Privacy
What we collect, and what we don't.
Last updated 19 September 2026.
This website
This site sets no cookies, runs no JavaScript, loads
no fonts, scripts or images from third parties, and carries
no analytics of any kind. Its content security policy is
default-src 'none' — the page is not permitted to contact any other host,
and it does not.
No account is created, no identifier is stored in your browser, and nothing you do on this page is recorded by us. Our hosting provider processes ordinary server request logs (IP address, timestamp, requested path, user agent) for delivery, security and abuse prevention. We do not use those logs to build profiles.
When you contact us
If you email us, we hold that correspondence and anything you attach for as long as needed to respond and, where an engagement follows, for the duration of that engagement and any period we are contractually or legally required to retain it.
Mail is handled by Google Workspace. We ask that anything sensitive is encrypted to our PGP key.
Client engagement data
- Scope, credentials, findings and evidence are held only as long as the engagement requires, and destroyed on request afterwards.
- Findings and evidence are encrypted at rest and are never shared with third parties.
- Client source code and scope material are never sent to third-party model or analysis services.
- We do not publish client names, and we do not reference an engagement publicly without written permission.
- An NDA is signed on request before scoping.
Legal basis and your rights
Where the GDPR or a comparable regime applies, we process correspondence on the basis of legitimate interest in responding to an enquiry, and engagement data on the basis of contract. You may ask what we hold about you, ask for it to be corrected, or ask for it to be deleted where no legal or contractual obligation requires us to keep it.
Contact
Privacy requests and questions: research@deebug.io.
Vulnerability reports about our own systems go to security@deebug.io — see security.txt.