal data present in your systems, and may include data relating to third parties where your application exposes it.
Logs, timestamps, token and credit consumption, error traces, and standard web server data such as IP address and user agent, used to run, secure, and bill the Service.
| Purpose | Data | Basis (GDPR, where applicable) |
|---|---|---|
| Provide the Service | Account, engagement, scan output | Performance of a contract |
| Billing and tax records | Billing, operational | Contract; legal obligation |
| Security, abuse prevention, debugging | Operational | Legitimate interests |
| Service notifications | Account | Contract |
| Product improvement | Aggregate/operational | Legitimate interests |
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
The Service uses a large language model to plan testing and interpret results. That model — Qwen 3.6 27B — runs on infrastructure Coastline operates directly. Your scope, prompt text, and scan output are not sent to any third-party AI provider, are not used to train any model, and do not leave our environment for inference. For a security product this is deliberate: your vulnerabilities are the last thing that should be sitting in someone else's inference logs.
Data is encrypted in transit using TLS and at rest by our infrastructure providers. Access to production systems and customer findings is restricted to personnel who need it. Reports are stored in per-tenant isolated storage paths, and the application enforces tenant separation on every read.
We do not collect the categories of data that Massachusetts regulation 201 CMR 17.00 defines as personal information — a resident's name combined with a Social Security number, driver's licence or state ID number, or a financial account or payment card number. Card details are handled entirely by Stripe and never reach our systems. Should we begin holding such data, we will implement and maintain a Written Information Security Program as that regulation requires.
No system is perfectly secure, and we do not claim otherwise.
We use the following providers to deliver the Service. Each is bound by confidentiality and data-protection obligations.
| Provider | Function | Data reaching them |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, report storage, CDN | Account, engagement, scan output, operational |
| Stripe, Inc. | Payment processing | Billing and contact details |
| Resend, Inc. | Transactional email delivery | Email address, message content |
Model inference is deliberately absent from this list: it runs on Coastline-operated infrastructure, so no AI provider is a sub-processor of your data.
We will post material changes to this list here before they take effect. Customers requiring notice of sub-processor changes as a contractual term should contact us.
We operate in the United States and our providers may process data in the United States and other countries. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
| Category | Retention |
|---|---|
| Account information | For the life of the account, then up to 12 months |
| Engagement data and findings | Retained while the account is active, so you can compare scans over time; deletable on request at any time |
| Generated reports | As above; deleted with the engagement |
| Test credentials you supply | Deleted at engagement close or on request |
| Billing and tax records | As required by law, typically 7 years |
| Operational logs | Typically 90 days |
Because findings describe live weaknesses in your systems, we encourage you to delete engagements you no longer need. We will do so promptly on request.
If we become aware of a breach of security involving personal information as defined by Massachusetts General Laws Chapter 93H, we will notify affected individuals, the Massachusetts Attorney General, and the Director of Consumer Affairs and Business Regulation as and when that statute requires, and will meet any other notification obligations that apply, including under GDPR where relevant. We will notify affected customers without undue delay.
Subject to applicable law, you may request access to the personal information we hold about you; correction of inaccurate information; deletion; a portable copy; restriction of or objection to certain processing; and withdrawal of consent where processing relies on it.
If you are a California resident, you have the rights described in the CCPA/CPRA, including the right to know, delete, correct, and to opt out of sale or sharing — we do neither. If you are in the EEA or UK, you have the rights described in the GDPR, including the right to lodge a complaint with your supervisory authority.
To exercise any of these, or to have an engagement and its findings deleted, contact us using Section 11. We will not discriminate against you for exercising a right.
We use only cookies and local storage that are necessary to operate the portal — keeping you signed in, preserving your session, and remembering interface preferences. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics that profile you.
Coastline Cyber Security, Massachusetts, United States.
Privacy requests and questions:
coastlinecyber.com/contact-us
To report a security issue in Coastline itself, see /.well-known/security.txt.
We will post any change here with a revised date, and will notify you of material changes where we have your email address.