Privacy Policy
Last updated: 2026-09-08
This policy explains what personal data Scopulars NETA collects, why, who we share it with, and what rights you have. It covers both the EU/UK General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).
1. Data controller
The data controller — the veri sorumlusu under KVKK — is Abdulsamet Buğdaylı, a natural person operating from İstanbul, Türkiye.
- Operator
- Abdulsamet Buğdaylı
- Legal form
- Sole proprietor / individual operator (gerçek kişi)
- Operating from
- İstanbul, Türkiye
- Contact
- privacy@scopulars.net
2. What we collect
2.1 Account and organization data
- Your email address and a cryptographic hash of your password (never the password itself).
- Your language preference and your organization’s name, slug, plan and seat count.
- The date and version of the legal terms you accepted at registration.
- If you enable two-factor authentication: your TOTP secret and recovery codes.
- If your organization uses SSO: the SAML configuration of your identity provider (entity ID, endpoints, signing certificate).
- Invitations you send: the invitee’s email address, the assigned role and an expiring invitation token.
2.2 Scan data — the targets you enter
- The targets you submit (IP addresses, subnets, domains, hostnames, API and GraphQL endpoints, container images, repositories and manifests).
- Scan results: open ports, detected services, product and version strings, operating system guesses, TLS/SSL details, identified CVEs with CVSS/EPSS/KEV context, findings, risk scores, compliance evaluations, discovered subdomains and assets, and any notes you add.
- Evidence of target ownership: the verification token and a hash of the proof you published (DNS TXT record or HTTP challenge file).
- Credentials you choose to store for authenticated scanning (SSH/WinRM) and for cloud posture scanning (AWS/Azure/GCP). Secret values are encrypted at rest; non-secret identifiers such as usernames, hostnames, role ARNs, project and subscription IDs are stored as entered.
- Destinations you configure for notifications and webhooks, and their signing secrets.
Scan targets frequently identify infrastructure rather than people, but an IP address or a domain can constitute personal data. We treat this category accordingly.
2.3 Billing data
Your Stripe customer identifier, subscription status, the date you upgraded, and charge records (amount, currency, refund status). We never receive or store your card number — card data is handled by Stripe.
2.4 Security and audit logs
For security-relevant actions we record the acting user and organization, the action and affected resource, the response status, your IP address, your browser user-agent string, and the request path. Values that look like passwords, tokens, secrets or card numbers are filtered out of the recorded metadata before it is written.
2.5 Cookies and local storage
We set an HTTP-only access_token cookie, and a refresh-token cookie scoped to the token-refresh endpoint, so that you stay signed in. These are strictly necessary for authentication. Your browser also stores your language preference locally. We do not use advertising, analytics or tracking cookies, and there is no third-party analytics script in the application.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating your account and providing scans, findings and reports | Performance of a contract (Art. 6(1)(b)) |
| Taking payment and managing subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Transactional email (welcome, password reset, scan completion, payment) | Performance of a contract (Art. 6(1)(b)) |
| Audit logging, abuse prevention, target-ownership enforcement, error monitoring | Legitimate interests in securing the platform (Art. 6(1)(f)) |
| Recording your acceptance of the legal terms | Legal obligation and legitimate interests (Art. 6(1)(c), (f)) |
Under KVKK, the equivalent bases are Art. 5(2)(c) (necessary for the performance of a contract) and Art. 5(2)(f) (legitimate interests of the data controller).
4. Who we share data with
We do not sell personal data and we do not share it for advertising. We use the following processors and third-party services. All of them are outside Türkiye, so using Scopulars NETA necessarily involves international transfer of your data.
4.1 Infrastructure and platform
- Railway — hosts the application backend, the PostgreSQL database and the Redis queue. All stored data described above resides here.
- Vercel — hosts and serves the web interface.
- Stripe — payment processing and the billing portal. Receives your email and payment details. Does not receive your scan data.
- Resend — delivers our transactional email. Receives your email address and the message content. Note that our scan-completion email names the scanned target, so a target you scanned can leave our systems in an email.
- Sentry — error and performance monitoring. Configured not to send personal data by default, and we filter authorization headers, password fields and card numbers from error reports. See the honest limitation in section 4.3.
4.2 Third parties that receive your scan targets
This is the disclosure that matters most for a security scanner. To enrich results, the Service sends target and finding data to independent third-party services. When this happens, the target you entered leaves our systems:
- VirusTotal, AbuseIPDB and Shodan — when threat-intelligence enrichment is used, the IP address or domain you are assessing is sent to these services and their reputation and exposure data is returned and cached.
- Certificate Transparency logs (crt.sh) — during attack surface discovery, the root domain you are assessing is queried to enumerate subdomains.
- Anthropic — when AI analysis runs, findings from your scan are sent to the Claude API to generate summaries and remediation advice. Before sending, we pseudonymize the data: the target address is replaced with a placeholder and product, version and free-text description fields are masked. Technical facts such as CVE identifiers, ports, services and severity scores are sent as-is.
- OSV — for software composition and SBOM analysis, the package names and versions found in your dependency manifests are queried.
- NVD (NIST), FIRST.org (EPSS) and CISA (KEV) — queried for vulnerability, exploit-probability and known-exploited data. These receive product, version and CVE identifiers, not your account identity.
Each of these is an independent controller of the data it receives, under its own privacy policy. If you do not want a target disclosed to a third party, do not use the enrichment features that query them.
4.3 A limitation we want to state plainly
Our error-monitoring filter removes credentials, passwords and card numbers, but it does not specifically strip scan data. If an error occurs while processing a scan, it is possible for scan details such as a target address to appear in an error report sent to Sentry. We consider this a residual risk rather than an intended flow, and we prefer to disclose it rather than imply a guarantee we do not enforce in code.
5. Retention
We keep your account, organization, scan and finding data for as long as your account exists, so that your history remains available to you. We do not currently operate an automated deletion schedule that purges old scans or audit logs after a fixed period; when we introduce one, this section will state the periods. Invitation and password-reset tokens expire on their own. Records we are required to keep for accounting or legal purposes, and billing records held by Stripe, are retained for the period the law requires.
6. Security
- Passwords are stored only as hashes and are never recoverable by us.
- Scanning and cloud credentials are encrypted at rest; for cloud providers we support keyless access so that no long-lived secret needs to be stored at all.
- Traffic is served over HTTPS with strict transport security.
- Access to data is scoped to your organization, and every data query is filtered by organization membership.
- Two-factor authentication is available on your account and we recommend enabling it.
No system is perfectly secure. If you believe you have found a vulnerability in Scopulars NETA, please see the support page for how to report it.
7. Your rights
Under the GDPR you have the right to access your data, to have inaccurate data corrected, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interests. Under KVKK Art. 11 you have equivalent rights, including the right to learn whether your data is processed, to request correction or deletion, and to object to a result produced solely by automated analysis.
How to exercise them: email privacy@scopulars.net. We will respond within the period required by applicable law. Self-service account deletion and data export are not yet available in the product; until they are, deletion and access requests are handled by contacting us at that address.
You may also lodge a complaint with your local supervisory authority, or in Türkiye with the Personal Data Protection Authority (KVKK Kurumu).
8. Children
The Service is not directed at children and is not intended for anyone under 16. We do not knowingly collect their data.
9. Changes
We may update this policy; the updated text is published here and the version identifier at the top of this page changes when we do. We do not currently push notifications about such changes, so please check this page from time to time.
10. Contact
Privacy questions and rights requests: privacy@scopulars.net. Anything else: support@scopulars.net.