Fabereye Cybersecurity
Privacy policy
Draft for professional review. This service is operated by Mariusz Gadula Digital Services in British Columbia, Canada. Questions can be sent to support@fabereye.com.
What we collect
We collect account and contact details, billing information required by Stripe, order and authorization records, target hostnames, testing windows, customer-provided scope information, assessment status and reports. Do not submit passwords or unnecessary personal information in free-text fields.
Service providers
The portal is hosted on Vercel, uses Neon PostgreSQL for production data, Stripe for payment processing, and a transactional email provider. Reports are stored in private S3-compatible object storage. These providers may process data in the United States or other countries where they operate.
The separate testing service uses local tools in isolated virtual machines and short-lived Docker instances. Its LLM orchestration sends necessary assessment context to OpenRouter and an eligible model-provider endpoint. Account-wide OpenRouter Zero Data Retention is enabled. This means prompts and responses are not persistently retained under the applicable ZDR route; it does not mean data never leaves the testing VM.
Retention and deletion
- Customer reports are available for 90 days after publication and then permanently deleted from active report storage.
- Testing credentials and ephemeral testing workspaces are deleted after testing or handoff.
- Temporary raw evidence is deleted after human report review and no later than 30 days after testing ends.
- Financial and tax records may be retained for the period required by Canadian law and professional advice.
Your choices
Contact support for access, correction, deletion or privacy questions. Some order, payment and tax records may need to be retained for legal or accounting reasons. We will not use customer target data to train a general-purpose model.