Skip to main content

New in August: Password manager research and finders updated Read more

Independent reviews. Real tests. Smarter security decisions.

SecurityChecklist

Privacy Policy

How SecurityChecklist approaches personal data: minimisation, assessment tools, contact forms, and affiliate logging. Written as a plain-language summary.

Independent methodology
Sources when claims need them
Affiliate disclosure where commercial

Summary

SecurityChecklist designs checkup and finder tools to keep basic answers in your browser and to avoid requesting passwords, MFA codes, identity documents, or full payment data. Optional email, when offered, comes only after a basic result.

Use /security-checkup/ without pasting secrets. Prefer /contact/ for privacy questions. Send vulnerabilities to /security/.

This is a summary rather than a formal legal notice. Controller details, retention schedules, subprocessor lists, and regional rights procedures are not covered here. Published 11 August 2026.

  • No sale of passwords or identity documents; we do not ask for them
  • Affiliate deal-link logging is allowlisted attribution, not open redirects
  • We do not publish product scores on this page.

Purpose

This summary explains what kinds of data our product experience is built to avoid collecting, how optional contact and email capture are intended to work, and what affiliate redirect logging is limited to.

It is not a substitute for a formal privacy notice. Our controller legal name beyond the public trading identity, jurisdiction-specific rights procedures, retention schedules, and subprocessor lists are not covered here.

Launch products under evaluation (Aura, NordPass, Bitdefender) may appear on commercial pages with sourcing limits. This privacy stub does not publish their scores, invent broker-removal guarantees, or collect credentials to check those products.

  • Describe intended data practices before wider commercial indexation
  • Point researchers to security disclosure channels
  • Legal review continues; this page states current practice

Who we are (public identity)

Public operator contact details match /about/ and /contact/: SecurityChecklist; intel@securitycheckli.st; +1 888 437 8441; One World Trade Center, 285 Fulton Street, 85th Floor, Suite 8500, New York, NY 10007, United States.

We do not invent a separate LLC or DPA entity name on this page. Formal controller language will carry a date when it is published.

  • Trading identity and postal address are published on About and Contact
  • No invented legal entity or privacy officer title
  • General privacy mail uses intel@securitycheckli.st until a dedicated privacy inbox is verified

Policy

We do not design assessment flows to request passwords, authentication codes, recovery keys, full payment data, identity documents, Social Security numbers, complete birth dates, or private breach contents.

Security checkup and finder tools are designed so answers can stay in the browser while a result is computed. Closing the tab ends the basic session for that result.

  • Client-side computation preferred for checkup and finder answers
  • No sale of passwords or identity documents; we do not ask for them
  • Basic tool results are shown without requiring email

Contact form data

The public contact form may collect name, email, optional company, enquiry type, subject, message, and consent. A honeypot field is present to reduce bots.

On the current static CDN host there is no Node API origin. Validated messages open a prefilled mailto to intel@securitycheckli.st after client validation and a browser rate limit (three successful submissions per hour). If a dedicated submission endpoint is added later, the form may send the message to it directly. Any credential for that service stays on the server and is never included in the page.

  • Do not send passwords, MFA codes, keys, card numbers, or unredacted IDs
  • Consent is required before submit
  • Direct email to intel@securitycheckli.st remains available

Affiliate redirect logging

Commercial product links to featured merchants are our own first-party tracked links. Destinations resolve only from an allowlisted merchant record with a verified destination. Where no verified destination exists the link stays inactive, because we do not send you to a guessed URL.

Safe attribution fields include merchant record, page id, placement, optional product/country/device/source tokens, and a derived subid. We do not accept an arbitrary destination URL from the query string.

  • Required page and placement parameters
  • HTTPS allowlisted destinations only
  • Affiliate payout does not set scores or recommendations

First-party analytics events

The site may record first-party analytics for tool starts, tool completions, outbound offer clicks, and contact form outcomes. These records exclude assessment answers and passwords.

We make no claims about Google Analytics, PostHog, or other third-party analytics on this page. Any future vendor will be listed only after verification.

  • No assessment answer bodies in event payloads
  • ChatGPT and search crawler logs may be retained for discovery measurement
  • Crawler logs should not include assessment answer payloads

Cookies and local storage

The contact form may use browser localStorage to enforce a client-side rate limit. Assessment answers are intended to remain in-memory or session-local for the basic result.

A full cookie inventory and consent record is not published on this page. We do not invent EU/UK cookie-banner compliance claims here.

  • Client rate-limit key: securitychecklist.contact_rate_v1
  • No invented advertising-cookie network claims
  • Legal review required before this is published as a legal notice

Children

SecurityChecklist tools and commercial pages are intended for adults making security decisions for themselves, households, or organizations. We do not knowingly design flows to collect children's personal data.

Family-safety tools ask about household responsibility at a high level and are not meant to gather a child's identity documents or account credentials.

  • No child-account signup product on this site
  • Do not submit children's sensitive identifiers via Contact
  • Report concerns via /contact/ or intel@securitycheckli.st

Process

Intended controls include input validation, CSRF protection where server forms exist, secure headers, rate limiting, and dependency scanning. Exact subprocessors remain pending verification.

Optional email reports, if shipped later, should require explicit consent, support unsubscribe, use short retention, avoid clear-text sensitive answers, and use signed result tokens without public enumeration.

Affiliate click logging and first-party analytics are designed without assessment answer bodies. Merchant destinations that have not been verified stay inactive rather than being guessed.

  • Short retention for optional email reports
  • Operator contact: intel@securitycheckli.st; postal address on /contact/ and /about/
  • Vulnerability reports: security@securitycheckli.st and /security/

Who should not rely on this page alone

Do not treat this summary as a GDPR or CCPA rights portal, DPA template, or shopping brief for Aura, NordPass, Bitdefender, or any other product. Anyone mid-compromise should contact their bank, platform, or local authorities as appropriate.

Skip pasting passwords, MFA codes, or identity documents into Contact to prove an issue. Use free hygiene steps and /security-checkup/ first. We do not publish product scores on this page.

  • Summary, not a formal legal notice
  • No product scores or removal guarantees here
  • Security vulns: /security/, not this privacy summary

Accountability

Our controller legal name beyond the published trading identity, a DPA mailing address, the subprocessor list, the cookie inventory, retention schedules, and regional rights request procedures are not published on this page.

This is deliberate. We would rather leave a clause out than publish one we cannot stand behind.

  • General privacy mail uses intel@securitycheckli.st until a dedicated privacy inbox is verified
  • Security contact remains security@securitycheckli.st
  • Related: /terms/, /security/, /affiliate-disclosure/

Contact or escalation

Privacy questions: /contact/ or intel@securitycheckli.st. Vulnerability reports: security@securitycheckli.st. Do not send passwords or identity documents to either channel.

Final verdict

  • No fabricated scores or invented lab results
  • Free remedies before paid recommendations on commercial pages
  • Commercial pages enter the sitemap once they are published

Limitations

  • This is a plain-language summary rather than final legal text.
  • Controller identity formalization, DPA contacts, and regional rights processes are pending verification.
  • Third-party analytics or email vendors are not asserted until listed in a verified notice.
  • Contact delivery on production currently uses mailto unless a separate CONTACT endpoint is provisioned.

Related reading

Continue with Personal Security Checkup

Open a live tool or guide for the next practical step.

Ready for a clearer next step?

Continue with a live guide or tool on SecurityChecklist.

Page information & sources

About this page

How SecurityChecklist approaches personal data: minimisation, assessment tools, contact forms, and affiliate logging. Written as a plain-language summary.

Methodology

Editorial responsibility

Published by SecurityChecklist editorial

Editorial policy

Corrections

Request a correction

Commercial disclosure

Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.