Legal

Privacy Policy

This notice explains what personal information Praeven Security LLC collects through praevensecurity.com, why it is collected, who it is shared with, and how long it is kept.

Effective July 31, 2026  ·  Last updated September 20, 2026

Scope. This notice covers the website, online purchases and policy-kit intake, and pre-engagement business communications. Information processed during another paid engagement, including training delivery, briefings, and PrismVector evaluation, is governed by the applicable engagement agreement, statement of work, rules of engagement, and any separate data processing terms.

1. What we collect

1.1 Information you submit

The website provides general contact, training, briefing, and PrismVector early-access forms. A reviewed policy purchase also uses an organization intake form. Depending on which you use, a submission may include:

  • Name, business email address, and organization
  • Workforce size, program selection, or estimated attendance
  • Approximate endpoint count and a description of an intended assessment environment
  • Event date, format, accessibility requirements, and recording expectations
  • Any free text you enter in a message field

Forms state that credentials, exploit detail, Controlled Unclassified Information, and confidential system information must not be submitted. Please observe that.

1.2 Purchase and delivery information

When you start or complete checkout, Praeven records an order identifier, product, price, currency, purchase status, the email supplied through Stripe, the accepted purchase-terms version and time, and delivery or download status. Stripe processes the payment credentials; Praeven does not receive your full payment-card number.

1.3 Information collected automatically

When a form is submitted, the following is recorded alongside it:

  • IP address and country, as reported by the content delivery network
  • The page the form was submitted from
  • A timestamp

The website uses no analytics software. We do not use page-view tracking, visitor profiling, or advertising technology. Form security, checkout, and delivery use the operational records described in this notice.

2. Why we collect it

  • To respond to your inquiry and scope potential work
  • To prevent automated abuse of the forms
  • To maintain a record of pre-engagement correspondence
  • To process purchases, deliver products, provide purchase support, and administer refunds
  • To document the terms accepted for an order and prevent unauthorized downloads
  • To comply with legal obligations

This information is not used for automated decision-making, and it is not used to build advertising or marketing profiles.

3. Who it is shared with

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws.

Three service providers process information on our behalf:

Service providers and the information they process
ProviderRoleWhat it processes
Cloudflare, Inc.Hosting, content delivery, form and order processing, storage, and bot preventionForm submissions, order and delivery records, IP address, technical request data, and purchased files
Google LLCBusiness email, form and purchase notifications, and reviewed-kit intakeForm and intake submissions, purchaser email, order identifier, and delivery link
Stripe, Inc.Hosted checkout, payment processing, receipts, refunds, and payment-risk controlsPurchaser and billing information, payment credentials, order details, accepted-terms record, and transaction status

Beyond these, information is disclosed only where required to comply with law or lawful process, to protect rights, property, or safety, or in connection with a merger, acquisition, or sale of assets, subject to the protections in this notice.

4. Cookies and similar technologies

Praeven does not use cookies or browser storage for analytics, advertising, or visitor profiling.

When you start checkout, Praeven sets a strictly necessary, HTTP-only order cookie for up to seven days. It connects the returning browser to the order without exposing the internal access value to page scripts. A successful Starter Kit flow may temporarily keep the private download token in the browser's session storage so the link survives navigation within that browser session.

Stripe's hosted checkout may use cookies or similar technologies needed for payment, fraud prevention, and service operation. Stripe describes its practices in its privacy policy and cookie policy.

Pages containing forms load Cloudflare Turnstile, which verifies that a submission comes from a person rather than an automated script. In its default configuration Turnstile sets no cookie. If a visitor is presented with an interactive challenge, Cloudflare may set a short-lived cookie, approximately one hour, recording that the challenge was passed, and the widget stores a transient value in session storage for the life of the page.

These are strictly necessary for the security of the forms. They are not used for tracking, profiling, or advertising. Cloudflare's practices are described in its privacy policy at cloudflare.com/privacypolicy.

5. How long it is kept

Form submissions are retained for 24 months from the date of submission and are then deleted automatically by the storage system. Order, payment, accepted-terms, delivery, refund, and related support records are retained as reasonably necessary to administer the purchase and meet legal, accounting, tax, fraud-prevention, and dispute-handling obligations. Correspondence that leads to another engagement is retained under the terms of the applicable agreement.

6. Security

Submissions are transmitted over TLS, stored in access-controlled infrastructure, and reachable only through an authenticated interface. Access is limited to personnel who need it to respond to an inquiry. No system is completely secure. Where a breach affecting personal information occurs, affected individuals and regulators will be notified as required by law.

7. Confidentiality of scoping information

Information describing your systems, networks, or environment, submitted when requesting an assessment or a PrismVector evaluation, is treated as confidential business information. It is used only to evaluate and respond to your request, is not published or shared for any other purpose, and is subject to the retention period in Section 5. Any testing that follows is conducted only under a separate written agreement and defined rules of engagement.

8. Your rights

Depending on where you live, you may have the right to:

  • Know what personal information is held about you and how it is used
  • Access a copy of it
  • Correct inaccurate information
  • Request deletion, subject to legal exceptions
  • Opt out of sale or sharing. We do neither.
  • Not be discriminated against for exercising these rights

To make a request, email privacy@praevensecurity.com. We will confirm identity using information reasonably necessary to do so, and respond within the period required by applicable law. An authorized agent may submit a request on your behalf, subject to verification.

Recognized opt-out preference signals, including Global Privacy Control, are honored. Because we neither sell nor share personal information, no further action is required, but the signal is respected as a matter of practice.

9. Children

The website is intended for businesses and professionals. We do not knowingly collect personal information from anyone under 18. If we learn that we have, it will be deleted.

10. Links to other sites

The website links to third-party resources, including standards bodies and framework publishers. We are not responsible for their privacy practices.

11. Changes

This notice may be updated. The date above will change and material revisions will be identified.

12. Contact

Praeven Security LLC
Washington, United States
privacy@praevensecurity.com

Prepare. Anticipate. Protect.