Effective date: 30 June 2026

Privacy Policy

threats.run builds security operations software for SOC triage, cyber threat intelligence, external exposure monitoring, detection engineering, and analyst-approved response workflows. This Privacy Policy explains what information we collect, how we use it, and the choices available to visitors, customers, and authorized users.

This page is written for the public website and early product access. If you enter into a separate agreement, order form, data processing addendum, or security schedule with threats.run, those documents may contain additional or more specific terms for your workspace.

1. Scope

This Privacy Policy applies to the threats.run website, product pages, contact and waitlist forms, product workspaces, APIs, notifications, and related services that link to this policy. It covers information processed when you browse the site, request access, communicate with us, or use AI SOC and AI CTI features.

Customer security data is handled differently from ordinary website contact data. Security data may include alerts, indicators, investigation notes, threat intelligence, protected domains, detection rules, evidence, and other operational material submitted to or generated inside a workspace.

2. Information we collect

Information you provide

Information collected automatically

Security operations data

When customers use threats.run, the service may process defensive security material such as SIEM alerts, EDR context, identity events, domains, IP addresses, hashes, URLs, screenshots, CVEs, affected products, actor or malware names, brand monitoring targets, evidence notes, analyst decisions, and response actions. This data is processed to provide the requested security workflow and should be submitted only by authorized users.

3. How we use information

4. AI-assisted processing

threats.run may use AI-assisted systems to summarize alerts, connect evidence, draft detection logic, prepare analyst notes, classify risk, suggest response actions, or explain why a signal may matter. AI outputs are intended to assist security teams, not replace analyst judgment.

We design product workflows so that operational action remains reviewable by authorized users. Customers are responsible for validating AI-assisted outputs before blocking, escalating, notifying, taking down, reporting, or otherwise acting on them.

5. Cookies and analytics

We may use cookies, local storage, server logs, or privacy-conscious analytics to keep sessions secure, remember preferences, understand site performance, and improve product experience. You can configure your browser to block or delete cookies, but some authenticated or preference-based features may not work correctly without them.

6. How we share information

We do not sell personal information. We may share information only in the following circumstances:

7. Third-party sources and integrations

Security workflows may use third-party intelligence sources, enrichment providers, public datasets, customer-configured integrations, or external APIs. These sources may return information about domains, IPs, URLs, malware, vulnerabilities, threat actors, exposed services, certificates, DNS records, phishing reports, and other security-relevant signals.

If you connect third-party tools to threats.run, those providers may process information according to their own terms and privacy policies. Customers should review the privacy and security posture of any integration they choose to enable.

8. Security and access controls

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, misuse, loss, and alteration. These may include access controls, least-privilege practices, logging, monitoring, encryption in transit, secure infrastructure configuration, and operational review processes.

No internet service can guarantee absolute security. Customers should use strong authentication, limit workspace access to authorized personnel, review integrations, and avoid submitting data they are not permitted to process.

9. Retention

We retain information for as long as needed to provide the service, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and preserve audit trails. Retention periods may vary depending on the data type, workspace configuration, customer agreement, and operational need.

Customers may request deletion or export of workspace data where supported and legally permissible. Some logs, backups, security records, or audit data may remain for a limited period after deletion requests if needed for security, compliance, or continuity.

10. International processing

Information may be processed in countries where threats.run, its infrastructure providers, or service providers operate. Where required, we use appropriate safeguards for cross-border transfers and vendor processing.

11. Your choices and rights

Depending on your location and relationship with threats.run, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also request that we stop sending non-essential communications.

If your account is provided by your employer or organization, some requests may need to be handled through that organization as the workspace administrator or data controller.

12. Children

threats.run is not directed to children and is intended for professional security operations use. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this Privacy Policy as the product, legal requirements, or operational practices change. When we make material changes, we will update the effective date and, where appropriate, provide additional notice.

14. Contact

Questions, privacy requests, and security enquiries can be sent to hello@threats.run.