Skip to main content

Privacy Policy

Your privacy matters. This policy explains how Vysiro Inc. collects, uses, and safeguards your information when you use our platform.

Effective Date: July 4, 2026

1. Introduction

Vysiro Inc. ("Vysiro," "we," "us," or "our") operates the website vysiro.com and the Vysiro domain trust scoring platform (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you access or use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

2. Information We Collect

We collect the following categories of information to provide and improve the Service:

2.1 Account Data

When you create an account, we collect your email address, display name, and authentication credentials through Firebase Authentication. If you sign in with a third-party provider (such as Google), we receive your name, email address, and profile picture from that provider.

2.2 Domain Scan Data

When you scan a domain, we collect and store the domain name, scan results (including DNS records, email authentication status, SSL certificate details, and DNSSEC configuration), TrustScore values (0–1000), issue breakdowns, and remediation recommendations. Scans are stored both globally (for public lookups) and within your tenant-scoped account.

2.3 DNS Provider Tokens

If you connect a DNS provider (such as Cloudflare) for automated fixes, we store an OAuth access token and refresh token. These tokens are encrypted using AES-256-GCM encryption before being stored in Firestore. We never store your DNS provider password. You can disconnect your DNS provider and revoke tokens at any time from your account settings.

2.4 Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, scan frequency, dashboard interactions, and AI Chat usage. This data is used to improve the Service and is not tied to advertising profiles.

2.5 API Usage Data

If you use the Vysiro API or MCP integration, we collect API request metadata including endpoints accessed, timestamps, response status codes, and rate limit consumption. API keys are stored as SHA-256 hashes; we do not store your raw API key after initial generation.

2.6 Payment Data

Payment processing is handled entirely by Stripe. We do not receive or store your credit card number, CVV, or full card details. We receive from Stripe your subscription status, plan tier, billing cycle, and a truncated card identifier (last four digits) for display purposes only.

3. How We Use Information

We use the information we collect for the following purposes:

  • Provide the Service: To perform domain scans, generate TrustScores, deliver scan reports, process automated DNS fixes, and provide AI-powered remediation guidance.
  • Improve the Product: To analyze usage patterns, identify bugs, optimize performance, develop new features, and improve the accuracy of our scoring algorithms.
  • Security: To detect and prevent fraud, abuse, and unauthorized access. To enforce rate limits, monitor for anomalous activity, and protect the integrity of the platform.
  • Communications: To send you account notifications, scan alerts, security warnings, billing receipts, and product updates. You can unsubscribe from non-essential communications at any time.
  • Analytics: To generate aggregate, anonymized statistics about domain security trends, TrustScore distributions, and platform usage for internal reporting and public benchmarks.
  • Compliance: To generate compliance reports and proof packs for supported frameworks (SOC 2, PCI DSS, NIS2, CISA, NIST, GDPR) as part of paid plan features.

4. Data Storage & Security

We take the security of your data seriously and employ multiple layers of protection:

  • Database: All data is stored in Google Cloud Firestore with encryption at rest enabled by default. Firestore provides automatic replication and high availability.
  • Tenant Isolation:Each customer's data is logically isolated using tenant-scoped Firestore collections and enforced through Firestore Security Rules. No customer can access another customer's data.
  • Encryption: All data in transit is protected with TLS 1.3. Sensitive fields (such as DNS provider tokens) use additional application-level AES-256-GCM encryption with unique initialization vectors.
  • Access Controls: Production database access is restricted to authorized personnel only. All access is logged. API keys are stored as one-way SHA-256 hashes.
  • Infrastructure:The Service is hosted on Vercel's globally distributed edge network with built-in DDoS protection, automatic SSL certificate management, and isolated serverless function execution.

5. Third-Party Services & Subprocessors

We use the following third-party services to operate the platform. This list also serves as our public subprocessor list. Each provider processes data under its own privacy policy and standard data processing terms; where required for transfers from the EEA/UK, Standard Contractual Clauses apply (see Section 10):

  • Firebase (Google):Used for user authentication (Firebase Auth) and database storage (Cloud Firestore). Subject to Google's Privacy Policy.
  • Stripe:Used for payment processing and subscription management. Stripe handles all credit card data directly. Subject to Stripe's Privacy Policy.
  • Vercel:Used for hosting, serverless function execution, and edge delivery. Subject to Vercel's Privacy Policy.
  • Google AI / Gemini: Used to power the AI Chat feature in the dashboard. Messages you send to the AI Chat are processed by the Gemini API to generate responses but are not stored by Google for model training. Chat messages are not retained after your session ends.
  • VirusTotal:Used for threat intelligence lookups when scanning domains. Domain names may be sent to VirusTotal's API to check for known malicious activity. Subject to VirusTotal's Terms of Service.
  • Cloudflare:Used as an optional DNS provider integration for automated fixes. If you choose to connect your Cloudflare account, we interact with Cloudflare's API on your behalf using your authorized OAuth tokens. Subject to Cloudflare's Privacy Policy.
  • OpenRouter:Used as a fallback provider for the AI Chat feature if the primary provider is unavailable. Chat messages routed through OpenRouter are subject to OpenRouter's Privacy Policy.
  • Upstash: Used for short-lived caching of rate-limit counters and usage metering (Redis). Cached entries are keyed by account identifier and expire automatically within minutes.
  • PostHog:Used for product analytics and client-side error tracking. Loaded only after you consent to analytics cookies (see Section 6). Subject to PostHog's Privacy Policy.
  • Google Analytics (GA4):Used for aggregate site usage analytics. Loaded only after you consent to analytics cookies (see Section 6). Subject to Google's Privacy Policy.

We will update this list when we add or replace a subprocessor that handles personal data, per Section 11.

6. Cookies & Tracking

We use the following categories of cookies and similar technologies:

  • Authentication Cookies: Firebase Auth session cookies are used to maintain your logged-in state. These are essential cookies required for the Service to function.
  • Preference Cookies: We may store user interface preferences (such as theme or dashboard layout settings) in local storage.
  • Analytics Cookies: With your consent, we use PostHog (product analytics) and Google Analytics (GA4) to understand aggregate usage and improve the Service. These are loaded only after you choose “Accept All” in our cookie banner. Choosing “Essential Only” disables them, and you can withdraw consent at any time by clearing the relevant cookies and local storage. These providers may set their own cookies subject to their respective privacy policies.

We do not use advertising cookies or third-party ad networks, and we do not sell your data to advertisers.

7. Data Retention

We retain your data for the following periods:

  • Account Data: Retained for the duration of your account plus 30 days after account closure to allow for reactivation.
  • Scan Results: Retained for the duration of your subscription plan. Free tier scans are retained for 90 days. Paid plan scans are retained according to your plan terms.
  • API Logs: Request metadata is retained for 30 days for debugging and rate limiting purposes.
  • Payment Records: Billing records are retained as required by applicable tax and financial regulations.
  • Account Deletion: When you close your account, we delete your personal data, scan history, connected provider tokens, and API keys within 30 days. Anonymized, aggregate data that cannot be linked back to you may be retained for analytics purposes.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

8.1 General Rights

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Data Export: Request a machine-readable export of your data, including scan history and account information.
  • Objection: Object to processing of your data for certain purposes.

8.2 European Economic Area (GDPR)

If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local data protection authority. Our legal basis for processing personal data is contractual necessity (to provide the Service you have requested) and legitimate interest (to improve and secure the Service).

8.3 California Residents (CCPA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect about you, the right to request deletion, and the right to opt out of the sale of your personal information. We do not sell your personal information to third parties.

To exercise any of these rights, please contact us at Support@vysiro.com. We will respond to your request within 30 days.

9. Children's Privacy

The Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at Support@vysiro.com.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including India (where our team is based) and the United States (where our infrastructure providers operate). These countries may have data protection laws that differ from those in your jurisdiction.

When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission for transfers from the EEA, and compliance with applicable data transfer frameworks. Our infrastructure providers (Google Cloud, Vercel, Stripe) maintain their own data transfer mechanisms and certifications.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page.
  • Notify registered users by email for significant changes.
  • Display a prominent notice on the Service for at least 30 days.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Vysiro Inc.

Privacy Inquiries: Support@vysiro.com

General Contact: Support@vysiro.com

Grievance Redressal (India, DPDP Act 2023): Support@vysiro.com (mark the subject line “Grievance”; we acknowledge and address grievances within the timelines prescribed by applicable law)

Website: vysiro.com