Privacy Policy
Last updated: June 14, 2026
1. Who We Are
AuditWard, LLC, a Delaware limited liability company ("we", "us", "our"), is an AI-powered QA testing and security auditing platform located at 2261 Market Street STE 19811, San Francisco, CA 94114. You can reach us at contact@platform.auditward.com.
This Privacy Policy explains how we handle personal data for which AuditWard is the controller, such as your account registration details, billing records, and scan-authorization audit logs. Where we process personal data contained in the targets, results, and credentials you submit for scanning ("Customer Data"), we generally act as your processor, and our Data Processing Agreement governs that processing.
Questions about this policy or your personal data can be sent to contact@platform.auditward.com.
2. Scope and Roles
This policy applies to personal data we process as a controller: data about visitors to auditward.com, people who contact us or previously joined our waitlist, and the account holders who use our platform. Because AuditWard is a B2B service, much of the data processed during a scan is supplied or designated by our customer. For personal data appearing inside the websites and applications a customer instructs us to test, the customer is the controller (or acts on behalf of its own controller) and AuditWard acts as a processor under the Data Processing Agreement. Sections 6, 8, and 9 of this policy describe how that scan content is handled.
3. Information We Collect
Account Information
When you create an account, we collect your email address and a password, which is stored only as a cryptographic hash and never in plaintext. We record whether your email has been verified, your active organization, and the time at which you accepted our Terms of Service.
Legal-Acceptance Audit Trail
When you register, we record proof that you accepted our legal documents (Terms of Service, DPA, and Privacy Policy), including the document type, the version accepted, the time of acceptance, and the IP address from which you accepted.
Device Fingerprint (Anti-Abuse)
To prevent multi-account and free-plan abuse, we process your IP address and request metadata (such as standard browser request headers) to derive an abuse-prevention identifier. This is computed on our servers from your request, not by a tracking script running in your browser.
Scan Targets and Authorization Records
When you initiate a scan, we collect and process:
- The target URL (up to 2,048 characters) and any instructions, project context, discovered targets, questions, and input guidance you provide.
- A record of who authorized each scan and when, including whether the target domain was verified, the authorization time, and the authorizing user.
Credentials and Answers for Authenticated Scans
If you supply login credentials or answers so that we can scan an area of a site that requires authentication, we encrypt them before storage and store only the encrypted value, never the plaintext.
Scan Results, Findings, Screenshots, and Reports
We store the results of each scan, including finding titles, descriptions, severity and category, compliance tags, triage status, structured evidence, and report details, along with references to screenshots and other artifacts. Screenshots, generated PDF reports, and raw security-tool output are stored as artifacts in AWS S3. Because scans run against live targets you designate, these results may incidentally contain personal data that appears on the scanned pages (see Section 8).
API and MCP Credentials
When you create an access token for programmatic or MCP access, we store the token name you choose, a hashed form of the token (never the token itself), and timestamps for creation, last use, and revocation. For OAuth clients we also store client identifiers and hashed forms of authorization codes and access/refresh tokens.
Billing Information
For paid plans we store references to your Stripe customer and subscription, the applicable plan, status, and billing-period dates. We do not store your payment card details, only the Stripe identifiers; card data is handled by Stripe.
AI Usage and Cost Metering
We log metadata about AI inference usage per organization, project, session, and user, including the model identifier, number of calls, token counts, and computed cost. This usage log records metadata only; it does not store the prompt or response content.
Marketing Communications
If you opt in to product updates, we collect your email address to send product news, and we record your email-category opt-out preferences so we can honor unsubscribe requests; an unsubscribe link is included in our emails via the List-Unsubscribe header.
Waitlist (Legacy)
Before AuditWard launched, visitors could join a waitlist on the landing site. The waitlist is no longer offered, but if you joined it we still hold the email address and signup time you provided. You can ask us to delete this at any time by emailing contact@platform.auditward.com.
Contact Form
When you submit the contact form, we collect your name, email address, phone number (if provided), and your message. This information is forwarded to our team by email and is not stored in a database.
Support Enquiries and Live Chat
Support requests and live chat are handled in our own helpdesk, which we host ourselves rather than hand to an outside chat provider. We process the contact details and message content you send us so we can answer you and keep a thread of the conversation. The chat widget stores a small identifier in a cookie or local storage on your device so your conversation carries over between page loads and visits. Support data is kept according to the retention rules in Section 11.
Website Analytics
We use Umami (cloud.umami.is), a privacy-focused, cookieless analytics tool, to understand how visitors use our website (for example page views and referral sources). Umami loads on every page of our landing site. It does not set cookies, store identifiers on your device, or collect personal information, so it does not require consent. We do not use Google Analytics, Contentsquare, or any other cookie-based analytics.
Error Monitoring
We use Sentry to monitor errors in our backend. Sentry may capture request and exception context to help us diagnose problems; we have configured it not to send personally identifiable information by default.
4. How We Use Information and Legal Bases
The table below maps each purpose to the lawful basis we rely on under Article 6 of the GDPR.
| Purpose | Data used | Lawful basis (GDPR Art 6) |
|---|---|---|
| Provide the scanning, QA, and reporting service you request | Account data; scan targets, instructions, and credentials; scan results and artifacts | Performance of a contract (Art 6(1)(b)) |
| Maintain an audit trail of scan and legal-document authorizations | Authorization records; legal-acceptance audit trail incl. IP | Legal obligation / legitimate interest in evidencing lawful, authorized testing (Art 6(1)(c)/(f)) |
| Send scan-completion notifications and account/service emails | Email address; notification preferences | Performance of a contract (Art 6(1)(b)) |
| Send product/marketing updates | Email address; opt-out records | Consent (Art 6(1)(a)) |
| Bill paid plans and meter usage | Stripe references; LLM usage metadata | Performance of a contract; legal obligation for tax/accounting records (Art 6(1)(b)/(c)) |
| Prevent spam, abuse, and unauthorized multi-account use | IP address and request metadata | Legitimate interest in securing the platform and preventing abuse (Art 6(1)(f)) |
| Understand and improve website usage | Cookieless Umami analytics | Legitimate interest for cookieless audience measurement (Art 6(1)(f)) |
| Respond to inquiries | Contact-form name, email, phone, message | Legitimate interest in responding to you (Art 6(1)(f)) |
| Diagnose and fix errors | Sentry request/exception context | Legitimate interest in operating a reliable, secure service (Art 6(1)(f)) |
We do not sell, rent, or share your personal information with third parties for marketing purposes.
To create an account and use the service, you must provide an email address and password and accept our terms; without this we cannot establish the account or deliver scans. To pay for a paid plan, billing information must be processed by Stripe.
5. AI Processing of Scan Content
AuditWard uses large language models (LLMs) to analyze scan targets, triage findings, and help generate reports. The only LLM provider that processes your scan and page content is Amazon Bedrock (AWS), accessed through the AWS Bedrock runtime; the models invoked are Anthropic Claude models hosted within AWS Bedrock. There is no direct OpenAI or direct Anthropic API integration in our scanning pipeline.
The content sent to AWS Bedrock for analysis can include: screenshots of scanned pages (sent as images), accessibility trees and ARIA snapshots of scanned pages, your QA instructions, and raw security-tool output. Because scans run against live targets you designate, any of this content may contain personal data present on the scanned page.
We log only usage metadata (model, token counts, and cost) for this AI processing, not the prompt or response content.
As set out in our Data Processing Agreement, your scan data, findings, evidence, artifacts, and credentials are not used to train, fine-tune, or benchmark any AI or machine-learning model, and our AI inference sub-processor is contractually restricted from using your data to train or improve its models.
Our AI assists with analysis and report generation but does not make decisions that produce legal or similarly significant effects on any individual within the meaning of Article 22 of the GDPR.
6. Ownership and Confidentiality of Scan Results
You retain ownership of all scan data generated through your use of the service, including findings, reports, and artifacts. AuditWard does not claim ownership of your scan results. We treat scan targets, scan results, evidence, and reports as confidential and process them solely to deliver the service to you and to secure and operate the platform; we make them available only to you and to the sub-processors needed to provide the service (see Section 7).
7. Recipients and Sub-Processors
We share personal data only with service providers (sub-processors) that help us deliver, secure, and operate the service, each bound by a data processing agreement. Our current sub-processors include:
- Amazon Web Services (AWS): cloud compute, storage, encryption, and AI model inference via Amazon Bedrock for scan analysis.
- Postmark: transactional/notification email delivery (backend) and contact-form/waitlist notification emails (landing).
- Stripe, Inc.: payment processing and subscription billing.
- Umami (cloud.umami.is): cookieless website analytics, loaded on all landing pages.
- Sentry: backend error monitoring.
The authoritative, current list (with processing locations and transfer safeguards) is published on our Sub-Processors page. We do not otherwise disclose your personal data except as required by law or to protect our rights.
8. Personal Data Appearing in Scan Targets
When we scan a live website or application you designate, we may incidentally capture personal data belonging to third parties, for example in screenshots, page content, form fields, accessibility snapshots, or findings. For this category of data:
- Categories of personal data (GDPR Art 14(1)(d)). Any personal data that happens to appear on the target you instruct us to scan; the specific categories are determined by the target and are outside our control.
- Source (GDPR Art 14(2)(f)). The data originates from the customer-designated target (often a publicly accessible or customer-operated web application), not from the data subject directly.
- Role. For such data we act as your processor under the Data Processing Agreement; you warrant that you own or are authorized to test each target you submit and that you have a lawful basis for the processing.
9. Data Storage, Security, and Encryption
Your data is stored on AWS infrastructure in the United States. Specific measures include:
- Credential encryption. Credentials and answers you supply for authenticated scans are encrypted and stored only in encrypted form, never in plaintext.
- Hashed secrets. Account passwords and API/MCP tokens are stored only as cryptographic hashes; raw tokens are never stored.
- Artifact access control. Scan artifacts are served only via short-lived, access-controlled links.
- Encryption in transit. We use TLS to encrypt data in transit.
Contact-form submissions are forwarded by email and are not stored in a database beyond delivery.
10. International Data Transfers
We are established in the United States and our sub-processors (AWS, Postmark, Stripe) process data in the United States. Where the GDPR or UK GDPR applies, transfers to the United States are made under the European Commission's Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum), as incorporated in each sub-processor's data processing addendum. You may request a copy of the relevant safeguards by emailing contact@platform.auditward.com.
11. Data Retention
- Account data is retained for as long as your account is active.
- Intermediate scan artifacts (raw security-tool output and the working per-step screenshots captured during a scan) are automatically deleted a limited period after the scan runs. Reports and the finding evidence we attach to results are retained while your account is active and for a reasonable period after account deletion for legal-compliance purposes.
- Upon account deletion or documented request, Customer Data is deleted or returned within 30 days, unless retention is required by law.
- Scan-authorization audit logs are retained for legal-compliance purposes.
- LLM usage metadata (token counts, cost) is retained for billing and usage analysis.
- Marketing email addresses are retained until you unsubscribe or request deletion.
- Contact-form data exists in email form only, for as long as necessary to address your inquiry.
- Support and live-chat conversations are kept for as long as necessary to handle your request and keep a reasonable history of the exchange, after which they are resolved and aged out.
- Waitlist entries (email and signup time) persist until manually removed.
12. Your Rights: GDPR / UK GDPR
If you are in the EEA or UK, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. Where we rely on consent (for example marketing email), you may withdraw consent at any time, without affecting processing carried out before withdrawal. You may exercise these rights by emailing contact@platform.auditward.com; we will respond within 30 days. You can also delete scan sessions, findings, and artifacts directly from the dashboard. Deletion of scan-authorization audit records may be restricted where retention is required for legal compliance.
You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO); in the EU, it is the data protection authority of your country of residence or workplace.
Where we process personal data inside your scan data on your behalf, our Data Processing Agreement governs how we assist you with data-subject requests.
13. California Privacy Rights (CCPA / CPRA)
This section applies to California residents, including business contacts.
Categories of personal information collected in the past 12 months: identifiers (email, account identifiers, IP address); internet/network activity (analytics signals, device-fingerprint inputs); commercial information (subscription and billing references); customer content you submit (scan targets, instructions, credentials, scan results and artifacts); and professional/contact information (contact-form name, phone).
Sources. Directly from you (account, scans, contact form, and the legacy waitlist); automatically from your device/browser (analytics, fingerprint inputs); and from the scan targets you designate (incidental data, see Section 8).
Business/commercial purposes. As described in Section 4.
Categories of third parties to whom we disclose PI. The sub-processors listed in Section 7 and on the Sub-Processors page.
Sale / sharing. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Our analytics tool (Umami) is cookieless and used for site measurement, not advertising.
Sensitive personal information. Account credentials and the login secrets you supply for authenticated scans, and any sensitive data that incidentally appears in a scan target, may constitute sensitive personal information. We use it only to provide the service and do not use it to infer characteristics.
Your rights. California residents may request to know/access, delete, and correct their personal information, opt out of sale/sharing, and limit use of sensitive PI, and will not be discriminated against for exercising these rights. To submit a request, email contact@platform.auditward.com.
14. Cookies and Tracking Technologies
Our website analytics tool, Umami, is cookieless: it does not set cookies or store identifiers on your device, so it does not require consent.
Because we use no cookies or other tracking technologies that require consent, we do not display a cookie consent banner.
Our forms are protected against spam and abuse by a web application firewall (WAF) at the network layer, which does not set cookies or store identifiers on your device.
Any cookies your browser may already hold can be cleared at any time through your browser settings.
15. Children's Privacy
Our service is intended for businesses and is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us at contact@platform.auditward.com and we will delete it.
16. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users at least 30 days before they take effect, and posted on this page with an updated revision date.
17. Contact
If you have questions about this privacy policy, email us at contact@platform.auditward.com. For data processed on your behalf during scans, see our Data Processing Agreement.