Legal Information
Our terms, policies, and compliance documentation.
1. Acceptance of Terms
By accessing or using ThreatLens's platform, you agree to be bound by these Terms of Service. If you do not agree, you may not use our services.
2. Account Registration
You must provide accurate information when creating an account. You are responsible for maintaining the confidentiality of your account credentials and for all activities under your account. Multi-factor authentication is required for all accounts.
3. Service Description
ThreatLens provides real-time threat intelligence, including AI-powered threat detection, attack surface mapping, vulnerability correlation, and automated incident response. Features may vary by subscription plan.
4. Acceptable Use
You may not use our services to conduct unauthorized security testing against third parties, distribute malware, or engage in any unlawful activity. All threat intelligence data must be used in accordance with applicable laws and regulations.
5. Intellectual Property
Threat intelligence reports and analysis generated through our platform are licensed to you for internal use. ThreatLens retains rights to the underlying technology, AI models, detection algorithms, and platform infrastructure.
6. Data Handling
ThreatLens processes security telemetry data in isolated, encrypted environments. We do not share your organization's security data with other customers. All data processing complies with SOC 2 Type II requirements.
7. Subscription & Billing
Paid subscriptions are billed in advance on a monthly or annual basis. You authorize us to charge your payment method for applicable fees. Enterprise contracts may have custom billing terms.
8. Limitation of Liability
ThreatLens Inc. is not liable for indirect, incidental, or consequential damages arising from security incidents. Our platform provides threat intelligence and automated response capabilities but does not guarantee prevention of all security breaches. Our total liability is limited to fees paid in the 12 months preceding the claim.
9. Governing Law
These terms are governed by the laws of California, USA. Disputes will be resolved in the courts of California, USA.
Last updated: October 10, 2026
1. Information We Collect
We collect account information (name, email, organization details), security telemetry data (network logs, endpoint data, threat indicators), and technical data (browser, device, IP address) to provide and improve our threat intelligence services.
2. How We Use Your Data
Your security telemetry is used exclusively to provide threat detection and response services for your organization. ThreatLens uses anonymized, aggregated threat data to improve our AI detection models. We never share your organization's specific security data with third parties.
3. Data Security
We use military-grade encryption (AES-256 at rest, TLS 1.3 in transit), SOC 2 Type II certified infrastructure, regular penetration testing, and strict access controls. All security telemetry is processed in isolated environments with zero cross-tenant data access.
4. Data Isolation
Each customer's security data is processed and stored in logically isolated environments. Our infrastructure is designed with zero-trust principles — no employee can access customer data without explicit authorization and audit logging.
5. Third-Party Services
We share data only with essential infrastructure providers (cloud hosting, payment processing) under strict data processing agreements. Threat intelligence feeds are consumed but never include customer-specific data.
6. Your Rights
You may access, correct, export, or delete your data at any time through your dashboard or by contacting dpo@threatlens.pro. Data export is available in standard formats (STIX, CSV, JSON).
7. Data Retention
Security telemetry is retained according to your plan (30 days to unlimited). Account data is retained while your subscription is active and for 90 days after cancellation. Threat intelligence reports can be exported at any time.
8. International Transfers
Data may be processed in the United States. We comply with applicable data transfer regulations including GDPR Standard Contractual Clauses. On-premise deployment is available for organizations with data residency requirements.
Last updated: October 10, 2026
1. Essential Cookies
Required for authentication, session management, and core platform security functionality. These cannot be disabled.
2. Analytics Cookies
Help us understand platform usage patterns to improve the user experience. Can be disabled in your account settings.
3. Security Cookies
Used for threat detection, session integrity verification, and anomaly detection within the platform. These are essential for security operations.
4. Managing Cookies
You can control non-essential cookies through your account settings or browser preferences. Disabling security cookies may limit platform functionality.
Last updated: October 10, 2026
1. SOC 2 Type II
ThreatLens maintains SOC 2 Type II certification, verified through annual third-party audits covering security, availability, processing integrity, confidentiality, and privacy.
2. GDPR Compliance
We comply with the General Data Protection Regulation for all EU/EEA users. We offer Data Processing Agreements (DPAs) and support Standard Contractual Clauses for international data transfers.
3. NIST CSF Alignment
ThreatLens's security controls are aligned with the NIST Cybersecurity Framework. Our platform helps customers achieve and maintain compliance with NIST, ISO 27001, HIPAA, and PCI DSS requirements.
4. Data Processing Agreement
Enterprise customers can request a custom DPA. Contact dpo@threatlens.pro for details.
Last updated: October 10, 2026
1. Data Controller & Processor
You (the customer) are the data controller. ThreatLens Inc. acts as the data processor, processing security telemetry and personal data only on your documented instructions.
2. Sub-Processors
We maintain a list of approved sub-processors (cloud infrastructure, threat feed providers). We will notify you of any changes to sub-processors at least 30 days in advance.
3. Data Breach Notification
In the event of a data breach affecting your organization's data, we will notify you within 72 hours of becoming aware of the breach, in compliance with GDPR and applicable regulations.
4. Data Deletion
Upon termination of services, we will delete all customer data within 90 days unless retention is required by law. You may request earlier deletion or full data export at any time.
Last updated: October 10, 2026
Legal Contact
ThreatLens Inc.
1 Hacker Way, Suite 800, San Francisco, CA 94025, United States
dpo@threatlens.pro