How we collect, use, and protect your information.
10x Pentest AI, Inc. ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at www.10xpentest.com and use our AI-powered autonomous penetration testing platform accessible at portal.10xpentest.com (collectively, the "Services").
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our Services immediately.
This Privacy Policy applies to all users of the Services, including visitors to the website, registered users, and enterprise customers. Our Services are designed for security professionals, organizations, and businesses seeking AI-driven cybersecurity assessments.
We collect information that you voluntarily provide when you create an account or register on the platform, complete forms, surveys, or sign up for our newsletter, contact us for customer support or inquiries, purchase or subscribe to our Services, or respond to communications from us. This information may include:
When you access our Services, we automatically collect certain technical information, including IP address, browser type, and operating system; device identifiers and hardware information; pages visited, time spent on pages, and navigation paths; referring URLs and search queries; log files, error reports, and crash data; date and time of access; and cookies, pixel tags, and similar tracking technologies (see Section 7).
Given the nature of our AI autonomous penetration testing platform, we may collect target scope configurations and scan parameters you define, pentest job submissions, results, and report data, AI model interaction logs and prompt history, security findings, vulnerability data, and remediation notes, API keys and integration configurations (stored in encrypted form), and dashboard activity and feature usage patterns.
Important: Any target systems, IP ranges, domains, or credentials you submit to the platform for testing purposes are processed solely to deliver our Services and are never used for any other purpose.
We may receive information about you from third-party sources, such as identity verification providers, marketing and analytics partners, Single Sign-On (SSO) providers (e.g., Google, Microsoft, Okta), and payment processors and billing services.
To create and manage your account; to execute AI-driven penetration tests and deliver results; to generate security reports and provide remediation guidance; to process transactions and manage subscriptions; to improve, personalize, and optimize our platform; to develop new features and capabilities; and to train and improve our AI models (using anonymized, aggregated data only).
To send transactional emails (account confirmations, scan completions, alerts); to respond to support requests and inquiries; to send service updates, security advisories, and policy changes; and to send marketing communications (with your consent, where required).
To detect, prevent, and investigate fraud, abuse, or security incidents; to verify user identity and authorization; to enforce our Terms of Service and acceptable use policies; to comply with applicable laws and regulations; and to respond to legal requests, court orders, and governmental inquiries.
To analyze platform usage trends and user behavior (in aggregated, de-identified form); to measure the effectiveness of our Services and marketing campaigns; and to conduct internal research and development.
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, we process your personal data under the following legal bases:
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following limited circumstances:
We engage trusted third-party vendors and service providers who assist us in operating our Services. These parties are contractually obligated to protect your information and may only use it to provide services on our behalf. This includes cloud infrastructure and hosting providers, payment processors and billing platforms, email delivery and communication services, analytics and monitoring tools, customer support platforms, and identity and authentication services.
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred to the acquiring entity. We will notify you via email or prominent notice on our website prior to any such transfer and any changes to this Privacy Policy.
We may disclose your information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, or legal process; enforce our Terms of Service or protect our legal rights; protect the rights, property, or safety of our users, employees, or the public; or investigate or prevent fraud, security incidents, or illegal activity.
We may share your information with third parties when you have expressly consented to such sharing, including for integration with third-party tools or for co-marketing activities.
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for research, analytics, industry benchmarking, or marketing purposes.
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Retention periods are determined based on the following criteria:
When information is no longer needed, we securely delete or anonymize it in accordance with our data destruction standards.
We use cookies and similar tracking technologies on our website and platform. These help us operate our Services, understand usage patterns, and improve your experience.
You can control and manage cookies through your browser settings. Disabling certain cookies may affect the functionality of our Services. We also honor browser-based "Do Not Track" (DNT) signals where applicable.
The security of your data is of paramount importance to us, especially given the sensitive nature of cybersecurity information processed by our platform. We implement a comprehensive set of technical and organizational security measures, including:
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you use our Services at your own risk. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
To exercise any of these rights, please contact us at privacy@10xpentest.com. We will respond to verified requests within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
We do not sell personal information as defined under the CCPA/CPRA. To submit a verifiable consumer request, contact us at privacy@10xpentest.com.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with applicable privacy laws may have similar rights. Please contact us to exercise your state-specific rights.
Our Services are intended for business and professional use by individuals 18 years of age or older. We do not knowingly collect, use, or disclose personal information from children under the age of 13 (or the applicable age of digital consent in your jurisdiction). If we learn that we have inadvertently collected personal information from a child under the applicable age threshold, we will take prompt steps to delete that information. If you believe we may have collected information from a minor, please contact us immediately at privacy@10xpentest.com.
10x Pentest AI, Inc. is based in the United States. If you access our Services from outside the United States, your personal information may be transferred to, stored, and processed in the United States or other countries where we or our service providers operate. Where applicable, we ensure that international data transfers are subject to appropriate safeguards, such as:
By using our Services, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules than those in your country.
Our Services may contain links to third-party websites, tools, or services that are not operated by us. We have no control over, and assume no responsibility for, the privacy practices or content of such third parties. Our platform may also integrate with third-party security tools, SIEM platforms, ticketing systems, or APIs. When you connect third-party services, their respective privacy policies govern the data shared with them. We encourage you to review the privacy policies of any third-party services you connect.
Our platform uses AI and machine learning technologies to perform autonomous penetration testing, analyze security vulnerabilities, and generate reports. This involves:
We do not make automated decisions about individuals that produce significant legal effects without human oversight. Pentest results and security findings are presented as professional tools to assist your security team and are not determinative of legal or individual rights. Where required by law, you have the right to obtain human review of any automated decisions, to express your point of view, and to contest the decision.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of our Services after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the changes, you must discontinue use of our Services and request account deletion.
10x Pentest AI, Inc.
2261 Market Street STE 61091, San Francisco, CA 94114, United States
Website: www.10xpentest.com
Platform: portal.10xpentest.com
Privacy Inquiries: privacy@10xpentest.com
Data Protection Officer: dpo@10xpentest.com
For EEA/UK residents, if you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.
© 2025 10x Pentest AI, Inc. All rights reserved. This document does not constitute legal advice. Consult qualified legal counsel for advice specific to your jurisdiction.