Privacy Policy
Last updated: August 27, 2026 · Effective date: January 1, 2026
1. Introduction
Summit Cyber Group LLC (“Summit Cyber,” “we,” “us,” or “our”) operates the website summitcyber.io and the SimpleSec platform, an AI-driven penetration-testing and security-assessment service (collectively, the “Services”).
This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have.
This Policy applies to visitors to our website, users of the SimpleSec dashboard and API, and individuals whose information we process in the course of providing the Services. It does not cover the practices of third parties we do not control.
Legal entity: Summit Cyber Group LLC
Privacy inquiries: privacy@summitcyber.io
2. Our Roles: Controller vs. Processor
Because SimpleSec is a business-to-business security-testing tool, our role depends on the type of data being processed.
- We are the controller for information we collect to operate our business, including account registration, authentication, billing, support, website analytics, and product telemetry.
- We are a processor or service provider for security-testing data that you submit or generate through SimpleSec, including scan targets, scan configurations, findings, evidence, and credentials supplied for authenticated testing. For that data, you, our customer, are the controller and determine what is tested and why.
Our processing of customer security-testing data is governed by the applicable customer agreement and any Data Processing Addendum (“DPA”) between us. If you require a DPA, contact privacy@summitcyber.io.
White-Label and Reseller Customers
SimpleSec may be operated under a partner’s own brand and vanity domain, and partners may create workspaces for their own end customers.
In those arrangements, the partner is generally the controller for its end-customer data and Summit Cyber acts as a processor or sub-processor, as applicable. The partner is responsible for providing its end customers with an appropriate privacy notice and establishing an appropriate lawful basis for processing.
3. Information We Collect
3.1 Information You Provide
We may collect:
- Account and profile information: name, email address, organization or workspace name, and role.
- Authentication information: passwords, which are stored only as salted hashes and never in plaintext, and, if enabled, multi-factor authentication secrets and backup codes, which are stored encrypted.
- Billing information: plan selection and subscription status. Card and payment details are collected and processed directly by our payment provider, Stripe. We do not store full payment card numbers.
- Support and communications: messages you send to us and related correspondence.
3.2 Security-Testing Data
When you use SimpleSec, you provide or generate data about systems that you have authorized for testing. This may include:
- Targets and scope: hostnames, IP addresses, URLs, network ranges, API specifications, and other information defining authorized testing targets.
- Engagement configuration: engagement type, testing preferences, and asset inventories.
- Operator-supplied credentials: usernames, passwords, tokens, API keys, or other credentials provided for authenticated testing. Sensitive credential values are encrypted at rest and are not returned through the API or intentionally written to logs or reports.
- Findings and evidence: vulnerabilities discovered, tool output, request and response information, and data captured from tested systems during an authorized assessment.
- Agent and connectivity data: for internal testing, information required to configure connectivity agents and WireGuard tunnels, including encrypted keys.
Security-testing data can, by its nature, include credentials, personal data, confidential information, or information belonging to third parties.
You are responsible for ensuring that you are authorized to test the targets you submit and are authorized to process data that may be accessed or revealed during testing.
3.3 Information Collected Automatically
We may automatically collect:
- Usage and audit logs: actions performed through the dashboard or API, timestamps, and associated audit records.
- Device and connection information: IP address, browser type, and similar technical information. IP addresses, including originating IP addresses forwarded by our edge or CDN providers, may be used for security, abuse prevention, authentication, and rate limiting.
- Error and performance telemetry: diagnostic information processed through our error-monitoring provider, Sentry, to maintain and improve reliability.
- Cookies and similar technologies: as described in Section 9.
4. How We Use Information
We use information to:
- Provide, operate, maintain, secure, and improve the Services;
- Authenticate users and protect accounts, including through multi-factor authentication, security monitoring, and abuse or rate-limiting controls;
- Plan and execute authorized security tests requested by customers;
- Generate findings, reports, and compliance-related artifacts;
- Process payments and manage subscriptions;
- Communicate about accounts, security matters, service changes, and administrative matters;
- Provide customer support and respond to requests;
- Monitor, debug, and improve reliability and performance;
- Detect, prevent, and investigate security incidents, fraud, and abuse;
- Comply with applicable legal obligations; and
- Enforce our agreements and protect our legal rights.
Legal Bases for Processing
Where the GDPR, UK GDPR, or similar laws apply, our legal bases for processing may include:
- Performance of a contract or taking steps at your request before entering into a contract;
- Our legitimate interests in providing, securing, administering, and improving the Services;
- Compliance with legal obligations; and
- Consent, where consent is required by applicable law.
5. Automated and AI-Assisted Processing
SimpleSec uses large-language-model (“LLM”) technology to assist in planning and orchestrating security-testing activities. The LLM planner may determine which authorized security-testing steps to perform based on the current state and context of an assessment.
Relevant assessment context may be transmitted to our third-party LLM provider, currently OpenAI, for processing. We seek to limit information transmitted to information reasonably necessary for test planning and execution. Operator-supplied credentials and secrets are handled separately from LLM planning wherever practicable.
OpenAI processes this information as a service provider or sub-processor under its applicable business and API terms.
The Services do not make legal, employment, credit, healthcare, or similarly significant automated decisions about individuals.
6. How We Share Information
We do not sell your personal information.
We share information only as reasonably necessary to operate the Services, fulfill customer requests, comply with law, or as otherwise described in this Policy.
Service Providers and Sub-Processors
We use service providers and sub-processors that assist in operating and delivering the Services. These providers are subject to applicable contractual confidentiality and data-protection obligations.
Current providers include:
| Sub-processor | Purpose | Processing Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, and storage | United States, including AWS us-east-2 |
| Cloudflare | DNS, CDN, edge TLS, security, and bot/abuse protection | Global |
| OpenAI | LLM-assisted security-test planning and orchestration | United States |
| Stripe | Payment processing and subscription billing | United States |
| Sentry | Error and performance monitoring | United States |
| Transactional email, including invitations, password resets, and notifications | United States / Global |
We may update our service providers and sub-processors as our Services evolve.
Other Disclosures
We may also disclose information to:
- Professional advisers, such as auditors, accountants, insurers, and attorneys, where subject to appropriate confidentiality obligations.
- Parties involved in business transactions, such as a merger, acquisition, financing, reorganization, or sale of all or a portion of our assets, subject to appropriate protections.
- Government authorities or other parties where legally required, including to comply with applicable law, regulation, court order, subpoena, or other lawful request.
- Parties necessary to protect rights and safety, where reasonably necessary to protect Summit Cyber, our customers, users, systems, property, or the public from fraud, abuse, security threats, or other harm.
We do not disclose customer security-testing data except to service providers or sub-processors necessary to provide the Services, as directed or authorized by the customer, or where required by law.
7. Data Retention
We retain information only for as long as reasonably necessary to provide the Services, fulfill contractual obligations, maintain security, comply with applicable legal requirements, resolve disputes, and enforce our agreements.
Unless a customer agreement specifies otherwise:
- Account and profile information is retained while the account or customer relationship remains active and may be retained for a reasonable period following account closure where necessary for legal, security, fraud-prevention, tax, accounting, or contractual purposes.
- Security-testing results, scan data, findings, reports, and associated evidence are retained while the applicable customer account or subscription remains active. Following account termination, security-testing data is deleted within 90 days, unless a different retention period is required by law or expressly agreed to in the applicable customer agreement.
- Audit and security logs may be retained as reasonably necessary for security monitoring, incident investigation, compliance, fraud prevention, and abuse prevention.
- Billing and transaction records may be retained as required to comply with applicable tax, accounting, contractual, and other legal obligations.
- Backup copies may temporarily persist following deletion as part of normal backup and disaster-recovery processes and will subsequently be deleted or overwritten in accordance with applicable backup lifecycles.
We may retain information for longer periods where required by law, necessary to establish, exercise, or defend legal claims, or necessary to investigate suspected fraud, abuse, or security incidents.
Eligible information may also be deleted upon customer request as described in Section 11.
8. Your Responsibilities for Security Testing
SimpleSec performs active security testing that can interact with systems and potentially access or reveal information contained within those systems.
By configuring a target for testing, you represent and warrant that you have authorization to test that target and have the necessary rights and lawful basis to process information that testing may access or reveal.
You are responsible for:
- Ensuring authorization exists for each target submitted for testing;
- Properly defining the scope of authorized engagements;
- Ensuring that testing complies with applicable law and contractual requirements;
- Maintaining appropriate authorization for credentials supplied to the Services; and
- Establishing an appropriate lawful basis for personal data contained in targets, credentials, findings, evidence, or other information submitted to the Services.
Summit Cyber implements safeguards designed to reduce unauthorized or unintended testing, including protected-infrastructure controls, access controls, and scan isolation. These safeguards do not replace the customer’s responsibility to obtain authorization and establish a lawful basis for testing.
9. Cookies and Similar Technologies
We use strictly necessary cookies and similar technologies to authenticate users, maintain sessions, secure the Services, prevent abuse, and support core application functionality.
These technologies may include security and bot-protection mechanisms provided by our infrastructure and edge-service providers.
We may also use limited diagnostic and performance technologies to understand application reliability and improve the Services. Where applicable law requires consent for nonessential cookies or similar technologies, we will obtain consent before using them.
Session tokens for the SimpleSec dashboard may be stored in your browser’s local storage to maintain your authenticated session.
10. Data Security
We implement technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, destruction, or misuse.
These measures include, as applicable:
- Encryption of sensitive information at rest;
- Encryption of information in transit using TLS;
- Salted and hashed password storage;
- Multi-factor authentication capabilities;
- Access controls;
- Audit logging;
- Per-scan isolation and network security controls;
- Encryption of sensitive credentials and connectivity information; and
- Use of established cloud infrastructure and security providers.
No method of transmission, processing, or storage can be guaranteed to be completely secure. Accordingly, while we maintain safeguards designed to protect information, we cannot guarantee absolute security.
11. Your Privacy Rights
Depending on where you live and applicable law, you may have rights concerning your personal information, including rights to:
- Access personal information we maintain about you;
- Correct inaccurate information;
- Request deletion of information;
- Receive certain information in a portable format;
- Restrict certain processing;
- Object to certain processing; and
- Withdraw consent where processing is based on consent.
To exercise an applicable privacy right, contact privacy@summitcyber.io.
We will respond in accordance with applicable law and may take reasonable steps to verify your identity before fulfilling a request.
EEA and United Kingdom
Individuals in the European Economic Area or United Kingdom may have additional rights under the GDPR or UK GDPR, including the right to lodge a complaint with an applicable supervisory authority.
California
California residents may have rights under the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”), including applicable rights to know, access, delete, and correct personal information and to opt out of certain sales or sharing of personal information.
Summit Cyber does not sell personal information.
We will not unlawfully discriminate against an individual for exercising applicable privacy rights.
Customer-Controlled Data
Where Summit Cyber processes personal information as a processor or service provider on behalf of a customer, the customer is generally responsible for responding to data-subject requests.
Where appropriate, we will refer requests concerning customer-controlled information to the applicable customer and provide reasonable assistance as required by our contractual and legal obligations.
12. International Data Transfers
Summit Cyber is based in the United States and uses service providers and sub-processors located in the United States and other jurisdictions.
Where required by applicable data-protection law, international transfers of personal data are protected through recognized transfer mechanisms. These may include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other legally recognized safeguards.
13. Children’s Privacy
The Services are intended for businesses and professional users and are not directed to children under 16 years of age.
We do not knowingly collect personal information directly from children through the Services. If we become aware that personal information has been collected directly from a child in circumstances where such collection is prohibited, we will take appropriate steps to delete the information.
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes to our Services, business practices, legal requirements, or other circumstances.
When we update this Policy, we will post the revised version and update the “Last updated” date above.
Where required by applicable law or contractual obligations, we will provide additional notice regarding material changes affecting how personal information is processed.
15. Contact Us
Questions, requests, or concerns regarding this Privacy Policy or our privacy practices may be directed to:
Summit Cyber Group LLC
25587 Conifer Rd, STE 105 PMB 503
Conifer, CO 80433
United States
Email: privacy@summitcyber.io
Data Protection Officer:
Rick Bohm, CISSP
Summit Cyber Group LLC
privacy@summitcyber.io
