Privacy Policy
Last updated September 25, 2026
This policy explains how Alesian Security LLC ("Alesian", "we", "us"), a Colorado limited liability company, collects, uses, shares and keeps personal information in connection with alesiansecurity.com and the Alesian Security service (the "Service"). Our Your Data Rights page explains how to exercise your rights.
1. Our two roles
Controller. We decide how and why personal information is used for: account and billing information; website and security records; business contacts; and public information we collect ourselves about third-party domain names.
Processor. When a customer gives us information to process on its behalf, the customer is responsible for it and we act on its instructions. This covers DMARC aggregate and failure reports. Our Data Processing Addendum governs that processing. If your information reached us that way, contact the customer concerned first. We will help them respond.
2. What we collect
Account information: name, email address, role, password (stored only as an Argon2id hash), second-factor secret, and recovery codes (stored only as hashes).
Security records: IP address and browser user agent for sign-in sessions and second-factor checks; failed sign-in attempts (email address and IP address); and a log of actions taken in each account.
Billing information: organization name, billing email address and purchase history. Stripe processes card payments, and we never receive full card numbers.
What you give us: the names you watch, the properties you own, tags, notes, decisions about detections, block and takedown requests, evidence of abuse you send us (such as phishing messages, which can contain the names and email addresses of senders and recipients), and messages to support, and the email you send to verify control of a domain (the sending address, the subject and the message's authentication results).
Public information about domain names: DNS records, WHOIS registration records, the network owners of IP addresses, and blocklist status. Where a registrar publishes them, WHOIS records can include a registrant's name, email address, postal address or phone number.
Mail-defense information (as processor): DMARC aggregate reports, which contain the IP addresses and host names of servers that sent mail using a customer's domain, with message counts and authentication results. DMARC failure (forensic) reports, which can also contain the headers of an individual message, including sender and recipient addresses and subject line. Some providers include the content of the message; we discard the body and any attachments when the report arrives and keep only the headers.
Mail we receive at our own monitoring addresses: we create email addresses on domains we control and use them to sign up for mailing lists and other mail sent by organizations, so that we can measure how those organizations send mail (volume, frequency, authentication, and whether unsubscribing works). We keep the messages received, which contain the sender's business contact details and whatever the sender chose to include. These addresses belong to no real person.
Business contacts: names, job titles, work email addresses and work phone numbers of people at organizations we may work with, collected from public sources or introductions.
Website visitors: server logs recording IP address, page requested and time. We count page views with Cabin, a privacy-focused analytics service that sets no cookies and uses no identifiers; Cabin uses your IP address in memory only to find your country, and does not store it. We use no advertising or session-recording tools.
3. Cookies
We set only two cookies, both strictly necessary:
| Cookie | Purpose | Lifetime |
|---|---|---|
session | Keeps you signed in | 12 hours |
| Second-factor ticket | Links the two steps of sign-in | A few minutes |
Because both are strictly necessary, we do not ask for consent. We do not use advertising or analytics cookies. Our pages load fonts from Google Fonts, which receives your IP address when a page loads.
4. Why we use it
| Purpose | Information | Legal basis (where GDPR applies) |
|---|---|---|
| Providing and supporting the Service | Account, billing, what you give us | Contract |
| Keeping the Service and accounts secure; preventing fraud and abuse | Security records, account | Legitimate interests |
| Detecting and responding to impersonation of our customers | Public information about domain names | Legitimate interests (our customers' and the public's interest in preventing fraud) |
| Measuring how organizations send mail, using our monitoring addresses | Mail received at those addresses | Legitimate interests (protecting organizations and the public from spoofed mail) |
| Improving detection | De-identified, aggregated results | Legitimate interests |
| Understanding how our website is used | Website visits, counted without cookies by Cabin | Legitimate interests |
| Contacting organizations that may benefit from the Service | Business contacts | Legitimate interests (you may opt out at any time) |
| Keeping tax and accounting records | Billing | Legal obligation |
We do not currently rely on consent for any processing. We do not make decisions with legal or similarly significant effects about individuals by automated means alone.
5. Who we share it with
- Subprocessors that host and run the Service for us. They are listed on our Subprocessors page.
- Blocklist operators, when a customer requests a block: the domain name, the evidence we hold about it, and the customer's organization name.
- Registrars and hosting providers: only when we pursue a takedown a customer has requested: the domain, and the evidence of abuse.
- Advisers, authorities and courts: where required by law or needed to establish, exercise or defend legal claims, or to protect people from fraud.
- A buyer or successor: if our business is sold or reorganised, subject to this policy.
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as those terms are used in California law.
6. Where it is stored
We host the Service with Amazon Web Services in the United States (us-east-1). When we receive personal information from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum. We do not participate in the EU-U.S. Data Privacy Framework. Our analytics provider processes website visit data in Ireland.
7. How long we keep it
| Information | Kept for |
|---|---|
| Failed sign-in attempts | 1 day |
| Expired sessions | 7 days after expiry |
| Account and customer information | Life of the subscription plus 90 days (so a late renewal loses nothing), then deleted within 30 days; or deleted within 30 days of a request to close and delete |
| DMARC aggregate and failure reports (as processor) | Life of the subscription plus 90 days, then deleted within 30 days |
| DNS, WHOIS and blocklist history for domain names | Kept as a long-term historical record, because showing how a domain changes over time is part of the Service. This is information registrars publish, and most registrants' details are replaced by a registrar's privacy service. You can ask about a record that names you (see Your Data Rights) |
| Mail received at our monitoring addresses | 3 years |
| Account action log | 2 years |
| Billing records | 7 years |
| Business contacts | 2 years after last contact, or until you opt out |
| Backups | Expire 30 days after creation; a replaced backup expires 30 days after replacement |
Because of the backup cycle, deleted information can remain in backups for up to about 60 days. We do not restore it from backup except to recover from a failure. We may keep information longer where needed for an open block request or a legal claim.
8. Security
We encrypt information in transit, store passwords and recovery codes only as hashes, offer and allow administrators to require a second sign-in factor, restrict access to people who need it, and accept traffic to our servers only through our content delivery network. Stored data, including backups, is encrypted at rest. No system is completely secure. Our Security Overview gives more detail.
9. Children
The Service is not directed to anyone under 18, and we do not knowingly collect their personal information.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete or port your personal information, to object to or restrict its use, and to appeal our decision. We respond within one month (45 days where US state law applies), and may extend that where the law allows. See Your Data Rights for how to make a request.
If you are unhappy with our response, you may complain to your data protection authority, or in the United States to your state Attorney General.
11. Changes
We will post changes here and update the date above. We will email account holders about material changes before they take effect.
12. Contact
Alesian Security LLC, Arvada, Colorado. Privacy questions: admin@alesiansecurity.com.