Privacy Policy

Last updated: [DATE]

VulnLogic is operated by 3 Orbit Solutions Sdn. Bhd. ("3OrbSol", "we", "us"), a company registered in Malaysia. This policy explains what data we collect when you use VulnLogic, why we collect it, and how it's handled.

What We Collect

Account information. Email address and authentication credentials. Paid tiers use Stripe for billing — we never store card details.

Scan configuration. The target URL/API address and any OpenAPI spec you upload.

Authentication tokens you provide. Used only for the duration of a scan, then discarded — never stored in plaintext.

Scan results. Findings and evidence generated during a scan. The free CLI sends nothing to our servers — it runs entirely on your machine.

What We Do Not Collect

We never access anything beyond the target you explicitly provide. We never sell your data.

Third-Party Processors

Stripe (payments), Supabase (auth/account data), and our hosting provider process data on our behalf under their own privacy policies.

Data Retention

Scan history is retained for the duration of your subscription plus 30 days after cancellation. Auth tokens are discarded immediately after each scan.

Your Rights

Request access, correction, or deletion of your data anytime at contact@3orbsol.my.

Contact

3 Orbit Solutions Sdn. Bhd.
Kuala Lumpur, Malaysia
contact@3orbsol.my