Privacy Policy
Radar 36 Inc. ("Radar 36", "Company", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and security of data processed across our white-labeled cybersecurity operating platform.
1. Operating Entity & Scope
This Privacy Policy applies to the software, platform services, subdomains (*.radar36.app),
APIs, and white-labeled client portals operated by Radar 36 Inc., a corporation registered
under the laws of the State of Delaware, United States (Registered Address: 8 The Green, Ste. R, City of
Dover, County of Kent, DE 19901, USA).
Radar 36 serves as a Business-to-Business (B2B) white-label Security Delivery & VAPT Operating System designed for cybersecurity consultancies, MSSPs, boutique penetration testing agencies, and enterprise security teams.
2. Data Controller vs. Data Processor Roles
In accordance with global data protection laws (including EU/UK GDPR and US state privacy acts):
- Tenant Security Consultancies (Data Controller): Our client organizations ("Tenants") control the scope of data uploaded, target environments tested, vulnerability severity classifications, client contact lists, and compliance report distribution.
- Radar 36 Inc. (Data Processor & Infrastructure Provider): We process data solely on behalf of and according to the instructions of the Tenant organization, operating the secure database engine, automated retesting pipelines, reporting engines, and white-label portals.
3. Categories of Data We Collect
We process data across the following categories to deliver platform functionality:
- Account & Administrative Data: Name, work email address, phone number, company name, domain configuration details, billing records, and authentication credentials.
- Technical & Session Data: IP addresses, browser types, device identifiers, session tokens, audit log history, API access logs, and portal interaction metrics.
- Tenant Security Assessment Data: Vulnerability findings, CVSS v3/v4 severity vectors, proof-of-concept (PoC) code snippets, remediation recommendations, target IP/domain scope, asset metadata, and client compliance tracking records.
- White-Label Customization Assets: Custom domain names (CNAMEs), firm logos, brand colors, custom CSS styles, email gateway SMTP parameters, and custom report header/footer templates.
4. Processing of Tenant Security Findings & Data Use
We process Tenant Security Data exclusively to fulfill contractual services, including:
- Rendering white-labeled client portals and real-time risk heatmaps under your firm's brand.
- Compiling 1-click executive and technical compliance reports (DOCX, PDF).
- Triggering automated patch verification checking and retesting scripts.
- Providing AI-assisted compliance framework auto-mapping (SOC 2, ISO 27001, PCI-DSS, HIPAA, NIST CSF).
5. Zero Sale or Commercialization of Security Data
Strict Guarantee: Radar 36 Inc. does NOT sell, rent, monetize, trade, or share tenant vulnerability data, pentest findings, or client lists with any third party, advertiser, or data broker. All vulnerability data remains strictly confidential to your workspace.
Aggregated, non-identifiable usage statistics may be used internally to monitor system performance and platform scaling.
6. Deployment Architecture & Tenant Isolation
Radar 36 provides three deployment choices designed to accommodate varying compliance and sovereignty requirements:
- Multi-Tenant SaaS (`*.radar36.app`): Logical database isolation with dedicated schema partitioning, row-level tenant separation, and domain-scoped authentication.
- Single-Tenant Dedicated Cloud: Isolated containerized infrastructure deployed in customer-selected cloud regions (AWS, GCP, Azure) with dedicated database instances.
- Self-Hosted / On-Premises: Single-tenant air-gapped or on-premise installation where all security data remains 100% inside the consultancy’s or enterprise client's internal network perimeters.
7. Security Controls & Encryption Standards
Radar 36 Inc. employs defense-in-depth security measures to protect stored and transmitted data:
- Encryption in Transit: TLS 1.3 / HTTPS encryption for all browser sessions, API calls, and webhooks.
- Encryption at Rest: AES-256 bit encryption for database volumes, object storage, and backup snapshots.
- Access Control & Multi-Factor Auth (MFA): Role-Based Access Control (RBAC), SSO/SAML 2.0 support, and mandatory MFA support.
- Audit Logging: Granular timestamped logs tracking finding modifications, report downloads, user invites, and credential changes.
8. Sub-processors & 3rd Party Integrations
To deliver core infrastructure, Radar 36 Inc. engages trusted sub-processors under strict data protection agreements:
- Cloud Hosting Infrastructure: Amazon Web Services (AWS), Google Cloud Platform (GCP), Azure.
- AI Hosting Infrastructure: Amazon Web Services (AWS), Google Cloud Platform (GCP), Azure.
- Email Notification Delivery: SendGrid / Postmark (or Tenant's custom SMTP gateway).
- Security Scanner API Integrations: Optional tenant-configured API connections (Nessus, Qualys, OpenVAS, Burp Suite, Zapier).
9. Data Retention & Tenant Offboarding
Tenants retain full control over data retention parameters. Data is retained for the active subscription period plus account grace periods. Upon tenant account termination, Radar 36 provides data export tools (JSON/CSV) followed by permanent purging of database backups within 60 days, unless longer retention is required by applicable law.
10. International Data Transfers & Global Privacy Rights
As a US C Corp, Radar 36 Inc. processes data in secure US and international cloud centers. For international customers, data transfers are protected via Standard Contractual Clauses (SCCs). Users possess rights to access, rectify, port, or request erasure of personal data by submitting a verified request to our legal team.
11. Updates & Legal Contact
We may update this Privacy Policy periodically to reflect legal or platform developments. Material updates will be notified via email or dashboard alert.
8 The Green, Ste. R, City of Dover, County of Kent, DE 19901, USA
Email: info@radar36.com • Phone: +1 (302) 306-3064