Privacy Policy
Last updated: April 26, 2025 · Effective immediately
Scorpion Security ("we", "us", "our") operates the Scorpion Security Platform. This policy explains what data we collect, why, and how we protect it.
1. Data We Collect
When you install and use the Scorpion platform, the following data is collected for license enforcement and abuse prevention:
- Hardware fingerprint — a one-way SHA-256 hash derived from CPU serial, motherboard serial, primary MAC address, and disk UUID. This hash cannot be reversed to recover original hardware identifiers.
- IP address — your internet-facing IP address at the time of activation and each license heartbeat.
- Hostname — the hostname of the machine running Scorpion.
- Usage metrics — aggregate counts: number of scans run, tools used, uptime hours. No scan targets, results, or report contents are transmitted.
- GeoIP data — country and city inferred from your IP address using MaxMind GeoLite2.
2. Why We Collect This Data
- License validation: enforce device limits per plan and detect unauthorized redistribution.
- Fraud prevention: detect cracked or shared license keys.
- Remote kill switch: revoke access in real-time if fraudulent use is confirmed.
- Product analytics: aggregate, non-personal usage trends to improve the platform.
We explicitly do not collect: scan targets, vulnerability results, credentials used in testing, report contents, or any data from the systems you scan.
3. Data Retention
- Active license data: retained for the subscription period + 90 days.
- Heartbeat logs: retained for 30 days on a rolling basis.
- Security flags: retained for 2 years for fraud investigation.
- Deleted accounts: all personal data deleted within 30 days of account closure.
4. Data Sharing
We do not sell your data. We share data only with:
- LemonSqueezy — payment processor (handles payment data independently).
- MaxMind — GeoIP lookup (IP addresses are sent to MaxMind's local database, no external call).
- Law enforcement when legally required.
5. Your Rights
You have the right to: access your data, request deletion, object to processing, and data portability. Submit requests to timaalien00@gmail.com.
6. Security
All communication with our license server uses TLS 1.3. License keys are signed with HMAC-SHA256. Hardware fingerprints are stored as non-reversible hashes. We conduct quarterly security reviews.
7. Contact
Data controller: Scorpion Security · timaalien00@gmail.com