Legal
Privacy Policy
This page will tell visitors, prospects, customers, and researchers what personal and organizational data SecurityBoat and the TriNetra platform collect, why, how long it's kept, who it's shared with, and what rights a person has over their own data — covering the marketing site (this domain), the Let's Connect lead form, the researcher application flow, and the TriNetra product itself.
⚠︎ Full legal text pending counsel review.
Nothing below is drafted policy language — it is a structural outline of the sections the final page will contain. Do not publish, link from a binding flow, or represent this page as final until legal counsel has reviewed and approved the language.
Planned coverage
What this privacy policy will cover
Who this policy applies to — website visitors, lead-form submitters, TriNetra platform customers (client-side users), registered security researchers, and job applicants.
What data is collected — form submissions (name, work email, company, role), platform telemetry (asset data, findings, engagement records), authentication data, and standard web analytics/cookies.
Why it's collected — responding to inquiries, delivering the TriNetra platform and its findings/reporting features, researcher vetting and payouts, legal and compliance obligations (e.g. SOC 2, ISO 27001 evidence retention ⚠︎).
How it's shared — sub-processors (with a link to the Trust Center's Sub-processor List document), payment processors for researcher payouts, and any regulator-mandated disclosure.
Data retention — how long findings, engagement, and account data are kept after an engagement or account closes ⚠︎ (retention periods not yet finalized).
User rights — access, correction, deletion, and export requests, and how to submit one.
Security measures — a summary reference to SecurityBoat's own security posture without duplicating the Trust Center's detailed control library.
International data transfers — relevant given BFSI/regulated Indian clients alongside international (GDPR-scope) prospects.
Cookie and tracking disclosure — what's used on the marketing site itself.
Contact for privacy requests — a named channel, once assigned ⚠︎.
Placeholder metadata
Not yet finalized
- Effective date:
- ⚠︎ to be set on publish
- Governing entity:
- SecurityBoat ⚠︎ confirm exact legal entity name with counsel
- Contact:
- ⚠︎ privacy contact address pending
Questions about your data before this policy is finalized? Reach us directly.
