We just launched SimpleSecVisit simplesec.ai

Summit Cyber Group
← Back to home

Privacy Policy

Last updated: August 27, 2026 · Effective date: January 1, 2026

1. Introduction

Summit Cyber Group LLC (“Summit Cyber,” “we,” us,” or “our”) operates the website summitcyber.io and the SimpleSec platform, an AI-driven penetration-testing and security-assessment service (collectively, the “Services”).

This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have.

This Policy applies to visitors to our website, users of the SimpleSec dashboard and API, and individuals whose information we process in the course of providing the Services. It does not cover the practices of third parties we do not control.

Legal entity: Summit Cyber Group LLC
Privacy inquiries: privacy@summitcyber.io


2. Our Roles: Controller vs. Processor

Because SimpleSec is a business-to-business security-testing tool, our role depends on the type of data being processed.

Our processing of customer security-testing data is governed by the applicable customer agreement and any Data Processing Addendum (“DPA”) between us. If you require a DPA, contact privacy@summitcyber.io.

White-Label and Reseller Customers

SimpleSec may be operated under a partner’s own brand and vanity domain, and partners may create workspaces for their own end customers.

In those arrangements, the partner is generally the controller for its end-customer data and Summit Cyber acts as a processor or sub-processor, as applicable. The partner is responsible for providing its end customers with an appropriate privacy notice and establishing an appropriate lawful basis for processing.


3. Information We Collect

3.1 Information You Provide

We may collect:

3.2 Security-Testing Data

When you use SimpleSec, you provide or generate data about systems that you have authorized for testing. This may include:

Security-testing data can, by its nature, include credentials, personal data, confidential information, or information belonging to third parties.

You are responsible for ensuring that you are authorized to test the targets you submit and are authorized to process data that may be accessed or revealed during testing.

3.3 Information Collected Automatically

We may automatically collect:


4. How We Use Information

We use information to:

Legal Bases for Processing

Where the GDPR, UK GDPR, or similar laws apply, our legal bases for processing may include:


5. Automated and AI-Assisted Processing

SimpleSec uses large-language-model (“LLM”) technology to assist in planning and orchestrating security-testing activities. The LLM planner may determine which authorized security-testing steps to perform based on the current state and context of an assessment.

Relevant assessment context may be transmitted to our third-party LLM provider, currently OpenAI, for processing. We seek to limit information transmitted to information reasonably necessary for test planning and execution. Operator-supplied credentials and secrets are handled separately from LLM planning wherever practicable.

OpenAI processes this information as a service provider or sub-processor under its applicable business and API terms.

The Services do not make legal, employment, credit, healthcare, or similarly significant automated decisions about individuals.


6. How We Share Information

We do not sell your personal information.

We share information only as reasonably necessary to operate the Services, fulfill customer requests, comply with law, or as otherwise described in this Policy.

Service Providers and Sub-Processors

We use service providers and sub-processors that assist in operating and delivering the Services. These providers are subject to applicable contractual confidentiality and data-protection obligations.

Current providers include:

Sub-processorPurposeProcessing Location
Amazon Web Services (AWS)Cloud hosting, database, and storageUnited States, including AWS us-east-2
CloudflareDNS, CDN, edge TLS, security, and bot/abuse protectionGlobal
OpenAILLM-assisted security-test planning and orchestrationUnited States
StripePayment processing and subscription billingUnited States
SentryError and performance monitoringUnited States
GoogleTransactional email, including invitations, password resets, and notificationsUnited States / Global

We may update our service providers and sub-processors as our Services evolve.

Other Disclosures

We may also disclose information to:

We do not disclose customer security-testing data except to service providers or sub-processors necessary to provide the Services, as directed or authorized by the customer, or where required by law.


7. Data Retention

We retain information only for as long as reasonably necessary to provide the Services, fulfill contractual obligations, maintain security, comply with applicable legal requirements, resolve disputes, and enforce our agreements.

Unless a customer agreement specifies otherwise:

We may retain information for longer periods where required by law, necessary to establish, exercise, or defend legal claims, or necessary to investigate suspected fraud, abuse, or security incidents.

Eligible information may also be deleted upon customer request as described in Section 11.


8. Your Responsibilities for Security Testing

SimpleSec performs active security testing that can interact with systems and potentially access or reveal information contained within those systems.

By configuring a target for testing, you represent and warrant that you have authorization to test that target and have the necessary rights and lawful basis to process information that testing may access or reveal.

You are responsible for:

Summit Cyber implements safeguards designed to reduce unauthorized or unintended testing, including protected-infrastructure controls, access controls, and scan isolation. These safeguards do not replace the customer’s responsibility to obtain authorization and establish a lawful basis for testing.


9. Cookies and Similar Technologies

We use strictly necessary cookies and similar technologies to authenticate users, maintain sessions, secure the Services, prevent abuse, and support core application functionality.

These technologies may include security and bot-protection mechanisms provided by our infrastructure and edge-service providers.

We may also use limited diagnostic and performance technologies to understand application reliability and improve the Services. Where applicable law requires consent for nonessential cookies or similar technologies, we will obtain consent before using them.

Session tokens for the SimpleSec dashboard may be stored in your browser’s local storage to maintain your authenticated session.


10. Data Security

We implement technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, destruction, or misuse.

These measures include, as applicable:

No method of transmission, processing, or storage can be guaranteed to be completely secure. Accordingly, while we maintain safeguards designed to protect information, we cannot guarantee absolute security.


11. Your Privacy Rights

Depending on where you live and applicable law, you may have rights concerning your personal information, including rights to:

To exercise an applicable privacy right, contact privacy@summitcyber.io.

We will respond in accordance with applicable law and may take reasonable steps to verify your identity before fulfilling a request.

EEA and United Kingdom

Individuals in the European Economic Area or United Kingdom may have additional rights under the GDPR or UK GDPR, including the right to lodge a complaint with an applicable supervisory authority.

California

California residents may have rights under the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”), including applicable rights to know, access, delete, and correct personal information and to opt out of certain sales or sharing of personal information.

Summit Cyber does not sell personal information.

We will not unlawfully discriminate against an individual for exercising applicable privacy rights.

Customer-Controlled Data

Where Summit Cyber processes personal information as a processor or service provider on behalf of a customer, the customer is generally responsible for responding to data-subject requests.

Where appropriate, we will refer requests concerning customer-controlled information to the applicable customer and provide reasonable assistance as required by our contractual and legal obligations.


12. International Data Transfers

Summit Cyber is based in the United States and uses service providers and sub-processors located in the United States and other jurisdictions.

Where required by applicable data-protection law, international transfers of personal data are protected through recognized transfer mechanisms. These may include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other legally recognized safeguards.


13. Children’s Privacy

The Services are intended for businesses and professional users and are not directed to children under 16 years of age.

We do not knowingly collect personal information directly from children through the Services. If we become aware that personal information has been collected directly from a child in circumstances where such collection is prohibited, we will take appropriate steps to delete the information.


14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes to our Services, business practices, legal requirements, or other circumstances.

When we update this Policy, we will post the revised version and update the “Last updated” date above.

Where required by applicable law or contractual obligations, we will provide additional notice regarding material changes affecting how personal information is processed.


15. Contact Us

Questions, requests, or concerns regarding this Privacy Policy or our privacy practices may be directed to:

Summit Cyber Group LLC
25587 Conifer Rd, STE 105 PMB 503
Conifer, CO 80433
United States

Email: privacy@summitcyber.io

Data Protection Officer:
Rick Bohm, CISSP
Summit Cyber Group LLC
privacy@summitcyber.io