Skip to policy
PlatformAgentsSolutions Engineering
Talk to Us

California Privacy

Additional information for California residents about our website and business enquiries.

Review draft · September 6, 2026

Privacy PolicyCalifornia Privacy
About this noticeInformation and sourcesUse and disclosureRetentionSale, sharing, and sensitive informationYour California rightsMake a privacy request
privacy@cipherstep.com
Draft for review. This supplement is being prepared for legal and operational review. It is not a statement of CCPA or GDPR compliance. Our Privacy Policy remains available.

About this notice

This notice supplements the Cipherstep Privacy Policy for California residents who visit our website, submit an assessment application, or contact us about our services. It describes information we process for our own business purposes, not information processed on a customer’s behalf through a deployed product.

The rights described here apply where Cipherstep and the relevant processing are subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA). Applicable exceptions may limit a particular request.

Information and sources

The following categories describe the website and business-enquiry activities covered by our Privacy Policy. Information is received directly from you, through your use of the website, or from providers helping us operate it.

CategoryExamples and sourcesPurpose
Identifiers and contact detailsName, email, phone number, and IP address, from applications, correspondence, booking details, and website requests.Respond to enquiries, arrange meetings, review applications, and protect the website.
Professional informationRole and industry that you provide in your application or conversations with us.Understand your business needs and assess engagement fit.
Enquiry and assessment informationSelected platforms, reasons for requesting a pentest, and related correspondence you provide.Define technical scope and follow up on your request.
Internet and network activityRequest timestamps, browser information, security logs, and website usage information from our hosting, security, and analytics services.Deliver and secure the website, troubleshoot issues, and understand aggregate usage.
Approximate locationCountry-level location derived from website traffic, rather than precise device location.Understand aggregate geographic usage and support website security.

Contact details may also fall within the personal information categories listed in California Civil Code section 1798.80(e). Our forms do not request passwords, government identifiers, financial account credentials, or other sensitive personal information. Please do not include such information in free-text fields.

Use and disclosure

We use these categories to operate and protect the website, evaluate and respond to applications, communicate with prospective customers, maintain relevant records, and meet legal obligations.

Hosting, security, communications, scheduling, and analytics providers may receive the information needed for their work on our behalf. For example, communications providers handle contact details and correspondence, while hosting and security providers handle website requests and logs. Plausible receives website analytics, not application-form contents.

Information may also be disclosed where required by law, to protect rights or safety, or as part of a corporate transaction, as described in the Privacy Policy.

Retention

For each category above, we keep information only as long as reasonably needed for its stated purpose. Retention depends on whether an enquiry or engagement remains active, applicable recordkeeping obligations, security needs, and the establishment or defence of legal claims. Information that is no longer needed is deleted or de-identified, subject to legitimate backup and legal requirements.

Sale, sharing, and sensitive information

As stated in our Privacy Policy, Cipherstep does not sell personal information or share it for cross-context behavioural advertising. We do not disclose application information to third parties for their own direct marketing.

The website does not use advertising trackers. A Global Privacy Control signal therefore does not need to disable a sale or advertising-sharing activity on this site. This is different from a browser’s “Do Not Track” setting.

We do not request sensitive personal information through the application form or use it to infer characteristics about visitors. The website is intended for business users and is not directed to children under 16.

Your California rights

Where the CCPA applies, you may exercise the following rights, subject to the law’s conditions and exceptions:

  • Know and access: Ask what personal information is held about you, its sources, purposes, and recipients, and request a copy.
  • Correct: Request correction of inaccurate personal information.
  • Delete: Request deletion of personal information, subject to permitted retention exceptions.
  • Opt out: Direct a business not to sell your information or share it for cross-context behavioural advertising.
  • Limit sensitive information: Restrict certain uses and disclosures of sensitive personal information where that right applies.
  • Equal treatment: Exercise these rights without unlawful discrimination or retaliation.

For more information, visit the California Privacy Protection Agency’s guide to these rights.

Make a privacy request

Email privacy@cipherstep.com with the right you wish to exercise and enough context to locate your information, such as the email address used in an application. No account is required. Do not send passwords, identity documents, or other sensitive material in your initial email.

We may ask for proportionate information to verify an access, correction, or deletion request and prevent unauthorised disclosure. Verification information is used only for that purpose. An authorised agent may submit a request on your behalf; we may request evidence of authority and, where permitted, direct confirmation from you.

We respond within applicable legal deadlines and explain any permitted extension or exception. Where the CCPA applies, access, correction, and deletion requests generally receive a response within 45 calendar days, with a notified extension where the law permits.

If your request concerns data a Cipherstep customer processes through its application, contact that business so it can handle the request under its own privacy notice.

© 2026 Cipherstep, Inc.
Privacy PolicyCalifornia Privacy