Effective date: 30 June 2026
Privacy Policy
threats.run builds security operations software for SOC triage, cyber threat intelligence, external exposure monitoring, detection engineering, and analyst-approved response workflows. This Privacy Policy explains what information we collect, how we use it, and the choices available to visitors, customers, and authorized users.
This page is written for the public website and early product access. If you enter into a separate agreement, order form, data processing addendum, or security schedule with threats.run, those documents may contain additional or more specific terms for your workspace.
1. Scope
This Privacy Policy applies to the threats.run website, product pages, contact and waitlist forms, product workspaces, APIs, notifications, and related services that link to this policy. It covers information processed when you browse the site, request access, communicate with us, or use AI SOC and AI CTI features.
Customer security data is handled differently from ordinary website contact data. Security data may include alerts, indicators, investigation notes, threat intelligence, protected domains, detection rules, evidence, and other operational material submitted to or generated inside a workspace.
2. Information we collect
Information you provide
- Contact details such as name, work email, company, role, and message content.
- Waitlist, pilot, procurement, support, partnership, or security questionnaire information.
- Account and workspace details such as organization name, invited users, permissions, preferences, notification channels, and configuration choices.
- Content you submit to the product, including alerts, URLs, domains, IOCs, notes, verdicts, suppression rules, detection preferences, reports, and response handoff material.
Information collected automatically
- Website and product logs such as IP address, browser type, device type, referring page, requested URL, timestamps, and basic diagnostic information.
- Security and reliability logs used to detect abuse, protect accounts, debug failures, rate limit requests, and investigate incidents.
- Usage metadata such as pages viewed, features used, searches performed, API endpoints called, notification delivery status, and product performance metrics.
- Cookie or similar browser storage data where needed for authentication, preferences, security, analytics, or session continuity.
Security operations data
When customers use threats.run, the service may process defensive security material such as SIEM alerts, EDR context, identity events, domains, IP addresses, hashes, URLs, screenshots, CVEs, affected products, actor or malware names, brand monitoring targets, evidence notes, analyst decisions, and response actions. This data is processed to provide the requested security workflow and should be submitted only by authorized users.
3. How we use information
- To operate the website, respond to enquiries, manage waitlist requests, and provide product access.
- To deliver AI SOC and AI CTI workflows, including enrichment, triage, intelligence matching, evidence gathering, detection rule drafting, notifications, reporting, and analyst handoff.
- To secure the service, prevent abuse, detect unauthorized activity, investigate incidents, enforce limits, and maintain auditability.
- To improve reliability, usability, accuracy, performance, and product quality.
- To communicate about access, onboarding, support, service changes, security notices, billing or administrative matters, and product updates.
- To comply with legal obligations, enforce agreements, and protect the rights, safety, and security of threats.run, customers, users, and the public.
4. AI-assisted processing
threats.run may use AI-assisted systems to summarize alerts, connect evidence, draft detection logic, prepare analyst notes, classify risk, suggest response actions, or explain why a signal may matter. AI outputs are intended to assist security teams, not replace analyst judgment.
We design product workflows so that operational action remains reviewable by authorized users. Customers are responsible for validating AI-assisted outputs before blocking, escalating, notifying, taking down, reporting, or otherwise acting on them.
5. Cookies and analytics
We may use cookies, local storage, server logs, or privacy-conscious analytics to keep sessions secure, remember preferences, understand site performance, and improve product experience. You can configure your browser to block or delete cookies, but some authenticated or preference-based features may not work correctly without them.
6. How we share information
We do not sell personal information. We may share information only in the following circumstances:
- With service providers that help operate hosting, infrastructure, analytics, communications, support, security, payment, or monitoring services.
- With customer-authorized integrations such as ticketing, chat, email, SOAR, SIEM, webhook, or notification destinations configured in a workspace.
- With members of your organization or workspace according to permissions, roles, and product configuration.
- When required by law, legal process, regulatory request, or to protect rights, safety, security, or service integrity.
- In connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate confidentiality and continuity protections.
7. Third-party sources and integrations
Security workflows may use third-party intelligence sources, enrichment providers, public datasets, customer-configured integrations, or external APIs. These sources may return information about domains, IPs, URLs, malware, vulnerabilities, threat actors, exposed services, certificates, DNS records, phishing reports, and other security-relevant signals.
If you connect third-party tools to threats.run, those providers may process information according to their own terms and privacy policies. Customers should review the privacy and security posture of any integration they choose to enable.
8. Security and access controls
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, misuse, loss, and alteration. These may include access controls, least-privilege practices, logging, monitoring, encryption in transit, secure infrastructure configuration, and operational review processes.
No internet service can guarantee absolute security. Customers should use strong authentication, limit workspace access to authorized personnel, review integrations, and avoid submitting data they are not permitted to process.
9. Retention
We retain information for as long as needed to provide the service, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and preserve audit trails. Retention periods may vary depending on the data type, workspace configuration, customer agreement, and operational need.
Customers may request deletion or export of workspace data where supported and legally permissible. Some logs, backups, security records, or audit data may remain for a limited period after deletion requests if needed for security, compliance, or continuity.
10. International processing
Information may be processed in countries where threats.run, its infrastructure providers, or service providers operate. Where required, we use appropriate safeguards for cross-border transfers and vendor processing.
11. Your choices and rights
Depending on your location and relationship with threats.run, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also request that we stop sending non-essential communications.
If your account is provided by your employer or organization, some requests may need to be handled through that organization as the workspace administrator or data controller.
12. Children
threats.run is not directed to children and is intended for professional security operations use. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this Privacy Policy as the product, legal requirements, or operational practices change. When we make material changes, we will update the effective date and, where appropriate, provide additional notice.
14. Contact
Questions, privacy requests, and security enquiries can be sent to hello@threats.run.