Home / Legal
Legal
Privacy policy
What we hold, why we hold it, how long we keep it, and what you can ask us to do with it. In plain words, because you should not need a lawyer to read this.
Last updated: 20 September 2026
Who we are
Cyberlop is built and operated by Cyberlop Labs, New Delhi, India. For the details you give us directly (a message through the form on this site, your account, your billing record), we decide what happens to that data and we are answerable for it. For everything inside your tenant (your targets, your findings, your own users), we act only on your instructions. You decide; we execute.
Write to hello@cyberlop.com about anything on this page. A person answers.
The contact form on this site
The form on our contact page collects your name and work email, and optionally your company, phone number, roughly how many applications you would license, what brought you here and whatever you write in the message box. It also records when the page was loaded, which is how we throw away automated submissions.
We use it for one thing: to answer you, and to work out whether a pilot makes sense. It is not added to a marketing list, not sold, and not shared with anyone for advertising. If the conversation goes nowhere we keep the message for a limited period in case you come back, and delete it on request. Ask at hello@cyberlop.com and it goes.
The law we work under
We operate under India's Digital Personal Data Protection Act, 2023. In the language of that Act you are the Data Principal and Cyberlop Labs is the Data Fiduciary for the data described above. We collect it for the purpose we have told you, keep it no longer than that purpose needs, and handle requests about it through the address on this page. Where customers outside India have rights under their own law, we apply the same process rather than argue about which statute reaches further.
Your source code
Cyberlop reads code while it attacks the running application, so this is the part of the policy that matters most.
Self-hosted
An agent runs inside your own network. Your repository is read where it already lives, the application is attacked from inside your perimeter, and the source never reaches us. What leaves your network is the finding, and you can see exactly what that contains before it goes.
Hosted
The repository is cloned read-only into a workspace created for that single scan. It is never written back to, never shared with another scan or another customer, and the whole workspace is wiped when the scan reaches a terminal state: finished, failed or cancelled, the same either way. We do not keep a copy afterwards.
In both options: we do not use your source code, your findings or your scan data to train models, ours or anyone else's.
Where your data lives
Each customer's data sits in its own database schema. Your rows are not mixed into a shared table with another customer's and separated by a filter at query time; the separation is in the structure itself. The credentials you give the platform so it can log in as your users are encrypted at rest in a vault, and every action taken in your tenant is written to an audit log you can read.
Your AI provider key
You bring your own key for the AI provider you already use. We store it encrypted, use it only to run your scans, and never for anyone else's work. That inference happens under your contract with your provider, not ours. Revoke the key at your provider and it stops working here immediately.
What we hold in your tenant
- Account data: the name, work email and organisation of each user you create, password hashes, MFA secrets, SSO subject identifiers, API token hashes and audit records
- Scan data: target configuration, findings including the request, the response and the screenshot captured while testing, and scan metrics such as duration and cost
- Billing data: the contact and payment details needed to invoice you
Website logs and analytics
Our web server keeps standard request logs, including IP addresses, for a limited period, to keep the site up and to deal with abuse. This site runs no analytics and no advertising trackers at all. There is no third-party script on any page, so nothing follows you between sites, and there is no profile of you to sell or share. If that ever changes we will name the tool here before we switch it on.
How long we keep things
Findings and scan records stay in your tenant while your contract runs, and you can export them at any time. When a contract ends, your data stays available for export for thirty days and is then deleted. Account and billing records are kept for the life of the contract and for as long afterwards as Indian tax and company law requires. Cloned source code, as above, does not survive the scan.
Other companies involved
We use infrastructure providers to run the hosted platform and, where you have not brought your own key, an AI provider to run analysis. We will name the current list on request, and publish it here as it settles. We do not add a sub-processor that gets access to customer data without telling customers first.
Your rights
You can ask what we hold about you, ask us to correct it, ask us to delete it, and complain if we handle it badly. Send any of those to hello@cyberlop.com; that is also our grievance address. We acknowledge within two working days and answer inside the period the law allows. If the data sits inside a customer's tenant rather than ours, because you are a user of an organisation that uses Cyberlop, we will point you to that customer and help them act on it.
Changes
If we change something that matters, we update this page and tell existing customers directly rather than hoping they re-read it.
Questions about this page
Anything about how we handle your data, including a request under the rights above, goes to hello@cyberlop.com and a person answers it. The contact page reaches the same people.