Privacy Policy

Privacy should be understandable by design.

This Privacy Policy explains how ShabuShabu Security may collect, use, store and protect personal information when you visit this website, contact us, submit a security testing request or communicate with us about a vulnerability or potential engagement.

Last updated: August 19, 2026
Privacy overview How information may be used
01
Communication Respond to contact, testing and security-related requests.
02
Service planning Understand potential penetration-testing scope and requirements.
03
Security Protect the website, detect abuse and investigate security events.
04
Legal obligations Retain or disclose information where legally required.
01

Scope of this Privacy Policy

This Privacy Policy applies to personal information processed through the ShabuShabu Security website and communications initiated through this website.

It covers information submitted when contacting us, requesting penetration testing or a Security Crash Test, discussing web application, API or AI security testing, or reporting a suspected vulnerability.

A separate client agreement, statement of work or security-testing engagement may contain additional privacy, confidentiality and data-handling terms applicable to a specific assessment.

02

Information we may collect

Information you provide directly

When you contact ShabuShabu or submit a security-testing request, you may provide information such as:

  • your name and work email address;
  • company or product name;
  • the type of product or service you want assessed;
  • the requested security-testing service;
  • testing environment or product stage;
  • an intended launch date or testing window;
  • information describing the proposed testing scope;
  • technical restrictions, security concerns or other engagement context;
  • information contained in communications you send to us.

Information collected through use of the website

Our website infrastructure may generate technical information such as IP address, browser or device information, requested pages, request timestamps, referrer information, server logs and events relevant to security or abuse detection.

Please do not send secrets through initial contact forms.

Passwords, API keys, authentication tokens, private keys and other sensitive credentials should only be exchanged through an explicitly agreed secure channel when required for an authorized engagement.

03

How we may use personal information

ShabuShabu may process personal information for purposes connected with operating the website, communicating with visitors, evaluating security-testing requests and protecting our systems.

  • responding to questions and contact requests;
  • evaluating proposed penetration-testing or Security Crash Test engagements;
  • understanding product architecture, testing objectives and scope requirements;
  • preparing, managing or discussing a potential service engagement;
  • processing responsible vulnerability disclosures;
  • maintaining website security and investigating suspected abuse;
  • improving website operation and technical reliability;
  • maintaining necessary business and security records;
  • complying with applicable legal or regulatory obligations.

We do not need every possible piece of information about a prospective client in order to begin a conversation. Initial requests should contain only information reasonably necessary to understand the proposed engagement.

04

Legal bases for processing

Where applicable data-protection law requires a legal basis for processing, the basis depends on the purpose and context in which the information is collected.

Depending on the circumstances, processing may be necessary to respond to your request or take steps related to a potential contract, to perform an existing agreement, to comply with a legal obligation, or for legitimate interests such as operating and securing our website and business.

Where consent is required for a particular processing activity, we may rely on consent and provide a method to withdraw it where applicable.

05

Cookies and technical website data

The website may use cookies or comparable technical mechanisms that are necessary for site functionality, security, session handling or other core operations.

Optional analytics, measurement or similar technologies may only be described as part of this policy if they are actually configured on the website. Where applicable law requires consent for optional cookies, the relevant consent controls should be presented before those technologies are activated.

Browser settings may also allow you to block or delete cookies, although restricting essential website technologies can affect site functionality.

06

Service providers and processors

ShabuShabu may use third-party providers where reasonably necessary to operate the website, communicate with users, maintain infrastructure or provide security services.

Depending on the technical configuration of the website, such providers may include hosting infrastructure, email or communication providers, form-processing services, security providers, backups or other operational technology suppliers.

Personal information should be shared with service providers only to the extent reasonably necessary for the relevant function and subject to appropriate contractual or confidentiality obligations where required.

07

Security-testing engagement data

A penetration-testing engagement may involve technical information that is substantially more sensitive than ordinary website contact data.

Depending on the authorized scope, this may include test accounts, application architecture, API information, security findings, evidence, logs, screenshots, reproduction details and other information required to understand a validated vulnerability.

The processing and handling of information obtained during an active client assessment may be governed by additional Security Testing Terms, engagement documentation or confidentiality obligations.

Authorized testing only.

Information collected during a security assessment is intended to support vulnerability validation, reporting, remediation and retesting within the approved engagement scope.

08

Vulnerability disclosure information

If you submit a vulnerability report, we may process the contact and technical information included in the disclosure in order to review, reproduce, triage and remediate the reported security issue.

A disclosure may contain an affected URL or component, reproduction steps, technical evidence, security-impact analysis and information necessary for follow-up communication.

Researchers should avoid collecting or submitting unnecessary personal information belonging to third parties and should follow our Responsible Disclosure process.

09

Data retention

We do not establish an arbitrary single retention period for every category of information.

Information should be retained only for as long as reasonably necessary for the purpose for which it was collected, including communication, service delivery, security investigation, vulnerability remediation, recordkeeping, dispute management and applicable legal obligations.

Retention periods may therefore differ between ordinary contact messages, prospective engagement information, active security-testing records and validated vulnerability reports.

When information is no longer reasonably required, it should be deleted, anonymized or otherwise removed from active use where appropriate.

10

International processing

Some infrastructure or service providers may process information in jurisdictions different from the country in which you are located.

Where cross-border processing is subject to specific data-protection requirements, appropriate transfer mechanisms or safeguards should be used where required by applicable law.

11

Your privacy rights

Depending on your location and the law applicable to the processing, you may have rights regarding personal information held about you.

These may include requesting access to personal information, correcting inaccurate information, requesting deletion or restriction, objecting to certain processing, requesting portability where applicable, or withdrawing consent where processing depends on consent.

Some rights are subject to legal conditions, exceptions and verification requirements. We may need enough information to verify the requester before acting on a privacy request.

Where applicable, you may also have the right to raise a concern with the relevant data-protection or supervisory authority.

12

Information security

ShabuShabu approaches personal and technical data with security considerations appropriate to the type of information being processed.

No online environment can be represented as completely immune from risk. Security controls are therefore intended to reduce unauthorized access, disclosure, alteration, loss or misuse rather than promise absolute security.

If you believe information or a ShabuShabu-operated system may be affected by a security vulnerability, please use our Responsible Disclosure process.

13

Third-party websites

The ShabuShabu website may contain references or links to external websites, services or research resources that are operated by third parties.

Their privacy practices and data-processing activities are governed by their own policies. This Privacy Policy does not describe or control independent third-party processing.

14

Changes to this Privacy Policy

This Privacy Policy may be updated when the website, data-processing practices, security services or legal requirements materially change.

The date displayed at the top of the page indicates when this version of the policy was last updated. Material changes should be reflected in the published policy rather than silently relying on outdated wording.

15

Contact ShabuShabu about privacy

If you have a question about this Privacy Policy, want to make a privacy-related request or need clarification about how information submitted through the website is handled, contact ShabuShabu through our official Contact page.

For suspected security vulnerabilities, use the Responsible Disclosure process so the report can be routed as a security issue rather than a general privacy inquiry.

Privacy controls

Your information should remain understandable and controllable.

Applicable privacy rights depend on jurisdiction and the context in which personal information is processed.

01

Access

Ask whether personal information about you is processed and request access where applicable.

02

Correction

Request correction of inaccurate or incomplete personal information where applicable.

03

Deletion

Request deletion of personal information where the legal conditions for deletion are satisfied.

04

Restriction

Request limits on certain processing activities where applicable law provides that right.

05

Objection

Object to certain processing based on the circumstances and applicable legal basis.

06

Portability

Request eligible information in a portable form where the relevant legal requirements apply.

Security-sensitive information

A penetration-testing company may receive data that requires more care than an ordinary contact form.

Initial inquiries should remain high level. Credentials, architecture details, vulnerability evidence and other sensitive technical material should move to an appropriate channel only when there is a clear reason to process it.

Specific client engagements may also be subject to additional confidentiality, testing and information-handling terms agreed for that assessment.

Data minimisation What not to send initially
× Production passwords or account credentials.
× API secrets, access tokens or private keys.
× Large exports of customer or user information.
× Unnecessary confidential source code or internal documents.
✓ Provide only enough context to define the security need first.
Privacy questions

Need clarification about your information?

Contact ShabuShabu if you have a privacy question, want to make an applicable data request or need clarification about information submitted through the website.

Contact ShabuShabu ↗