This privacy policy describes how CyberEscudo handles visitor information.
This site does not directly collect personal data. The web server may automatically log IP addresses, browsers, and visited pages for statistical purposes.
Necessary cookie: a first-party session cookie to remember the selected language and the state of forms (protection against forged submissions and the certificate exam). No consent required.
Analytics (optional): Google Analytics, with anonymized IP and no advertising signals, to measure visits in aggregate. It is only enabled if you accept in the cookie banner; if you reject, nothing is loaded and no third-party cookie is set. You can change your choice anytime via the "Cookies" link in the footer.
Most tools run entirely in your browser (encoders, generators, calculators, decoders) and send nothing to any server. Some, in order to work, do query public third-party services; in those calls your IP address and the value you look up (a domain, an IP…) are visible to those services, each with its own privacy policy:
These tools are intended for authorized testing, education and research. Only query assets you own or have permission to test.
If you use the API, we do not store your IP: to apply the rate limit we count each client (its IPv4, or the /64 prefix of its IPv6) with a summary (HMAC) made with a random key that is replaced every day; the previous one is deleted with the first request of the next day. Without that key, which never leaves the server, the IP cannot be recovered and two days cannot be linked. No cookies. The domains you query are kept for 6 hours, as in the auditor, so DNS is not queried again.
If you subscribe to the bulletin (from that page or from the blog), we store your email, the language, the dates of sign-up and confirmation, the last issue we sent you and two random codes to confirm and unsubscribe. We do not store your IP. Purpose: sending you the bulletin every Monday (plain text, no tracking pixels). Legal basis: your consent, which you confirm from the email we send you; without confirmation we write nothing else and the request is deleted 7 days after the last confirmation email. If that email reached you without asking, its "Wasn't you?" link cancels the request: we keep the address for 7 more days, only so nobody can ask again on your behalf, and then it is deleted. Retention: until you unsubscribe; unsubscribing, from the link in every issue (also one-click from your email client), deletes your data. The email is sent from our own server: it is not shared with third parties.
Anyone who signed up earlier for the blog's article notices (a list with the email, the language and the IP they signed up from) does not get the bulletin: they agreed to something else, so we do not write to them. To have that address deleted, email info@cyberescudo.com.
If you ask us to watch a domain at /vigila, we store your email, the domain, the language and the dates of sign-up and confirmation, plus two random codes to confirm and to unsubscribe. We do not store your IP. Purpose: auditing that domain once a week (public DNS only) and writing to you if its protection changes. Legal basis: your consent, which you confirm from the email we send you; without confirmation we write nothing else and the request is deleted 7 days after the last confirmation email. If that email reached you without asking, its "Wasn't you?" link cancels the request: we keep that address and domain for 7 more days, only so nobody can ask again on your behalf, and then they are deleted. Retention: until you unsubscribe; unsubscribing, from the link in any alert, deletes the subscription. Alerts are sent from our own server: there are no third parties and nothing is shared. You can also email info@cyberescudo.com to exercise your rights of access, rectification or erasure.
The DMARC report analyzer processes files in your browser: they are neither uploaded nor stored.
The path exam is graded on the server. While you take it, the session cookie keeps which questions you got and, if you pass, your score for one hour so you can issue the certificate. To limit attempts (5 exams per hour) we count each client as in the API: with a summary (HMAC) of its IP made with a key that changes every day. The IP is not stored.
If you issue a certificate, we store the name you type, the path, the score, the language and the date, plus the summary (SHA-256) of its deletion link. No email and no IP. Purpose: publishing the certificate at its link so anyone can check it (the page is not indexed by search engines). Legal basis: your consent, given when you issue it. Retention: until you delete it with the deletion link, which is shown only once when it is issued; since we do not have your email, we cannot send it to you again. To exercise your rights you can also email info@cyberescudo.com. The "Add to LinkedIn" button does not connect us to LinkedIn: your browser opens its form with the certificate details, and what you publish there is under its terms.
For any privacy-related questions: info@cyberescudo.com