Privacy Policy
Last updated: May 2026
Who we are
Secureflo provides AI-accelerated security intelligence, regulatory tracking, and self-service security readiness assessments. The data controller is Secureflo, reachable at karunakar@secureflo.net. Business address: Concord, USA. For data-protection inquiries, please use the same email.
Scope
This Privacy Policy describes how we collect and use personal data when you use knowledge.secureflo.net and related Secureflo products. It applies to visitors, registered users, and those who request our consulting services through this site.
What we collect
- Business email address — required to verify you are a business user and to deliver the personalized intelligence feed and assessment report.
- One-time verification codes — short-lived 6-digit codes we send to your email to confirm ownership. Codes expire within 10 minutes.
- Context you provide — country (and where applicable, US state, Canadian province, EU member state, Australian state, or UAE zone), industry, company size, role, optional tech stack, compliance frameworks, and any optional free-text notes you add to assessment questions.
- Assessment data — your multiple-choice responses, the AI-generated questions, scores, risk findings, and action plan associated with your session.
- Authentication data — if you sign in, we store your email and (when provided by your identity provider) display name and profile picture, via Supabase Auth and Google OAuth.
- Usage and operational data — IP address (for rate limiting and fraud prevention), request timestamps, browser user-agent, session identifiers, and error logs (with personal identifiers scrubbed where possible).
- Cookies and local storage — see "Cookies and local storage" below.
How we use your data
- To verify you and deliver the personalized intelligence feed, assessment, and report you requested.
- To send transactional emails such as verification codes and report deliveries.
- To contact you about Secureflo consulting services where you have explicitly requested them through the Contact form, "Talk to an Expert" flow, or by sending us an email.
- To operate and secure the service: rate limiting, abuse prevention, debugging, and incident response.
- To analyze aggregate usage and improve our questions, prompts, and product. We do not sell personal data.
- To comply with applicable legal obligations and to defend our legal rights.
Legal bases (EU/UK/Swiss users)
- Contract — to deliver the assessment, feed, and report you requested.
- Legitimate interest — to operate the service, prevent abuse, and offer relevant follow-up to business users. We balance this against your interests and rights.
- Consent — for optional analytics cookies and for marketing communications.
- Legal obligation — for retention and disclosure required by applicable law.
Sub-processors and recipients
We engage the following sub-processors to operate the service. Each is bound by contractual confidentiality and security obligations.
- Google Cloud (Cloud Run, Secret Manager, Cloud Logging) — application hosting and infrastructure secrets.
- Supabase — Postgres database, authentication, and session storage.
- Anthropic — AI model provider for generating questions, articles, regulatory summaries, and assessment analysis. Submitted prompts may include your context and answers; we send only the data required to produce your output, and Anthropic does not use API content to train its models under our configuration.
- Resend — transactional email delivery (verification codes and report emails).
- Google (OAuth) — optional "Sign in with Google."
- Cloudflare — DNS for our domains.
- PostHog — product analytics. Loaded only after you accept the cookie banner. We send domain-level identifiers (not raw email).
- Sentry — error monitoring. Captured events pass through a PII scrubber that removes emails and tokens.
We do not sell personal data and do not share assessment answers or free-text notes with third parties beyond what is necessary to operate the service.
AI processing disclosure
When you request a personalized feed, regulatory summary, or assessment, we transmit relevant context (industry, country, company size, role, and your assessment answers) to our AI sub-processor (Anthropic) to generate output. Free-text notes you add are also transmitted. Output is generated by large language models, which may produce inaccurate, incomplete, or outdated information. You should independently verify any regulation, statistic, or finding before relying on it for security, compliance, or legal decisions.
Data retention
- Verification codes — expire within 10 minutes.
- Rate-limit logs — purged within 24 hours.
- Assessment sessions and report data — retained for as long as you have an active relationship with us, plus up to 24 months thereafter for customer-support and compliance purposes, unless you ask us to delete sooner.
- Business leads (email addresses captured through forms) — retained for as long as necessary to respond to your inquiry and follow up on related Secureflo services, subject to your right to request deletion.
- Sign-in account data — retained while your account exists; deleted on request, subject to a brief residual retention for audit/security purposes.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, export (data portability), or restrict processing of your personal data; to object to processing based on legitimate interests; and to withdraw consent at any time. EU/UK residents may also lodge a complaint with their local supervisory authority.
California residents (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect, to delete personal information we hold about you, to correct inaccurate information, to opt out of any "sale" or "sharing" of personal information (we do not engage in either), and to non-discrimination for exercising these rights.
To exercise any of these rights, email karunakar@secureflo.net. We respond within 30 days (45 days for CCPA requests, extendable to 90 days for complex requests with notice).
International transfers
Secureflo and our sub-processors operate in multiple regions including the United States and the European Union. If you are located outside the United States, your personal data will be transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home country. For EU/UK/Swiss residents, we rely on Standard Contractual Clauses or equivalent safeguards with our sub-processors. You may request a copy of these safeguards by contacting us.
Cookies and local storage
We use strictly necessary cookies and browser local storage to operate the service: session tokens, rate-limit identifiers, and assessment state so you do not lose progress on refresh. With your consent (via the cookie banner), we also use product analytics (PostHog) to understand aggregate usage. You can withdraw consent at any time by clearing the relevant entries in your browser's local storage and cookies, or by adjusting your browser settings.
Security
We apply industry-standard controls to protect personal data, including: encryption in transit (HTTPS with HSTS); secrets stored in Google Cloud Secret Manager (not in source code); row-level security on database tables that contain personal data; per-IP and per-session rate limiting on expensive endpoints; PII-redaction on AI-generated content before persistence; and audit logging of administrative access. No method of transmission or storage is 100% secure. We disclose security incidents to affected users and authorities as required by applicable law.
Children
Secureflo is a business product intended for use by employees of organizations. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information to us, contact us so we can delete it.
Responsible disclosure
If you believe you have found a security vulnerability in our service, please report it to karunakar@secureflo.net. See our security contact details at /.well-known/security.txt.
Changes to this policy
We may update this policy as the product evolves or as laws change. Material changes will be notified by email to registered users or by a prominent notice on the site. The "Last updated" date above reflects the current version.
Contact
Questions, requests, or concerns about this Privacy Policy or your personal data: karunakar@secureflo.net.