🔒 Enterprise Security • SOC2 Compliant
Your privacy and data security are fundamental to our mission. Learn how Obsedian protects, processes, and respects your information.
At Obsedian, we understand that your trust is earned through transparency and demonstrated security practices. This Privacy Policy explains how we collect, use, protect, and share your information when you use our security testing platform and related services.
Your application source code and sensitive security data are processed locally and encrypted in transit. We implement strict access controls and data isolation to ensure your security information remains confidential and is only accessible to authorized personnel for platform improvement purposes.
Provide security testing, vulnerability assessment, and platform functionality
Manage your account, process payments, and provide customer support
Analyze usage patterns to enhance features and security capabilities
We do not sell, rent, or trade your personal information. We only share information in the following limited circumstances:
Trusted third-party vendors who help us operate our platform:
When required by law or to protect our rights:
In the event of a business transaction:
When you explicitly agree to share information:
Security is at the core of everything we do. We implement multiple layers of protection to safeguard your data:
We retain your information only as long as necessary to provide our services and comply with legal obligations:
When you delete your account or request data deletion:
You have comprehensive rights regarding your personal information. We provide tools and processes to exercise these rights:
Request a copy of all personal information we have about you
Update or correct any inaccurate personal information
Request deletion of your personal information and account
Export your data in a machine-readable format
Limit how we process your personal information
Object to certain types of data processing activities
Obsedian operates globally while ensuring your data receives adequate protection regardless of where it's processed.
Enterprise customers can choose specific data residency locations to meet regulatory requirements.
For EU residents, we provide additional protections under GDPR, including data processing within the EU where possible and enhanced rights exercising procedures.
We maintain industry-leading certifications and comply with global privacy regulations to earn your trust.
Annual audit of security, availability, and confidentiality controls
CertifiedInternational standard for information security management
CertifiedEuropean Union General Data Protection Regulation
CompliantCalifornia Consumer Privacy Act requirements
CompliantHealthcare data protection capabilities
AvailableFederal government cloud security program
In ProgressHave questions about our privacy practices? We're here to help. Contact our privacy team for assistance with any privacy-related inquiries.
For EU residents and GDPR-related inquiries, contact our dedicated Data Protection Officer.
We respond to privacy inquiries within 30 days. For urgent matters, we aim to respond within 72 hours. GDPR requests are processed within the required 30-day timeframe.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes through email or platform notifications.