Privacy Policy

Last updated: [PUBLICATION DATE]

This policy explains what Agent-C Security, LLC (“Agent-C,” “we,” “us”) does with information collected through agentcsecurity.com (the “Site”).

We sell security assessments. It would be a poor look to be careless with your data, so we collect as little as we can get away with and we’re specific about what happens to it.


1. The short version

2. What we collect

Information you give us:

Where What
Checkup request / booking form Your name, email address, information about your application or repository, which tier you’re interested in, and anything else you type into the message field
Sample report request Your email address
Platform waitlist Your email address
Email to us Whatever the message contains, plus your address and any signature block

Information collected automatically:

We do not collect: account credentials (there are no accounts), payment card details (no payments happen on the Site), precise geolocation, biometric data, or any special-category / sensitive personal data. We don’t ask for any of it, so please don’t send it.

3. Your source code is not covered by this policy

This is worth stating plainly, because it is the thing our prospective clients most want to know.

This policy covers website visitors. It does not cover the material you provide during an actual engagement — your repository, credentials, architecture, findings, or any report we produce about your system.

That material is governed by the written services agreement and confidentiality terms for that engagement, which are considerably stricter than this page. Access is granted per-engagement, scoped, time-limited, and revoked on completion.

Do not send code, credentials, secrets, or security findings through the Site’s forms or by ordinary email. Those aren’t secure channels. Tell us what you need, and we’ll set up an appropriate one.

4. Why we use it, and on what basis

Purpose Basis (UK/EU GDPR terms)
Reply to your enquiry, scope and quote work Steps taken at your request prior to a contract
Send the sample report you asked for Consent
Send occasional product updates / waitlist news Consent — withdrawable at any time
Keep the Site available, secure, and free of abuse Legitimate interests
Understand aggregate traffic to improve the Site Legitimate interests (no personal data involved — see §5)
Meet legal, tax, and accounting obligations Legal obligation

We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects.

5. Cookies and analytics

The Site sets no cookies of its own, and stores nothing on your device for tracking purposes. There is no advertising pixel, no social widget, no session recording, no heatmap, and no cross-site tracker anywhere on this Site. There is no cookie banner because there is nothing to consent to.

We do measure aggregate traffic — which pages get read and roughly where visitors come from — because we can’t improve the Site blind.

Our analytics is Netlify Analytics, provided by our host, Netlify, Inc. It is server-side and cookieless: it runs no script on your device and stores no cookie or other identifier, does not fingerprint you, does not build a profile, and does not track you across other websites. It is derived from the standard server logs described in §2 and produces counts and trends, not records about individuals. We cannot identify you from it.

Global Privacy Control / Do Not Track. Because we run no cross-site tracking and sell no data, there is nothing for these signals to switch off. We honor them by design rather than by setting.

6. Who else touches your information

We use a small number of service providers. They process data on our instructions and are not permitted to use it for their own purposes:

Provider What they do What they see
Netlify, Inc. Hosts and serves the Site Standard server-log data for every request
[FORM / EMAIL PROVIDER] Delivers form submissions and any email list What you submit through a form; your email address
Netlify Analytics (Netlify, Inc.) Aggregate traffic measurement, derived from server logs Aggregate, non-identifying traffic data

We will also disclose information if we’re legally required to — a valid subpoena, court order, or lawful government request — or where necessary to establish or defend legal claims, or to protect the rights and safety of others. If we ever receive a legal demand for your information, we will notify you unless we are legally prohibited from doing so.

If Agent-C is ever acquired or merged, your information may transfer as part of that transaction. You’d be told before it became subject to a materially different policy.

7. What we don’t do

8. How long we keep it

Data Retention
Enquiries that don’t become engagements Up to 24 months, then deleted
Enquiries that become engagements For the engagement, plus the period required by our tax and legal obligations (generally 7 years)
Sample-report and waitlist email addresses Until you unsubscribe or ask us to delete, plus a suppression record so we don’t re-add you
Server logs Short rolling window set by our host
Aggregate analytics Retained as non-identifying aggregates

9. How we protect it

We keep the number of places your data lives small, use reputable providers, enforce multi-factor authentication on the accounts that hold it, serve the Site over HTTPS, and limit access to those who need it — currently a very short list.

No system is perfectly secure, and we won’t claim ours is. That’s the same honesty we bring to assessments. If a breach affects your personal information, we will notify you and any required regulator without undue delay.

10. Your rights

Wherever you live, you can ask us to:

Email privacy@agentcsecurity.com. We’ll respond within 30 days. We won’t charge you, and we won’t treat you differently for asking.

If you’re in California: you have the rights above under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing. Since we don’t sell or share, there’s no opt-out to exercise, but the right stands. You may use an authorized agent. We will not discriminate against you for exercising any of these rights.

If you’re in the UK, EU, or EEA: you have the rights above under the UK/EU GDPR, plus the right to withdraw consent at any time and the right to lodge a complaint with your supervisory authority. We are established in the United States, so your data is processed in the US. Where we transfer personal data out of the UK/EEA, we rely on the UK/EU Standard Contractual Clauses with our providers.

11. Children

The Site is for business users and is not directed to anyone under 16. We don’t knowingly collect information from children. If you believe a child has given us information, email privacy@agentcsecurity.com and we’ll delete it.

12. Changes to this policy

If we change this policy we’ll update the “Last updated” date above. If a change is material — a new category of data, a new purpose, a new class of recipient — we’ll say so prominently on the Site, and where the law requires consent, we’ll ask for it rather than assume it.

13. Contact

Agent-C Security, LLC
Nashville, Tennessee
Privacy: privacy@agentcsecurity.com
Security reports: security@agentcsecurity.com

The data controller for the purposes of the UK/EU GDPR is Agent-C Security, LLC.

← Back to the site