loading

Privacy Policy

Aleph Security, Inc. offers innovative solutions for protecting applications and is deeply committed to upholding the highest standards of privacy and information security. This commitment is reflected in our product offerings and compliance environment. Our core values of accountability, integrity, transparency, privacy by design, and maintaining a strong internal security posture are integral to all decisions we make, and we adhere to best practices such as NIST and OWASP.

To be transparent with our customers, we have published this Privacy Policy. It outlines the information we collect through our products and services, how we use it, how we share it, and the controls we offer for accessing, updating, and deleting your information. We strive to present this information in a clear and easy-to-understand manner, without relying on confusing legal jargon. If you have any questions about this policy, please feel free to reach out to us at privacy@aleph-ecurity.com.

We want to provide clear and concise information about our Privacy Policy, which covers the following points:

  • The types of personal data we collect and where we obtain this information from
  • The reasons why we collect and use personal data
  • Circumstances under which we might share personal data with others
  • Measures we take to safeguard personal data
  • Your options for controlling your personal data
  • Specific information relevant to your region
  • Updates we may make to this Privacy Policy in the future.

Your Consent: By using our website at https://www.aleph-security.com (the "Site") and submitting personal data, you consent to our processing of that data as outlined in this Privacy Policy. This applies regardless of your location outside of the United States. If you do not agree to the terms of this Privacy Policy, please refrain from submitting your personal data through the Site.

We define "personal information" or "personal data" as data that identifies you as an individual, such as your name, email address, and phone number. This information is treated with care and is collected only for specific purposes, as outlined in this Privacy Policy.

The types of personal data we collect and where we obtain this information from

the personal data we collect, both through the Site and offline interactions with you, can be categorized as follows:

Categories of Data

  • Identifiers, such as your name, email address, telephone number, social media identifier, and signature
  • Internet activity information, such as your IP address, page requests, browser type, referring and exit pages, files viewed, operating system, and average time spent on the Site
  • Professional or employment-related information, including business contact information, job function, and company location
  • User content, including information you submit when contacting technical support, responding to surveys, or interacting with us on social media, as well as audio recordings or voicemails you submit to us
  • Communications data, including the content and metadata of communications with us
  • Sensory or surveillance data, such as voicemails and recordings provided in interactions with us
  • Commercial information, including products and services purchased and demos requested

We use technology to collect data and improve our service to you. This includes collecting information about how you interact with the Site. Both Contrast and our third-party service providers may collect this information. Below are some of the methods we use to collect data through technology:

  • IP address and other connection information: When you visit the Site, we collect your device identifier, browser information, and IP address. We cannot determine your identity based on your IP address alone.
  • Cookies: Cookies are small files transferred to your computer's hard drive that allow our systems to recognize your browser and capture certain information. We use cookies to understand how you use the Site and what web pages are of most interest to users. A complete list of cookies we use and why we use them can be found on our website.
  • Google Analytics: We use Google Analytics cookies to better understand our Site visitors. This includes data tied to your IP address (but not the address itself), such as the length of time spent on a page, the pages visited, and the websites visited before and after the Site. This information helps us offer better Site experiences and tools in the future. Please note that we do not collect any personal data through Google Analytics cookies, and we have adopted Google's "restricted data processing" configuration to prevent their collection of personal information about you.

Please note that we do not link your personal data to device identifier information, browser information, or IP addresses unless required to do so by law.

Our Site tracks your online activities on an individually identifiable basis over time and across websites or online services. For example, we may serve you ads on other websites based on your interests as indicated by your activity on our Site. We do allow third parties to use our Site to track your activities across different websites or online services.

Our Site includes links to Third-Party Sites and plug-ins from sites or applications operated by third parties such as Twitter, Instagram, and Facebook buttons. Contrast does not control these Third-Party Sites and is not responsible for the information they collect. The information collection practices of a Third-Party Site are governed by its own privacy policy. It is your choice to enter any Third-Party Site, and we recommend that you read their privacy policy if you choose to do so.

We comply with the Children's Online Privacy Protection Act (COPPA) and do not collect any information from anyone under the age of 13. Our Site, products, and services are intended for use by individuals who are at least 13 years old or older. If you are under the age of 13, you are not authorized to use the Site.

Categories of sources :

  • You: Refers to any individual who registers with our Site, inquires about the services we offer, engages with us over social media, or otherwise provides information directly to us.
  • Automated technologies: Refers to technologies that automatically collect data, such as browsing activity, on the Site.
  • Service providers: Refers to third-party entities that provide us with services, such as analytics providers, IT, and system administration services.
  • Third parties: Refers to external organizations that we may engage with to assist with distribution of our products or services.
  • Marketing/advertising companies: Refers to organizations such as social media platforms, consumer research companies, and analytics or marketing/advertising companies that may provide us with information for marketing or advertising purposes.
  • Recording technologies installed by Contrast: Refers to technologies such as voicemail and audio recording that may be installed by Contrast with consent to the extent required by law.
  • Our clients' web applications: Refers to the web applications of our clients for which we provide web application security services and products. We may collect and use personal data through our clients' web applications for the purpose of performing the web application security services on behalf of our clients. We do not collect or use personal data through your web applications for any purpose other than to provide the Service to which you have subscribed, including providing support and answering questions that you may have about the Service.

The reasons why we collect and use personal data

The data we gather is utilized to enhance your experience on our website. Here are some instances of how we use it

  • Delivering products and services to you
  • Administering customer support and addressing service complaints
  • Communicating with you
  • Sending you marketing information about our products and services if you have opted-in to receive such communications, including notifying you of promotions and sweepstakes
  • Troubleshooting technical issues on the Site
  • Responding to your questions and feedback
  • Conducting research and analysis
  • Marketing and advertising our products and services
  • Improving our products and services, developing new products and services, and conducting research on further improvements
  • Continuously evaluating and enhancing the online user experience
  • Detecting, preventing, and investigating violations of our Privacy Policy or any applicable terms of service or use, and investigating fraud or other related matters
  • Complying with the law or protecting the rights, property, or safety of Contrast, our users, or others, including maintaining network and information security, fraud prevention, and reporting suspected criminal activity.

Data Retention

We hold onto your personal data for the duration of our customer relationship, unless you explicitly request for it to be erased. Customer data will be deleted within 37 days of the conclusion of the agreement that pertains to our collection of your personal data, unless we have a contractual obligation or legal obligation that requires us to retain the data for a longer period of time. If you request for your data to be deleted earlier, we will keep it for 7 days after deletion to ensure that we comply with regulatory requirements before the data is permanently deleted.

Circumstances under which we might share personal data with others

We are committed to not selling your personal information or sharing it with third parties for cross-context behavioral advertising. However, we may disclose your personal data to the following categories of third parties:

  • Third-Party Service Providers: We may share your personal data with third-party service providers who work under contract with Contrast to help us provide services to you. They are only given the information they need to perform their designated functions, and they are not authorized to use, sell or disclose personal data for their own marketing or other purposes. Our hosting services are provided by Amazon Web Services (AWS), which adheres to the strictest compliance standards. For more information on their current certifications and compliance standards, please visit https://aws.amazon.com/compliance/programs/.
  • Public: We may release personal information to the public as part of a press release, for instance, to announce, with your organization's consent, that we have entered into a significant contract for our services.
  • Required Disclosures: We may be obligated to disclose personal information in response to a court order, subpoena, regulatory request, civil discovery request, or other legal process, or as otherwise required by law.
  • Legal Compliance and Protections: We may disclose personal information to government agencies, law enforcement, regulators, and other parties as required by law and necessary to protect the rights, property, or safety of Contrast, its subsidiaries or affiliates, employees, customers, and users.
  • Corporate Transactions: If Contrast is involved in a merger, sale, or acquisition, we may transfer your personal information in connection with the transaction. We will make every effort to notify you in advance of any such merger, sale, or acquisition, as well as any significant corporate reorganization or change in control.

We take primary responsibility for managing any personal data that you voluntarily provide to us and jointly use with our affiliates or third parties. We do not share your personal data with third parties for marketing purposes without your prior consent.

Measures we take to safeguard personal data

We place great importance on the security and confidentiality of your personal data. To protect your personal data from unauthorized access or disclosure and improper use, we have implemented technical, administrative, and physical security measures.

For instance, we utilize Transport Layer Security (TLS) encryption to safeguard the data collection forms on our Site, and we restrict access to your personal data. Only employees who require your personal data to perform their job functions, such as a customer service representative, are granted access. Employees with access to personal data are kept up-to-date on our security and privacy practices.

You can help us protect the security of your personal data in several ways:

  • It is crucial to protect your password and computer against unauthorized access. Always close your browser after completing your visit to the Site.
  • If you are asked to provide personal data or other confidential information to someone claiming to represent Contrast, please do not share that information and notify privacy@aleph-security.com. If you discover a security vulnerability at Contrast or with one of our products or services, please visit our Vulnerability Disclosure page or email security@aleph-security.com.

Please be aware that despite our best efforts, no security measure is ever entirely foolproof, so we cannot guarantee the complete security of your personal data.

Your options for controlling your personal data

If you wish to access, update, correct, or delete your personal data, you can contact us at privacy@aleph-security.com.