Odysec

Privacy Policy

Last updated: July 30, 2026

Courtesy translation. This English text is provided for reference only. The legally binding version of this Policy is the Traditional Chinese version; in the event of any discrepancy, the Chinese version prevails.

This Policy explains what data Odysec (the "Service") collects, how it is used, where it is stored, and how long it is kept. Our principle is simple: we collect only what is necessary to perform the service, and we tell you explicitly what that is.

1. Data We Collect

1. Order data

2. Host assessment result files

Produced by you, by running the collector yourself — and uploaded only if you choose to. The contents are a configuration fingerprint of the examined host:

IncludedNot included
File paths and hashes (SUID binaries, system executables)
Contents of boot-time persistence entries
Names, paths and command lines of running processes
Listening ports and their processes
Local account names, UIDs, shells
Kernel module list, package list, hostname and kernel version
Your documents, mail, database contents
Any business or customer data
Contents of passwords, keys or certificates
Actual file contents (only hashes are computed)
Network traffic or communication contents

The result file is plain-text JSON. You can inspect it in full before uploading — or decide not to upload at all.

2-1. Backup verification result files

If you use backup restorability verification, the result file is produced by running the verification program yourself, and you decide for yourself whether to upload it. It contains: file names, sizes and verification outcomes of the restored artifacts (pass/fail and why), backup-related schedule command lines (password-like strings are redacted before the result file is written), the list of backup tools present on the host, statistics and repository format of the backup directory, and the type of offsite destinations (such as s3/sftp — full URLs are not recorded). It contains no file contents from your backups or restored artifacts. Storage and retention are the same as for host assessment result files (see Section 3).

3. Monthly email re-check subscription (optional)

If you subscribe to the monthly re-check after a free email check, we store the email address you entered and the domain name — those two items only.

4. Cloud tenant configuration exports (optional)

If you use the Microsoft 365 tenant configuration review, the export file is produced by you with read-only commands, and uploaded only if you choose to. It contains the tenant's security configuration values (e.g. whether legacy authentication is blocked, the number of admin accounts, whether audit logging is enabled) and account sign-in settings. It contains no mail contents, file contents, passwords or access tokens. The file is not stored — it is released from memory once the report is generated, the same as the config review.

5. Continuous monitoring subscription

If you subscribe to continuous monitoring, we store:

The baseline itself is never uploaded. It is a complete fingerprint of your system and stays on your own host (/var/lib/odysec/baseline.json, mode 600). We only receive diffs — so even as a subscriber, we still never hold a complete inventory of your system.

6. External attack surface monitoring

If you subscribe to external attack surface monitoring, we store:

The nature of this service is change detection, so scan snapshots must be retained for comparison, for the full duration of the subscription. All of the above is information obtainable from the public internet — none of it comes from inside your systems.

7. Server access logs

The web server keeps ordinary access logs (source IP, time, request path, response code) for troubleshooting and abuse prevention. Access to report pages (the /r/ path) is not logged, because those URLs contain the report access key.

8. What we do not do

2. Purposes of Use

The Service uses none of the above data for marketing. Notifications sent by subscription services are limited to the detection results of what you subscribed to and the liveness of the service itself.

3. Retention Periods

Data typeRetention
Assessment reports and uploaded result filesDeleted automatically after 30 days; the report URL expires at the same time
Order records (name, email, quota usage)Kept 12 months after the order's validity ends, for accounting and dispute handling
Monthly re-check subscription (email, domain)Kept until you unsubscribe; unconfirmed records deleted after 7 days
Cloud tenant configuration exportsNot stored; released once the report is generated
Continuous monitoring diff reportsKept during the subscription; deleted 12 months after it ends
External attack surface scan snapshots and change recordsKept during the subscription (required for comparison); deleted 12 months after it ends
Server access logs14 days
Encrypted backupsUp to 6 months, per backup retention policy

4. Security Measures

That said: no system can guarantee absolute security. We apply protections consistent with industry practice, but cannot promise absolute safety.

5. Your Rights

Under the Taiwan Personal Data Protection Act, you may exercise the following rights over your personal data held by the Service:

You may at any time ask us to delete your assessment reports and result files immediately, without waiting for the 30-day period. Write to contact@odysec.org and we will act promptly on receipt.

Some of these you can exercise yourself, without contacting us:

Note: if you request deletion of data necessary to perform the service, we may no longer be able to provide it.

6. Minors

The Service is designed for business and professional users. It is not directed at minors, and we do not knowingly collect personal data of minors.

7. Changes to This Policy

Changes will be announced on this page with an updated "Last updated" date. For material changes, we will additionally notify users with active orders by email.

8. Contact

For questions about this Policy or your personal data, write to contact@odysec.org.