Privacy Policy
Last updated: August 27, 2026
This Policy has not been reviewed or approved by legal counsel. Contact dsovan2004@gmail.com with privacy questions or requests.
1. Who We Are
DefendML is an offensive AI red team testing service operated by Sareth Dustin Sovan trading as DefendML (“DefendML,” “we,” or “us”). Contact: dsovan2004@gmail.com.
2. Data We Collect
- Account and organization data: email address, name, authentication identifiers, organization information, membership, role, and entitlement state.
- Authentication and session data: information needed to create, maintain, verify, and end authenticated sessions, including access and refresh tokens stored by the authentication client in browser storage.
- Target configuration: Target name, description, type, URL, endpoint path, environment, rate and timeout settings, tags, metadata, authentication method, credentials, custom headers, and related declarations.
- Assessment and evidence data: assessment scope and objective, attack prompts, Target responses, decisions, findings, evidence, detection information, timing and job state, Reports, Fix Plan records, remediation cases, and retest outcomes.
- Service and support data: audit events, lifecycle and operational events, technical request information, browser-provided device/network information processed by our infrastructure, and communications you send us.
- Billing data: organization-level customer, subscription, entitlement, and billing-event metadata created during authorized Stripe test-mode validation. DefendML does not currently accept live public payments and does not store payment-card details.
3. How We Use Data
- Authenticate users, resolve organization membership, and enforce tenant-scoped access.
- Configure Targets, run authorized assessments, dispatch and monitor jobs, produce findings, Reports, Fix Plan guidance, and retest records.
- Provide support, service communications, security monitoring, incident response, audit history, and abuse prevention.
- Maintain and improve the Service using operational data and appropriately minimized aggregate signals.
- Meet legal obligations and respond to valid legal process.
DefendML does not use Customer prompts, Target responses, or evidence Reports to train general-purpose AI models.
4. Target Credentials and Sensitive Configuration
Target credentials and custom-header values may be stored for use in an authorized assessment. They are write-only from the customer-facing browser after submission: browser-safe Target responses expose configuration status rather than stored values. DefendML also applies evidence redaction intended to prevent configured Target-secret values from appearing in retained evidence and customer-facing Reports. No security control is infallible; do not submit credentials that are unnecessary for the assessment.
5. AI and Assessment Processing
Assessment prompts and Target responses may be processed by AI inference services to classify results and generate contextual findings or remediation guidance. We limit the data sent to what is needed for that function and do not intentionally include account credentials or stored Target-secret values. Provider identity and data-location obligations require review for a customer's specific contractual or regulatory requirements; contact us before submitting regulated or specially restricted data.
6. Service Providers
Verified service providers include:
- Supabase: database and authentication infrastructure.
- Cloudflare: website and application delivery, Pages Functions, Workers, and edge networking.
- Google: optional Google authentication when selected by a user.
- Resend: configured service-email delivery for supported notification workflows.
- Stripe: test-mode billing foundation; live public payment collection is disabled.
- AI inference services: assessment classification and contextual guidance where configured.
These providers process data under their own terms and privacy notices. The precise provider, region, transfer mechanism, retention, and contractual role can vary by service configuration. A counsel-reviewed subprocessor register and international-transfer position are not yet published.
7. Browser Storage, Cookies, and Tracking
The authenticated application uses browser storage to maintain Supabase authentication sessions and limited workflow preferences. Authentication providers may use their own session technologies. Cloudflare and other infrastructure providers process technical request data needed to deliver and secure the Service.
Current application source does not include an advertising pixel or third-party behavioral-analytics SDK. DefendML does not sell personal data or use it for cross-context behavioral advertising. This statement does not mean that no service provider receives technical data necessary to provide its service.
8. Sharing and Disclosure
We disclose data to service providers as needed to operate the Service; to an organization's authorized users; when you direct or authorize disclosure; to protect the Service, customers, or others; and when required by applicable law or valid legal process. We do not sell or rent Customer Data, and we do not disclose one customer's data to another customer.
9. Retention and Deletion
DefendML does not currently publish fixed retention periods for every data category. We retain data while needed to provide and secure the Service, preserve authorized audit and evidence history, meet legal obligations, resolve disputes, and maintain backups. Retention depends on the data type, organization status, technical deletion capability, security needs, and applicable agreement or law.
You may request account or data deletion by contacting us. Requests are verified and evaluated against organization ownership, security, backup, audit-history, contractual, and legal requirements. The current product does not provide a complete self-service account-deletion workflow, and deletion may not be immediate or remove data that must be retained.
10. Privacy Requests and Applicable Rights
Depending on where you live and whether a privacy law applies to DefendML's processing, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about disclosures. These rights are not absolute and may be subject to verification and legal exceptions.
Send requests to dsovan2004@gmail.com. We will respond within the period required by applicable law. Whether particular U.S. state, EU, UK, or other privacy laws apply to DefendML requires review based on company scale, customer location, processing role, and the relevant statutory thresholds.
11. Security and Incidents
DefendML uses safeguards including encrypted network transport, authenticated access, organization-scoped authorization, credential redaction boundaries, and security testing. No system is completely secure. If an incident creates a notification obligation, DefendML will provide notice as required by applicable law or an executed agreement; this Policy does not promise a universal notification deadline.
12. Children
DefendML is a business service and is not directed to children. If you believe a child has provided personal data, contact us so the circumstances can be reviewed. This statement does not establish an unverified age threshold.
13. International Processing
DefendML and its providers may process data in the United States and other locations where they operate. We do not currently promise a customer-selected residency region. The applicability of GDPR, UK GDPR, cross-border transfer mechanisms, or other regional requirements must be evaluated for the relevant customer and processing activity before regulated or residency-restricted data is submitted.
14. Policy Changes
We may update this Policy by posting the revised version and effective date here. If applicable law or an executed agreement requires additional notice or consent, we will follow that requirement. Whether this update requires direct notice or renewed consent is a counsel-review item.
15. Contact
Privacy questions or requests: dsovan2004@gmail.com