K9 Security Privacy Policy
Effective date: August 18, 2026
k9 Security Inc. ("k9 Security", "we", "us") provides software security services, including the k9 Security web application at k9security.io and the k9 Security MCP server at mcp.k9security.io ("Services"). This policy covers the Services and our marketing website at www.k9security.io, and is published at https://www.k9security.io/privacy; other k9 surfaces link or redirect here. It describes what information we collect, how we use it, and the choices you have. Questions and requests about this policy or your data: privacy@k9security.io.
1. Information We Collect
Account and identity information. When you sign in, our identity provider, Auth0 (an Okta company), authenticates you and issues us a signed token identifying your user account and your organization. We receive and store your name, email address, and organization membership. Auth0 processes your login credentials; we do not receive or store your password. If you sign in through Google or GitHub, we receive your name and email address from that provider. Signing in with GitHub does not give us any access to your repositories or code.
Billing information. If you purchase a subscription, our payment processor, Stripe, collects and processes your payment card details. We do not receive or store full card numbers; we receive and store your billing contact details, transaction records, and card metadata (such as card brand and last four digits) needed to administer your subscription. If you purchase through AWS Marketplace, AWS processes that transaction instead.
Service request data. When you or an AI agent acting on your behalf calls the k9 MCP server, we process the content of those requests. Depending on the tools used, request content includes public vulnerability identifiers (such as CVE and GHSA ids), software package names and versions, and information you or your agent supply to describe findings in your environment — for example file paths, repository and manifest names, execution-context descriptions, and risk-context statements about how your systems are deployed. The Services are not designed to receive source code, credentials, or secrets, and you should not submit them. Vulnerability lookups are answered from threat-intelligence data we mirror in our own infrastructure; your queries are never sent to external threat-data providers.
Risk-scoring records. When you use the risk-scoring tools, we record the finding submitted and the verdict returned, associated with your organization. These records expire automatically 90 days after creation.
Operational logs. Our infrastructure records service logs (request metadata, timestamps, and error information) to operate, secure, and troubleshoot the Services. Logs are retained for up to 30 days.
Website forms. If you fill out a form on www.k9security.io — for example to contact us, request content, or sign up for updates — we collect the information you enter, typically your name, email address, and any message you include. This information is stored in HubSpot, our marketing and CRM platform, and we use it to respond to you, deliver the content you requested, and send you related emails about k9 Security, which you can stop at any time using the unsubscribe link in every such email.
Website analytics. Our marketing website (www.k9security.io) uses Google Analytics, HubSpot, and PostHog to understand how visitors use the site; these tools set cookies and collect device, usage, and approximate location information. Where required by law, we request your consent before setting analytics cookies. The MCP server and web application do not use analytics cookies or advertising trackers.
2. How We Use Information
We use the information above to provide and operate the Services, to authenticate you and authorize access, to respond to support requests, to administer subscriptions and billing, to secure the Services and investigate abuse, to improve the Services and website, and to send you content you request and related marketing communications, which you can opt out of at any time. Consistent with our Terms of Service, we may analyze Service usage and disclose the results only in aggregate or other de-identified form that does not identify you, your organization, or your systems.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your data for third-party advertising.
3. How We Share Information
We share information only with the service providers that operate the Services and website, under agreements that limit their use of it to providing services to us:
- Amazon Web Services — cloud infrastructure hosting all Service data.
- Auth0 (Okta) — identity and sign-in.
- Stripe — payment processing and subscription billing.
- Google (Google Analytics) — website analytics for www.k9security.io.
- PostHog — website analytics for www.k9security.io.
- Google Workspace — email and business operations, including messages you send to our privacy and support addresses.
- HubSpot — marketing and CRM platform holding information submitted through forms on www.k9security.io, and website analytics that can associate your form submissions with your visits to the site.
If you purchase through AWS Marketplace, AWS also processes that transaction. We may disclose information if required by law, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to the transferred information.
4. Where Your Data Lives; International Users
The Services run in Amazon Web Services regions in the United States, and Service data is stored only in the United States. We are a U.S. company. If you use the Services from outside the United States, your information is transferred to and processed in the United States. Our service providers protect that data under their data processing agreements with us, including standard contractual clauses and, where applicable, their certifications under the EU-U.S. Data Privacy Framework.
For users in the European Economic Area, United Kingdom, and Switzerland: we process your information (a) to perform our agreement with you (providing the Services, billing, support); (b) for our legitimate interests in securing, operating, and improving the Services and preventing abuse; (c) to comply with legal obligations; and (d) with your consent where required, such as for analytics cookies. You have the rights described in Section 7, and you may also lodge a complaint with your local data protection supervisory authority.
5. Retention
Account information is retained for as long as you or your organization have an active agreement with us. Risk-scoring records expire automatically after 90 days. Triage reports are generated by your agent in your environment and stored by you, not by us; under our Terms of Service, you are responsible for retaining copies of reports required for your compliance or audit purposes. Operational logs are retained for up to 30 days. Billing records are retained as required for tax and accounting purposes. When your agreement ends, you have 30 days to export your data, as described in our Terms of Service; after that window, we delete your or your organization's remaining data within 60 days automatically — no request needed — except for limited copies in routine backups (which expire in the ordinary course) and records we are required to keep by law. You can also request earlier deletion at any time at privacy@k9security.io.
6. Security
We maintain reasonable and appropriate technical and organizational measures to protect your information. Service traffic is encrypted in transit using TLS. Stored customer data is encrypted at rest using AWS-managed encryption keys. Access to production systems follows least-privilege practices. No system is completely secure, and we cannot guarantee the security of information transmitted to us.
7. Your Choices and Rights
You may request access to, correction of, deletion of, or a portable copy of your personal information, or object to or ask us to restrict certain processing, by emailing privacy@k9security.io. We honor these rights for all users regardless of location, respond to verified requests within 30 days, and do not discriminate against you for exercising them. If you sign in through your organization, some requests (such as deleting your organization's account or data your organization controls) are handled through your organization's administrator, and we will refer those requests accordingly. You can opt out of marketing emails at any time using the unsubscribe link in each message, and you can opt out of analytics cookies on our website through the cookie banner on the site and standard browser settings.
8. Children
The Services are business tools and are not directed to children under 16. We do not knowingly collect personal information from children.
9. Changes to This Policy
We will post any changes to this policy at this address and update the effective date. Material changes will be announced to customers by email before they take effect.
10. Contact
k9 Security Inc. — privacy@k9security.io. Support requests: support@k9security.io or https://www.k9security.io/contact/.
