Korisec (“we”, “us”) provides automated website security checks for small businesses. This policy explains what we collect, why we collect it, and the choices you have.

Information we collect

  • Account details — name, email address, and password (stored hashed) when you register. If you sign in with Google, we receive your Google account ID, email, and basic profile information from Google.
  • Website data — domain names you submit for scanning, scan results, security findings, and related metadata (timestamps, scores, reports).
  • Free scan usage — when you run a quick check without an account, we process the domain you enter, your consent confirmation, and anti-abuse signals (such as IP address and Cloudflare Turnstile verification).
  • Billing — if you subscribe, payment processing is handled by Paystack. We store subscription status and customer references, not full card numbers.
  • Support & communications — messages you send us and service emails we send you (alerts, verification, password reset).
  • Technical logs — standard server logs (IP address, browser type, request timestamps) used for security, debugging, and rate limiting.

How we use information

  • Run security scans and deliver plain-English results
  • Operate your account, dashboard, and scheduled monitoring
  • Send security alerts and product emails you expect from the service
  • Process payments and manage subscriptions
  • Prevent abuse, fraud, and unauthorized scanning
  • Improve reliability and fix bugs

Third-party services

We use trusted providers to operate Korisec, including:

  • Google — optional sign-in (OAuth) and Safe Browsing reputation checks during scans
  • Cloudflare — Turnstile bot protection on public forms
  • Paystack — subscription billing
  • Email delivery — transactional messages from our mail infrastructure

These providers process data according to their own policies and only as needed to deliver the service.

Scanning & permission

You must only scan websites you own or have explicit permission to test. By submitting a domain, you confirm that permission. Our scans access publicly available information (such as HTTPS configuration, DNS records, and HTTP headers) — we do not attempt to bypass authentication or exploit vulnerabilities.

Data retention

We keep account and scan data while your account is active and for a reasonable period afterward so you can access history and reports. You may request deletion of your account and associated data from the dashboard or by emailing us.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Contact us at and we will respond within a reasonable time.

Security

We use encryption in transit (HTTPS), access controls, and industry-standard practices to protect your data. No online service can guarantee perfect security; please use a strong, unique password and keep your login credentials private.

Children

Korisec is a business service and is not directed at children under 16.

Changes

We may update this policy from time to time. We will post the revised version on this page and update the effective date above.

Contact

Questions about privacy? Email or .