Last updated 2026-09-15
Privacy
What this covers
This describes what the ClearPenTest website and customer portal collect, why, and who it reaches. It does not cover data encountered during a penetration test, which is governed by the engagement agreement and the rules of engagement for that assessment.
What the marketing site collects
If you submit the contact form: your email address, and optionally your name, company, website and whatever you write in the message. We use it to reply to you. It is not added to a marketing list and is not shared with anyone.
Page analytics: first-party event records containing the page path, an event name, a timestamp, and a session identifier generated in your browser's sessionStorage. That identifier is discarded when you close the tab. There is no cookie behind it, nothing that persists between visits, and nothing that identifies you.
We do not use third party analytics, advertising pixels or cross-site trackers.
What the portal collects
To create an account: your email address and name, handled by Clerk as our identity provider.
To run an engagement: your company details, the repositories and systems you place in scope, the testing authorization you sign, and the assessments and reports associated with your organization.
The signed testing authorization records the signer's name and title, the time of signing, and the IP address and browser user agent at that moment. That is an audit trail for a legal authorization, which is why it is kept rather than minimized.
Who processes it
Vercel, hosting and content delivery for the website.
Convex, the database storing site content, enquiries and portal records.
Clerk, identity and authentication for the portal.
These are the only subprocessors. If that changes, this page changes before the change ships.
Penetration test reports
A report describes how to compromise your systems, so it is treated as the most sensitive thing we hold. Report files are not served from a public URL. They are retrieved through a request that checks, on the server, that the requesting account belongs to the organization the report was delivered to.
How long it is kept
Contact enquiries: until they are no longer needed to respond, and no longer than two years.
Analytics events: 13 months.
Portal records, including assessments, reports and signed authorizations: for the life of the customer relationship and as long afterwards as is needed for our legal and professional obligations.
You can ask us to delete your account data at any time by emailing us. Signed testing authorizations are retained where we are required to keep a record of the authority under which testing was performed.
Your rights
You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, or ask for a copy. Email us and we will respond within 30 days.
Questions about this page: hello@clearpentest.com