Skip to content
SolrSunriseSecurity Company
PlatformPentestWhy SolrSunrisePricingResources
Sign inStart free

Privacy policy

SolrSunrise Web Application Privacy Policy

How SolrSunrise collects, uses, discloses, and protects information across its website, application, scanner workflows, APIs, and related services.
Provider
SolrSunrise LLC
Brand
SolrSunrise
Application / Sites
solrsunrise.com, app.solrsunrise.com, and related SolrSunrise web portals, dashboards, scanners, hosted workflow tools, APIs, and customer-accessible application features
Effective Date
2026-05-31

1. Overview

This Privacy Policy explains how SolrSunrise LLC (“SolrSunrise,” “we,” “us,” or “our”) collects, uses, discloses, and protects information through our websites, web application, portals, dashboards, scanner orchestration tools, APIs, support channels, and related services (the “Application”).

This Policy applies to website visitors, prospective customers, customer contacts, account administrators, invited users, analysts, remediation owners, scanner operators, and other Application users. Customer contracts, Data Processing Addenda, security testing authorizations, and SOWs may provide additional or more specific rules for customer data and regulated workflows.

2. Information We Collect

We may collect the following categories of information depending on how the Application is used:

  • Account and identity information: name, email address, role, customer/account organization, invitation status, authentication status, and password or credential metadata. Passwords are stored in hashed form.
  • Authentication, session, and scanner identity information: session identifiers, hashed session tokens, pending OTP/enrollment data, sign-in events, invite acceptance records, scanner enrollment records, certificate metadata, public certificates, certificate fingerprints, serial numbers, timestamps, and security-related metadata.
  • Business and customer information: organization name, business type, contact information, account details, billing status, plan information, implementation materials, notes, and support requests.
  • Asset, scan, and finding information: asset inventories, hostnames, IP addresses, domains, cloud/account identifiers, scan scope, scanner policy selections, vulnerability findings, risk scores, remediation statuses, evidence, screenshots, logs, reports, and audit events.
  • Workflow and remediation data: ownership assignments, tasks, remediation notes, exceptions, approvals, comments, report exports, policy configuration, scanner YAML templates, routing decisions, and review-status information.
  • Billing and payment-related information: plan name, plan code, status, billing interval, charge labels, invoice data, and payment-processing metadata. Full payment-card numbers are handled by payment processors when payment features are used.
  • Communications: emails, form submissions, support messages, meeting notes, uploaded materials, feedback, and other communications with us.
  • Device, log, and usage data: IP address, browser, device, pages viewed, referring URLs, timestamps, diagnostic logs, cookie data, API calls, scanner callbacks, and actions taken in the Application.

3. Sensitive Information and Security Data

SolrSunrise is designed for authorized defensive security operations. Customers are responsible for ensuring that scan scope, asset data, evidence, reports, and uploaded materials may lawfully be processed through the Application. Do not submit protected health information, payment-card numbers, government IDs, employee background files, trade secrets, production credentials, exploit payloads, malware, or other highly sensitive data unless a written agreement specifically authorizes that use.

We do not intentionally collect scanner private keys after issuance. Customers and scanner operators are responsible for securing scanner credentials, tokens, certificates, private keys, logs, and deployment environments.

4. Cookies and Similar Technologies

The Application may use cookies, local storage, session storage, and similar technologies for:

TypePurposeExamples
Essentialauthentication, session management, invite acceptance, security, CSRF protection, load balancing, and app operationsession cookies, pending OTP/enrollment cookies
Preferenceremembering interface or workflow contextselected customer/account, tenant, dashboard, or application preferences where enabled
Analytics / diagnosticsunderstanding usage, performance, errors, and security eventsfirst-party logs or analytics tools if enabled
Marketingmeasuring campaigns or website referralsonly if marketing or advertising tools are enabled

You can control cookies through your browser. Disabling essential cookies may prevent the Application from working.

5. How We Use Information

We use information to:

  • provide, operate, secure, and maintain the Application;
  • authenticate users, manage sessions, process invitations, enroll scanners, validate scanner identity, and enforce role-based access;
  • create and manage accounts, customers, users, memberships, permissions, scanner certificates, policies, and audit logs;
  • support asset inventory, scanning, finding triage, risk prioritization, remediation tracking, evidence capture, and reporting features;
  • process customer requests, implementation tasks, support tickets, and service communications;
  • provide AI-assisted workflow routing, summarization, classification, and remediation suggestions subject to human review;
  • administer billing, plans, subscriptions, invoices, and payment processing;
  • monitor performance, troubleshoot errors, prevent fraud, detect security incidents, and investigate misuse;
  • comply with legal, contractual, accounting, tax, audit, privacy, security, sanctions, and data-protection obligations;
  • enforce agreements and protect our rights, users, customers, services, and third parties; and
  • improve Application usability, reliability, security, scanner safety, and service offerings.

6. Legal Bases for Processing

Where GDPR or similar law applies, we rely on one or more of the following legal bases:

PurposeLegal Basis
Account access, authentication, service delivery, scanner operation, billing, and supportContractual necessity
Security monitoring, fraud prevention, diagnostics, service improvement, and administrative operationsLegitimate interests
Tax, accounting, legal response, sanctions, security, and regulatory obligationsLegal obligation
Optional marketing, non-essential cookies, and certain communicationsConsent where required
Customer data and scan-result processingCustomer instructions and applicable agreements

7. How We Share Information

We may share information with:

  • Customer organizations and authorized administrators to manage their accounts, users, scanners, assets, workflows, billing, audit events, and data;
  • Service providers such as cloud hosting, database, email, security, analytics, monitoring, payment, support, document, AI/API, scanner, and infrastructure providers;
  • Integration partners when a customer authorizes integrations with ticketing, SIEM, EDR, cloud, messaging, document, storage, payment, or other systems;
  • Professional advisors such as lawyers, accountants, auditors, insurers, and security consultants;
  • Authorities or third parties when required by law, subpoena, court order, regulatory request, vulnerability-disclosure duty, or to protect rights and safety;
  • Business transaction parties in connection with a merger, financing, acquisition, reorganization, or sale of assets; and
  • Others with consent or customer instruction.

We do not sell personal information in the ordinary sense. If any future advertising or analytics activity constitutes “sale” or “sharing” under California law, we will provide required notices and opt-out mechanisms.

8. AI Providers and Model Processing

When AI-assisted features are enabled, information may be processed by AI model providers or infrastructure providers to generate workflow drafts, classifications, summaries, routing suggestions, remediation language, or other outputs. Customer agreements may restrict which data can be sent to specific AI providers and whether data may be used for model training. Unless expressly stated in a signed agreement, users should not assume AI outputs are final, accurate, complete, or appropriate without human review.

9. Data Retention

We retain information for as long as needed to provide the Application, maintain accounts, comply with agreements, resolve disputes, enforce terms, meet legal/tax/accounting/security obligations, preserve audit logs, maintain backups, support customers, and investigate misuse. Typical retention categories include:

Data TypeTypical Retention
Account and user recordsduration of account access plus a reasonable administrative period
Sessions and authentication logsas needed for security, troubleshooting, and audit purposes
Scanner certificate metadata and enrollment eventsas needed for scanner identity, revocation, audit, and security purposes
Customer assets, findings, evidence, and workflow dataas directed by customer agreements and operational needs
Billing and transaction recordsas required for accounting, tax, chargeback, and legal obligations
Support and communicationsas needed for service history, legal, and operational needs
Backups and logsretained according to backup, disaster recovery, and security practices

10. Security

We use commercially reasonable technical and organizational safeguards designed to protect information, including role-based access controls, hashed credentials/session tokens, secure cookies, audit logs, encryption in transit where supported, scanner identity checks, certificate metadata tracking, limited access, and security monitoring. No system is perfectly secure. Users and customers must protect credentials, configure access appropriately, use secure devices, secure scanner deployments, and promptly report suspected incidents.

11. Your Privacy Choices and Rights

Depending on your location and relationship to us, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing is based on consent. Requests may be subject to identity verification, customer-admin approval, legal exceptions, contract restrictions, retention obligations, and security limitations.

Authorized users seeking access to customer-controlled data should usually contact their organization’s administrator first. Privacy requests may be sent to privacy@solrsunrise.com or legal@solrsunrise.com.

12. California Privacy Notice

California residents may have rights to know, access, correct, delete, and opt out of certain sale or sharing of personal information, and to limit use of sensitive personal information where applicable. We do not discriminate for exercising privacy rights.

Categories of personal information we may collect include identifiers, professional or employment-related information, commercial information, internet or electronic network activity, account credentials, security logs, and sensitive personal information where required for authorized services. We collect and use these categories for the purposes described in this Policy.

13. International Users

Information may be processed in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards such as contractual commitments, data processing agreements, and customer instructions.

14. Children

The Application is not directed to children under 13, and we do not knowingly collect personal information from children through public websites or the Application.

15. Changes to This Policy

We may update this Policy from time to time. The updated version will be posted with a new effective date. Material changes may also be communicated through the Application, email, or other reasonable notice.

16. Contact

Privacy questions or requests may be sent to privacy@solrsunrise.com or legal@solrsunrise.com.

SolrSunriseDefense begins before dawn.
Vulnerability managementApplication scanningPentest servicesPricingWhy SolrSunriseExposure monitoringMSSP workflowComparisonsSecurityPrivacyTerms
SolrSunrise LLCWeb address: solrsunrise.com

© 2026 SolrSunrise LLC. Built for authorized security work.