Legal

Privacy Policy

Last updated September 25, 2026

Draft, not yet in effect. This document is being finalized. Highlighted text is still to be decided. Questions to admin@alesiansecurity.com.

This policy explains how Alesian Security LLC ("Alesian", "we", "us"), a Colorado limited liability company, collects, uses, shares and keeps personal information in connection with alesiansecurity.com and the Alesian Security service (the "Service"). Our Your Data Rights page explains how to exercise your rights.

1. Our two roles

Controller. We decide how and why personal information is used for: account and billing information; website and security records; business contacts; and public information we collect ourselves about third-party domain names.

Processor. When a customer gives us information to process on its behalf, the customer is responsible for it and we act on its instructions. This covers DMARC aggregate and failure reports. Our Data Processing Addendum governs that processing. If your information reached us that way, contact the customer concerned first. We will help them respond.

2. What we collect

Account information: name, email address, role, password (stored only as an Argon2id hash), second-factor secret, and recovery codes (stored only as hashes).

Security records: IP address and browser user agent for sign-in sessions and second-factor checks; failed sign-in attempts (email address and IP address); and a log of actions taken in each account.

Billing information: organization name, billing email address and purchase history. Stripe processes card payments, and we never receive full card numbers.

What you give us: the names you watch, the properties you own, tags, notes, decisions about detections, block and takedown requests, evidence of abuse you send us (such as phishing messages, which can contain the names and email addresses of senders and recipients), and messages to support, and the email you send to verify control of a domain (the sending address, the subject and the message's authentication results).

Public information about domain names: DNS records, WHOIS registration records, the network owners of IP addresses, and blocklist status. Where a registrar publishes them, WHOIS records can include a registrant's name, email address, postal address or phone number.

Mail-defense information (as processor): DMARC aggregate reports, which contain the IP addresses and host names of servers that sent mail using a customer's domain, with message counts and authentication results. DMARC failure (forensic) reports, which can also contain the headers of an individual message, including sender and recipient addresses and subject line. Some providers include the content of the message; we discard the body and any attachments when the report arrives and keep only the headers.

Mail we receive at our own monitoring addresses: we create email addresses on domains we control and use them to sign up for mailing lists and other mail sent by organizations, so that we can measure how those organizations send mail (volume, frequency, authentication, and whether unsubscribing works). We keep the messages received, which contain the sender's business contact details and whatever the sender chose to include. These addresses belong to no real person.

Business contacts: names, job titles, work email addresses and work phone numbers of people at organizations we may work with, collected from public sources or introductions.

Website visitors: server logs recording IP address, page requested and time. We count page views with Cabin, a privacy-focused analytics service that sets no cookies and uses no identifiers; Cabin uses your IP address in memory only to find your country, and does not store it. We use no advertising or session-recording tools.

3. Cookies

We set only two cookies, both strictly necessary:

CookiePurposeLifetime
sessionKeeps you signed in12 hours
Second-factor ticketLinks the two steps of sign-inA few minutes

Because both are strictly necessary, we do not ask for consent. We do not use advertising or analytics cookies. Our pages load fonts from Google Fonts, which receives your IP address when a page loads.

4. Why we use it

PurposeInformationLegal basis (where GDPR applies)
Providing and supporting the ServiceAccount, billing, what you give usContract
Keeping the Service and accounts secure; preventing fraud and abuseSecurity records, accountLegitimate interests
Detecting and responding to impersonation of our customersPublic information about domain namesLegitimate interests (our customers' and the public's interest in preventing fraud)
Measuring how organizations send mail, using our monitoring addressesMail received at those addressesLegitimate interests (protecting organizations and the public from spoofed mail)
Improving detectionDe-identified, aggregated resultsLegitimate interests
Understanding how our website is usedWebsite visits, counted without cookies by CabinLegitimate interests
Contacting organizations that may benefit from the ServiceBusiness contactsLegitimate interests (you may opt out at any time)
Keeping tax and accounting recordsBillingLegal obligation

We do not currently rely on consent for any processing. We do not make decisions with legal or similarly significant effects about individuals by automated means alone.

5. Who we share it with

  • Subprocessors that host and run the Service for us. They are listed on our Subprocessors page.
  • Blocklist operators, when a customer requests a block: the domain name, the evidence we hold about it, and the customer's organization name.
  • Registrars and hosting providers: only when we pursue a takedown a customer has requested: the domain, and the evidence of abuse.
  • Advisers, authorities and courts: where required by law or needed to establish, exercise or defend legal claims, or to protect people from fraud.
  • A buyer or successor: if our business is sold or reorganised, subject to this policy.

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as those terms are used in California law.

6. Where it is stored

We host the Service with Amazon Web Services in the United States (us-east-1). When we receive personal information from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum. We do not participate in the EU-U.S. Data Privacy Framework. Our analytics provider processes website visit data in Ireland.

7. How long we keep it

InformationKept for
Failed sign-in attempts1 day
Expired sessions7 days after expiry
Account and customer informationLife of the subscription plus 90 days (so a late renewal loses nothing), then deleted within 30 days; or deleted within 30 days of a request to close and delete
DMARC aggregate and failure reports (as processor)Life of the subscription plus 90 days, then deleted within 30 days
DNS, WHOIS and blocklist history for domain namesKept as a long-term historical record, because showing how a domain changes over time is part of the Service. This is information registrars publish, and most registrants' details are replaced by a registrar's privacy service. You can ask about a record that names you (see Your Data Rights)
Mail received at our monitoring addresses3 years
Account action log2 years
Billing records7 years
Business contacts2 years after last contact, or until you opt out
BackupsExpire 30 days after creation; a replaced backup expires 30 days after replacement

Because of the backup cycle, deleted information can remain in backups for up to about 60 days. We do not restore it from backup except to recover from a failure. We may keep information longer where needed for an open block request or a legal claim.

8. Security

We encrypt information in transit, store passwords and recovery codes only as hashes, offer and allow administrators to require a second sign-in factor, restrict access to people who need it, and accept traffic to our servers only through our content delivery network. Stored data, including backups, is encrypted at rest. No system is completely secure. Our Security Overview gives more detail.

9. Children

The Service is not directed to anyone under 18, and we do not knowingly collect their personal information.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete or port your personal information, to object to or restrict its use, and to appeal our decision. We respond within one month (45 days where US state law applies), and may extend that where the law allows. See Your Data Rights for how to make a request.

If you are unhappy with our response, you may complain to your data protection authority, or in the United States to your state Attorney General.

11. Changes

We will post changes here and update the date above. We will email account holders about material changes before they take effect.

12. Contact

Alesian Security LLC, Arvada, Colorado. Privacy questions: admin@alesiansecurity.com.