Last updated: 15 June 2026 · VerlorenEnergie · KvK 95543511
ASMGUARD is a product of VerlorenEnergie, a private limited company registered in the Netherlands (KvK 95543511, VAT NL005159997B14). Our platform provides attack surface management and offensive security scanning services accessible at asmguard.com.
Contact: privacy@asmguard.com
When you register we collect your email address, display name, and a hashed password. We do not store plaintext passwords.
Domains, URLs, and API endpoints you register as scan targets. Scan findings, CVSS scores, and AI-generated reports are stored and associated with your tenant account.
Actions performed in the console are recorded in an audit log for security and compliance purposes. Audit log entries are anonymised (user_id set to NULL) rather than deleted when an account is removed.
Payment processing is handled by Mollie B.V. We store a Mollie customer ID and subscription status. We never store full card numbers or payment credentials.
Standard server logs (IP address, timestamp, HTTP method, path, status code) are retained for up to 30 days for security incident investigation.
We process your data on the following GDPR legal bases:
We do not sell your data to third parties. We do not use your scan data to train AI models.
We share data only with the following sub-processors, all bound by GDPR-compliant data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Mollie B.V. | Payment processing | Netherlands (EU) |
| Resend Inc. | Transactional email (fallback) | USA (SCCs) |
| Neon / Replit | Database & infrastructure hosting | USA (SCCs) |
| Sentry (optional) | Error monitoring | USA (SCCs) |
SCCs = Standard Contractual Clauses approved by the European Commission.
As a data subject you have the right to:
To exercise any right, email privacy@asmguard.com. We will respond within 30 days.
We use only a session cookie (sv.session) necessary for authentication, and a CSRF cookie (sv.csrf) necessary for security. No third-party tracking or advertising cookies are used.
We use industry-standard security measures including TLS encryption in transit, bcrypt password hashing, AES-256-GCM encryption for stored secrets, CSRF protection, and SSRF mitigation. For details see our security architecture documentation.
We may update this policy and will notify registered users by email at least 14 days before material changes take effect. Continued use of the service after the effective date constitutes acceptance.