Effective Date: 1 September 2026
Privacy Policy
This Privacy Policy describes how PandaOne(“we”, “us”, or “our”) collects, uses, discloses, and protects information in connection with our website at pandaone.dev, developer security tools, and autonomous penetration testing platform.
Our Security & AI Data Guarantee
We treat all security scan findings, repository metadata, and discovered vulnerabilities as strictly confidential. We never sell your data and we do not train public AI models on your private source code or scan results.
1. Overview & Scope
PandaOne provides continuous autonomous offensive security, AI-powered vulnerability assessment, and software development security tools. This Privacy Policy applies to personal data and technical data collected when you browse our websites, register for early access, use our web-based tools, or interact with our scanning services.
This policy does not supersede specific enterprise data processing agreements (DPAs) or custom written agreements executed directly between you and PandaOne.
For any privacy-related questions or data requests, you can contact our team at privacy@pandaone.dev.
2. Information We Collect
We collect information across several distinct categories:
2.1 Information You Provide to Us
- Account & Registration Details — Name, business email address, company name, role, and authentication credentials when requesting early access or accessing the platform.
- Scan Targets & Asset Identifiers — Domain names, URLs, IP addresses, APIs, and code repository links you explicitly submit for security scanning.
- Billing & Commercial Information — Subscription tier, transaction history, and payment metadata. Payment card processing is handled securely by PCI-DSS compliant third-party payment gateways; PandaOne does not store raw credit card numbers.
- Communications & Feedback — Inquiries, support requests, bug reports, and survey responses you send to us.
2.2 Security Scan & Telemetry Data
When an authorized scan is initiated, our autonomous engine interacts with the designated target to evaluate vulnerabilities. In this process, we collect and store:
- Target server HTTP response headers, status codes, and endpoint structures.
- Vulnerability verification traces, reproduction steps, and severity classifications.
- Generated remediation patches and pull request recommendations.
Scan findings are isolated per account and accessible only to authorized members of your organization.
2.3 Data Collected Automatically
- Device & Network Data — IP address, browser type and version, operating system, language preferences, and referring URLs.
- Usage & Performance Metrics — Timestamps, tool execution latency, feature interactions, and error diagnostic logs.
- Essential Cookies & Local Storage — Session security tokens, CSRF validation, and interface preference states (see our Cookie Notice).
3. How We Use Your Information
We process collected data for the following legitimate purposes:
- Service Delivery — Operating our platform, executing scheduled security scans, generating vulnerability reports, and creating automated remediation pull requests.
- Authentication & Security — Verifying user identity, managing multi-tenant isolation, protecting against unauthorized access, and mitigating denial-of-service abuse.
- Account & Payment Management — Processing invoices, administering billing, and delivering service notifications.
- Customer Support & Product Improvement — Diagnosing technical errors, optimizing scanner accuracy, and developing new detection capabilities.
- Legal & Compliance — Complying with applicable legal obligations and enforcing our Terms of Service.
4. Scan Data Confidentiality & Model Training
When utilizing advanced AI reasoning for vulnerability analysis and patch generation, PandaOne uses enterprise-tier AI infrastructure with strict zero-data-retention and non-training commitments. Your proprietary code, architecture traces, and vulnerability findings are never ingested to train public AI foundation models.
5. Legal Bases for Processing (GDPR / Global Standards)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing include:
- Contractual Necessity — To fulfill our agreement to deliver security testing services requested by you.
- Legitimate Interests — To safeguard platform integrity, detect malicious activity, and optimize performance, where our interests do not override your privacy rights.
- Legal Obligations — To comply with applicable tax, financial, and regulatory requirements.
- Consent — Where you have given explicit consent (e.g., subscribing to optional security research updates), which you can withdraw at any time.
6. Data Sharing & Third-Party Subprocessors
PandaOne does not sell, rent, or trade your personal or scanning information. We share data only with trusted service providers bound by strict confidentiality and data protection agreements:
- Cloud Infrastructure & Database Providers — High-security cloud hosting and database clusters (e.g., AWS, MongoDB Atlas) hosted in secure global regions.
- Payment Gateways — Certified PCI-DSS payment processors (e.g., Stripe, Razorpay) handling subscription checkout and billing.
- Transactional Communications — Secure email delivery providers for scan completion alerts, billing receipts, and authentication links.
- AI Analysis Providers — Enterprise AI APIs (e.g., Anthropic Claude) utilized strictly for automated vulnerability reasoning under enterprise data privacy controls.
- Legal Requirements — When required by applicable law, court order, or governmental regulation to protect life, safety, or legal rights.
7. Scan Authorization & Lawful Use
PandaOne is strictly designed for authorized security assessments. Users are required to warrant that they own or hold explicit written permission to test all submitted domains and digital assets. We reserve the right to immediately suspend scans or accounts that appear to target unauthorized third-party infrastructure.
8. Data Retention & Automatic Deletion
- Account Records — Maintained during the active lifetime of your account and deleted within 30 days of account termination upon request.
- Scan Telemetry & Artifacts — Raw scan logs and temporary probe artifacts are retained for 90 days for client review, after which they are automatically purged from active storage.
- Financial & Transaction Records — Retained for the statutory period required by applicable tax and accounting laws (typically 5 to 7 years).
9. Security Safeguards
We implement comprehensive technical and organizational measures designed to protect information from unauthorized access, alteration, or destruction:
- Encryption in transit using modern TLS 1.3 cryptographic protocols.
- Encryption at rest for all database clusters, backups, and scan findings using AES-256.
- Role-Based Access Control (RBAC) and strict least-privilege administrative access policies.
- Continuous vulnerability assessment of our own codebase and deployment infrastructure.
If you discover a potential vulnerability in PandaOne, please report it to our security team at security@pandaone.dev.
10. Your Privacy Rights
Depending on your geographic location, you may have the following statutory rights:
- Right of Access — Request confirmation and copies of personal data held about you.
- Right to Rectification — Request correction of inaccurate or incomplete information.
- Right to Erasure (“Right to be Forgotten”) — Request deletion of your personal data where retention is no longer necessary.
- Right to Restrict Processing — Request limits on how we process your personal data under certain conditions.
- Right to Data Portability — Obtain your data in a structured, machine-readable format.
- Right to Object — Object to data processing based on legitimate interests or direct marketing.
To exercise your rights, please submit a request to privacy@pandaone.dev. We respond to verified requests within 30 days.
11. International Transfers
PandaOne operates globally. Your information may be transferred to and processed in countries where our cloud infrastructure providers maintain data centers. For transfers from the EEA, UK, or Switzerland, we utilize standard contractual clauses (SCCs) and appropriate technical safeguards to ensure adequate protection.
12. Children's Privacy
PandaOne is an enterprise and developer security product not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from minors.
13. Updates to this Privacy Policy
We may periodically update this Privacy Policy to reflect platform enhancements or changes in regulatory obligations. When material changes occur, we will provide notice by updating the effective date at the top of this page and, where appropriate, notifying registered users via email.
14. Contact Us
For questions, data requests, or privacy concerns, please contact our team:
PandaOne Privacy & Compliance
Email: privacy@pandaone.dev
Security Disclosure: security@pandaone.dev
Website: pandaone.dev