Draft, pending counsel review

Privacy Policy

Security Checklist practices data minimisation. Assessment tools are designed to compute results client-side when possible. This page is a provisional summary; binding legal text is pending counsel review.

Purpose

This summary explains what kinds of data our product experience is built to avoid collecting, and how optional email capture is intended to work after a basic result is shown.

It is not a substitute for a counsel-approved privacy notice. Jurisdiction, controller identity, and retention schedules remain unpublished pending verification, listed in the verification register.

  • Describe intended data practices before launch
  • Point researchers to security disclosure channels
  • Keep draft legal pages noindex

Policy (provisional)

We do not design assessment flows to request passwords, authentication codes, recovery keys, full payment data, identity documents, Social Security numbers, complete birth dates, or private breach contents.

Email, when collected, should be optional, after a basic result is shown, with explicit consent and unsubscribe support. Sensitive answer detail should not be emailed in clear text.

  • Client-side computation preferred for checkup answers
  • No sale of passwords or identity documents, we do not ask for them
  • Affiliate redirect logging is limited to safe, allowlisted fields

Process (provisional)

Intended controls include input validation, CSRF protection, secure headers, rate limiting, and dependency scanning. Exact subprocessors and cookie inventory are pending verification before a counsel-approved notice publishes.

ChatGPT and search crawler logs may be retained for discovery measurement; they should not include assessment answer payloads.

  • Short retention for optional email reports (details not yet published)
  • Signed result tokens if email reports ship, no public enumeration
  • Operator mailing address not yet published pending verification

Accountability

Until counsel signs off, treat this page as informational only. Material privacy commitments will be updated here and dated when verified.

Security vulnerabilities that affect personal data should be reported via /security/ and security@securitycheckli.st.

  • Counsel review required before indexation as a legal notice
  • Contact for privacy questions: /contact/ (inbox not yet published)
  • Terms of use: /terms/

Assessment tools and optional email

Security checkup and finder tools are designed so answers can stay in the browser while a result is computed. We do not ask for passwords, MFA codes, government IDs, or full payment card data inside those flows.

If email capture ships, it should appear only after a basic result, remain optional, and avoid emailing raw sensitive answers in clear text. Until that backend exists, treat newsletter bands as non-functional without inventing a subscriber count.

  • Client-side preference for checkup answers
  • No breach-content uploads required to use guides
  • Affiliate redirect logs limited to allowlisted fields

Outstanding verification (honest status)

Controller legal name, mailing address, subprocessor list, cookie inventory, retention schedules, and regional rights request processes are not yet published, see the verification register in docs/completion-register.md.

This is intentional: we will not invent a polished legal notice. The page stays noindex until counsel review completes.

  • Inbox for general privacy mail not yet published
  • Security contact remains security@securitycheckli.st
  • Related: /terms/, /security/, /affiliate-disclosure/

Contact or escalation

Privacy questions: /contact/. Vulnerability reports: security@securitycheckli.st. Do not send passwords or identity documents to either channel.

  • Security disclosure: /security/
  • Accessibility: /accessibility/
  • Affiliate disclosure: /affiliate-disclosure/

Limitations

  • This is not final legal text and has not been reviewed by counsel.
  • Controller identity, DPA contacts, and regional rights processes are pending verification.
  • Third-party analytics or email vendors are not asserted until listed in a verified notice.

Expert guides & insights

Related pages

Trust, tools, and category hubs that connect to this policy.

Illustration for Terms of use

Legal

Terms of use

Provisional site terms pending counsel.

P012

Illustration for Contact

Trust

Contact

Reach the Security Checklist team.

P013

Stay ahead of online threats.

Email capture is not enabled in this preview. Use Contact if you want updates when the newsletter launches.