Full Site Background
🎓 VELLORE INSTITUTE OF TECHNOLOGY SPECIAL CAMPUS LAUNCH IS LIVE! CLAIM STUDENT OFFER
Data Protection & Privacy Policy

Privacy & Security Policy

Operated by AIVI Intelligence Private Limited. This policy details how we handle scanned target domains, GitHub tokens, user credentials, and security findings.

1. Information We Collect

We collect account identity information from Firebase authentication, domain origins you register, scan results produced by our multi-engine scanner (OWASP ZAP, Nuclei, Semgrep), and generated PDF report summaries. We do not inspect unrequested traffic or non-whitelisted assets.

2. Ephemeral In-Memory Code Analysis Guarantee

For GitHub repository scans, our background workers clone the specified repository branch ephemerally into volatile memory solely for static analysis (Semgrep). Absolutely no source code, repository files, or access tokens are permanently written to disk or retained in our databases; all cloned assets are completely purged immediately upon scan completion.

3. Mandatory Domain Authorization & Safe Harbor

Hack My Website is designed exclusively to audit domains verified and controlled by the customer. The platform strictly requires DNS TXT or .well-known token ownership verification before initiating any active DAST fuzzing or vulnerability testing.

4. Masking of Sensitive Detected Data

Our scanning engine automatically masks and scrubs raw detected secrets, leaked .env values, and production credentials before storing them in database records or rendering them in final report artifacts.

5. Data Retention & Account Deletion

Customers retain full ownership of their scan history and reports. Users can request immediate deletion of their account records and scan archives at any time by contacting support@hackmywebsite.io.

Last Updated: August 2026AIVI Intelligence Private Limited