Privacy Policy
Last updated: July 21, 2026
1. Introduction
Krytho ("we," "us," or "our") is operated by Orange-Robot LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at krytho.com and our security review services (collectively, the "Service").
2. What a Review Involves
To review your application we need access to your source code, usually through a read-only connection to your repository, and the address of the running application. Where you have authorized testing in writing, we send requests to that application in the same way a user or an attacker would.
This means we handle two categories of sensitive material that most services never touch. The first is your source code, which we read but do not redistribute. The second is whatever a working security test surfaces, which routinely includes credentials, session tokens, API keys, and fragments of production data that happen to be exposed by the vulnerability being demonstrated.
We treat that second category as hostile material rather than as findings data. It is encrypted at rest, redacted by default wherever it is displayed, kept only as long as needed to demonstrate and fix the issue, and never written to our application logs. We ask you to provide dedicated test accounts so that testing does not touch accounts belonging to real users, though we cannot guarantee that a vulnerability will not expose real data when we demonstrate it.
3. Information We Collect
Information you provide:
- Repository access, source code, and the address of the application to be reviewed
- The signed authorization identifying scope, and the name, role, and contact details of the person who signed it
- Test account credentials you provide for the engagement
- Email address (used to deliver your scan results and related communications)
- Account information (such as your name and email address) when you create an account. Authentication is handled by Clerk: your password and any two-factor method you enable are managed by Clerk, and we never receive or store your password. If you turn on SMS two-factor authentication, Clerk processes the phone number you provide for that purpose.
- Payment information when you subscribe to a paid plan. Payments are processed by Stripe: your card details are submitted directly to Stripe, and we never receive or store full card numbers. We retain only your plan status and the Stripe customer and subscription identifiers needed to manage your subscription.
Information we generate on your behalf:
- Requests we send to your application during testing, and the responses it returned, retained as the record of what we did
- Security findings about your application, including any evidence captured while demonstrating them
- Visibility scores, share-of-voice results, and recommendations derived from that research data
Information collected automatically:
- Usage data (pages visited, features used, scan results viewed)
- Device and browser information (browser type and operating system)
- Website activity: pages viewed, browser type, and approximate location (city, region, and country derived from your IP), used to operate the site, prevent abuse, and improve the Service
- IP addresses are stored only as a salted, irreversible hash (used for rate limiting and abuse prevention); we do not retain raw IP addresses
- When you acknowledge an announcement from us, we record that acknowledgment together with request metadata, including a salted, irreversible IP hash, coarse geographic location from edge headers, browser user-agent, accept-language, and referer, as proof of notice; as with other IP data on this page, we do not retain raw IP addresses
- Cookies and similar technologies
4. How We Use Your Information
- To provide the Service, including running the AI-engine research you request and generating your visibility results and recommendations
- To create, authenticate, and secure your account, including two-factor authentication if you enable it
- To process payments and manage your subscription
- To send you scan results, monitoring reports, and service-related communications
- To improve and optimize the Service
- To comply with legal obligations
5. How We Share Your Information
We do not sell your personal information. We may share information with:
- Service providers (sub-processors): Third-party services that help us operate, including Clerk (authentication and account security), Stripe (payment processing and subscription billing), Vercel (hosting), Neon (database), and Cloudflare Turnstile (bot and abuse prevention). We do not share your source code, findings, or testing evidence with any third party except where you direct us to or where we are legally compelled. We also use analytics providers including PostHog, which may include session replay and heatmaps to help us improve the product, and email providers to operate and communicate about the Service.
- Legal requirements: When required by law, regulation, or legal process
- Business transfers: In connection with a merger, acquisition, or sale of assets
6. Data Retention
Different material is kept for different periods, deliberately.
Evidence captured during testing, including any credentials or data a vulnerability exposed, is kept only as long as needed to demonstrate and resolve the issue and is then deleted. Findings and reports are retained for the life of your engagement so that a re-review can compare against them. Signed authorizations are retained after an engagement ends, because they are the record of what you permitted us to do and when, and deleting them would leave us unable to account for testing already performed.
You may request deletion of your data at any time. Where a seal has been issued, the findings behind it are retained while that seal is valid, since a seal with no supporting record asserts something we could no longer evidence. Ask us to revoke the seal and the underlying record can then be erased.
7. Data Security
We encrypt in transit (TLS) and at rest, and we encrypt the most sensitive fields individually rather than relying on disk encryption alone. Testing evidence is redacted by default in reports and interfaces and is excluded from application logs.
We are a security company and we are not exempt from the failure mode we are hired to find. No method of transmission or storage is completely secure, and we do not claim otherwise.
8. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, including under the EU/UK GDPR and the California Consumer Privacy Act (CCPA), you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information
- Object to or restrict processing of your information
- Data portability
- Opt out of the sale of personal information (note: we do not sell personal information)
To exercise any of these rights, including a request to access or delete your data, contact us at support@krytho.com. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising your rights.
9. Third-Party Platforms and Services
Reviewing your application means interacting with the platforms it runs on, including your hosting and repository providers. Your relationship with those providers is governed by their own terms and privacy policies, not ours, and their restrictions on security testing apply regardless of what you authorize us to do.
10. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date.
12. Contact Us
If you have questions about this Privacy Policy or wish to make a data access or deletion request, contact us at:
Orange-Robot LLC
260 Williamson Blvd
Suite 731678
Ormond Beach, FL 32174
Email: support@krytho.com
