DPDP Act 2023 CompliantGDPR ReadyPolicy v1.0

Privacy Policy & Data Protection

This policy outlines how Pentoolkit ("we", "our") collects, safeguards, and processes telemetry data when you perform security evaluations, alongside your statutory rights under the Digital Personal Data Protection Act, 2023.

Last Updated: 2 June 2026Data Fiduciary: Pentoolkit | Rivedix Technology SolutionsJurisdiction: India / Global

1. Who We Are

Pentoolkit | Rivedix Technology Solutions ("we", "us", "our") operates Pentoolkit, an autonomous offensive security engineering platform accessible at https://pentoolkit.com. We act as the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 (India) and Data Controller under the EU GDPR.

This Privacy Policy establishes how we collect, process, isolate, and secure data submitted by security researchers, enterprise teams, and individual engineers.

2. Data We Collect

We adhere to strict data minimization principles, collecting only what is strictly necessary to conduct authorized vulnerability testing:

Identity & Account Data

Name, primary email address, linked OAuth IDs (Google / Microsoft), and active workspace tenant IDs.

Target & Scope Telemetry

Domain names, IP addresses, subdomains, CIDR ranges, and port configuration verified for testing.

Security Findings & Reports

Vulnerability details, CVE mappings, reproduction evidence, risk scores, and generated audit artifacts.

Audit & Access Logs

IP address, user-agent, session fingerprints, API key identifiers, and consent timestamp history.

Excluded Categories: We do not store raw passwords, payment card numbers (processed exclusively by Stripe / payment gateway), government IDs, biometric data, or health records.

3. How We Use Your Data

Data provided to Pentoolkit is strictly isolated and used exclusively for:

  • Executing automated vulnerability scans and continuous attack surface monitoring.
  • Authenticating user sessions and enforcing multi-tenant organization boundaries.
  • Synthesizing executive summary reports (PDF, HTML, DOCX, JSON).
  • Dispatching real-time notifications for critical severity vulnerability alerts.
  • Statutory compliance and audit logging required under cybersecurity regulations.

We will never sell, lease, or monetize your scan findings or target architectures to any third party.

4. Third-Party Subprocessors

We engage vetted subprocessors who comply with SOC 2 Type II, ISO 27001, and GDPR standards:

SubprocessorPurposeData LocationCertifications
Amazon Web Services (AWS)Core cloud compute, database, encrypted S3 object storageus-east-1 / GlobalSOC 1/2/3, ISO 27001
Anthropic (AWS Bedrock)AI Finding Remediation (Anonymized finding descriptors only; Zero PII)AWS VPC IsolatedZero Data Retention
Upstash / RedisEphemeral message queues for background worker orchestrationIn-memory / EphemeralTLS 1.3 In-transit

5. Data Retention Schedule

  • Active Account Data: Retained while your workspace remains active, and for 90 days following explicit deletion requests to allow rollback.
  • Scan Findings & Telemetry: Retained across active subscriptions. Permanently shredded within 30 days of workspace termination.
  • Statutory Consent & Audit Logs: Maintained for 3 years to comply with statutory DPDP §13 audit compliance.

6. Your Statutory Rights (DPDP Act 2023 & GDPR)

As a Data Principal, you possess statutory rights enforceable directly via our self-service portal:

Right to Access (§11 DPDP)

Download a complete structured JSON export of all personal information and scan records.

Right to Correction (§12 DPDP)

Request real-time rectification of inaccurate profile data, corporate email, or billing contacts.

Right to Erasure / Forgotten

Request permanent account and telemetry purging, finalized within statutory 30-day timelines.

Right to Withdraw Consent (§6)

Revoke data processing consent at any time without punitive measures.

7. Security Safeguards & Encryption

Pentoolkit employs enterprise-grade cryptographic controls:

  • In-Transit: Mandatory TLS 1.3 / HTTPS encryption with strict HSTS policies.
  • At-Rest: AES-256 encryption across all databases, backups, and S3 scan report artifacts.
  • Zero-Password Authentication: Cryptographic passwordless Email OTP and verified OAuth 2.0 PKCE.
  • Isolation: Multi-tenant database row-level separation with isolated organization UUID scopes.

11. Grievance Redressal Officer

In compliance with Section 13 of the Digital Personal Data Protection Act, 2023, you may address any concerns or formal complaints directly to our designated Grievance Officer:

Officer Name: Santosh Kamane

Designation: Data Protection & Grievance Officer

Email: info@rivedix.com

SLA Response Window: Within 7 business days

Appellate Authority: Data Protection Board of India

12. Contact Information

For general inquiries or privacy policy clarification, contact us at:

Rivedix Technology Solutions Private Limited
Email: info@rivedix.com