Legal

Privacy Policy

Effective: 11 August 2026 · Version: 1.5 · Controller: AssurePort Team · DPO contact: dpo@assureport.com

Language: The English version is the authoritative legal text. Türkçe / Deutsch / Français translations are provided for convenience; in case of conflict the English version prevails.

§1 Who we are & scope

AssurePort is an AI-powered penetration testing platform operated by the AssurePort Team, based in Türkiye. We are the controller for data we collect about visitors, account holders and billing contacts. For data our customers upload while running scans (target URLs, evidence captures, scan reports), we act as processor under Article 28 GDPR — see our separate Data Processing Addendum.

This policy covers assureport.com, app.assureport.com, and any subdomain we operate. It is written to satisfy GDPR Articles 12–14, Türkiye's KVKK transparency obligations, and the UK GDPR equivalents for visitors from Great Britain.

§2 Data we process

We minimise. We collect what is necessary to deliver the service and nothing more.

CategoryExamplesSource
Accountemail address, hashed magic-link tokens, session cookie (aprt.session), 2FA secret (hashed)you, on sign-up
Scan metadatatarget hostname, scan engine, reservation ID, start/end timestamps, finding count, scan statuscustomer-initiated
BillingPolar.sh customer ID, invoice ID, plan tier, per-scan reservation amount, token balance snapshot, billing ledger entries, paid amount, currency. We do not see card numbers — Polar.sh acts as Merchant of Record.Polar.sh webhook
Technical telemetrypseudonymised IP (last octet truncated), truncated user agent, request path, response code, request IDCloudflare edge logs
Support correspondenceemail body, attachments, ticket numberyou, on contact
Engine launch waitlist (v1.26.58, optional)email address, engine you're interested in (AD Security Assessment / SAP Pentest / Email Security), signup date, IP, browser User-Agent. Used solely to (a) notify you when the engine launches, and (b) deliver a one-time WAITLIST20 promo code valid for 14 days post-launch. Stored in Cloudflare D1 (EU region). Deleted 90 days after the engine launches. Opt out any time via the unsubscribe link in our emails or by writing to dpo@assureport.com.you, on public waitlist form
“Field notes” newsletter (2026-08-11, optional)email address, signup source, consent timestamp and a hash of the consent wording, hashed signup IP (never in clear text), browser User-Agent. Legal basis is consent (Art. 6(1)(a)), confirmed by double opt-in: an address is not added to the list until the confirmation link is clicked, and unconfirmed entries are deleted after 30 days. Every email carries a one-click unsubscribe link. Stored in Cloudflare D1 (EU region). Withdraw consent at any time via that link or by writing to dpo@assureport.com. Separate from the engine launch waitlist above — different list, different consent.you, on the newsletter form
Signup profile (v1.26.58, optional)given name, surname, country, city, organisation — collected during account creation to help us detect duplicate accounts, deter fraud and contact you for account-integrity matters. Every field is optional and may be left blank; the account can be created with email alone.you, on sign-up
Signup network metadata (v1.26.58, mandatory)IP address at the time of sign-up, user-agent string, Cloudflare request metadata (CF-Ray, CF-IPCountry), accepted UI language. Captured automatically to attribute the liability-waiver acceptance to a verifiable session.Cloudflare edge
Liability-waiver acceptance (v1.26.58, mandatory)waiver text hash (SHA-256), waiver version (v1.0), waiver language (en/tr/de/fr), accepted-at timestamp (ISO 8601), referenced ToS version (v1.2) and sections (§19, §20). Persisted in the append-only audit log as legal evidence of informed acceptance.you, on sign-up

§3 Lawful bases (GDPR Art. 6)

We do not use automated decision-making within the meaning of Article 22 GDPR. Scan AI agents produce findings that a customer reviews; token charging on scan completion is an accounting operation, not a decision producing legal or similarly significant effects on a natural person.

We do not share customer scan data with any third party outside the sub-processor list in §6. AssurePort does not currently expose webhooks, third-party integrations, single sign-on (SAML/SCIM/OIDC), or white-label / MSSP partner programs — see our Terms §10 for the architectural commitment.

§4 Retention schedule

WhatHow longWhy
Account profile (email, hashed credentials)1 year from last sign-in, then deletioncontract + abuse defence
Scan reports & evidence2 years from scan completioncustomer audit retention
Raw uploaded material (third-party scanner reports, mobile app binaries)30 days for uploaded scanner reports, 60 days for app binaries, then automatic deletion. The report we generate from them is unaffected and follows the 2-year row above.data minimisation — the raw file is only needed while the scan runs
Anonymous surface preview (result, target URL, user-agent)24 hours, then the content is erased. A minimal abuse-prevention skeleton (preview id, domain, hashed IP, timestamps, consent record) is kept 12 months, then deleted.rate-limit and abuse defence; consent evidence
Audit log (sign-ins, scans, settings changes)7 years. The audit log is append-only by design — entries are chained with an HMAC hash so that neither we nor an intruder can alter or remove one without breaking the chain. That tamper-evidence is the point of the log, so individual entries are never deleted; the same record also carries the liability-waiver acceptance evidence described above, which shares this period.tamper-evident incident record; DORA Art. 21 operational-risk evidence; establishment, exercise or defence of legal claims (Art. 17(3)(e))
Billing ledger (token reservations, charges, releases, grants)10 yearsTürkiye VUK / EU VAT obligation
Polar.sh invoices & payment events10 yearsaccounting / VAT obligation
Support email correspondence2 yearscontinuity, dispute defence
Cloudflare edge logs (pseudonymised)30 days rollingsecurity + uptime
Signup profile fields (name, surname, country, city, organisation)1 year from last sign-in, then deletion together with the accountaccount integrity / duplicate-account detection
Signup network metadata (IP, user-agent, Cloudflare CF-Ray / CF-IPCountry)7 years from sign-upDORA Art. 21 operational-risk evidence + establishment, exercise or defence of legal claims (Art. 17(3)(e))
Liability-waiver acceptance record (hash, version, language, timestamp, ToS reference)7 years from sign-upcontract evidence for ToS §19 (Customer Representations) and §20 (Indemnification)
Anonymous preview — scanned-domain surface summary (headers, fingerprint, robots/sitemap summary — describes the public domain, not the visitor)Up to 24 hours in a short-lived cache, then discardeddeduplication & rate control; no long-term storage
Anonymous preview — visitor abuse signals (IP keyed-hash, device fingerprint, entered domain, timestamp, rate counters)12 months from creation, then deletionabuse / DoS-facilitation prevention (Art. 6(1)(f))

On account deletion, scan reports and evidence are purged within 30 days, except where the law requires longer retention (billing ledger, Polar.sh invoices, signup network metadata and liability-waiver acceptance record).

§5 Your rights (GDPR Articles 15–22)

Send rights requests to dpo@assureport.com. We respond within one month (extendable to three for complex requests, with notice).

§6 Sub-processors

The following sub-processors process customer data on our behalf. We sign appropriate data-processing terms with each and require equivalent GDPR commitments. Updates to this list are published with at least 30 days' advance notice; you may object to a new sub-processor and, if we cannot accommodate, terminate without penalty.

ProviderPurposeData plane
Cloudflare, Inc. (US-incorporated)Edge compute, DNS, DDoS, Workers KVEU data plane, SCCs (Module 3)
Anthropic, PBC (US)AI inference for scan agentsSCCs (Module 3), zero-retention enterprise contract
Polar.sh (EU)Merchant of Record, invoice issuance, VAT remittance, token economics processorEU (Netherlands)
Resend (EU)Transactional email dispatch (magic links, invoices)EU (Ireland)
Fly.io, Inc. (US)Sandbox runners for scan executionEU region (Frankfurt), SCCs
No integrations, no MSSP partners. AssurePort does not currently expose webhooks, third-party integrations (Slack, Microsoft Teams, Jira, Linear, GitHub Issues, ZenDesk), Single Sign-On (SAML/SCIM/OIDC), or white-label / MSSP partner programs. This is a deliberate design choice: it guarantees that your scan findings, target metadata, and report content remain inside the AssurePort platform boundary and do not flow to any third party beyond the sub-processors listed above. If we introduce integrations in the future, we will add them as opt-in features, treat the destination as a sub-processor where applicable, and notify active accounts at least 30 days in advance.

§7 International transfers

Customer data is stored on EU regions. Where a sub-processor is incorporated outside the EEA (Cloudflare, Anthropic, Fly.io), transfers are governed by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) plus supplementary technical measures (encryption in transit and at rest, EU-restricted data planes). A transfer impact assessment is on file and available on request.

§8 Children

AssurePort is a B2B security service. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact dpo@assureport.com and we will delete the account within 72 hours.

§9 Breach notification

Where a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, we notify our lead supervisory authority within 72 hours (Art. 33). Affected individuals are notified without undue delay where the risk is high (Art. 34). Notification includes the nature of the breach, categories and approximate number of affected records, the DPO contact, likely consequences, and mitigation steps taken.

§10 Contact & changes

For privacy questions: dpo@assureport.com. For other legal matters: legal@assureport.com. Postal address available on request.

We may revise this policy as the service evolves. Material changes are notified by email to active accounts at least 30 days before they take effect. The "Effective" date at the top of this page reflects the current version.

§11 Fraud prevention & free-tier abuse

Update, 3 August 2026: the free full web penetration test is no longer offered. The anti-abuse processing described below still applies, because those signals are still collected at sign-up; what was withdrawn is the free benefit they protected.

We offer one free full web penetration test per new user. Because a real pentest consumes substantial compute and runs active checks against a target, we apply abuse controls to keep the free tier sustainable and to prevent a single actor from creating many accounts to obtain unlimited free scans. This section explains exactly what we process for that purpose, on what legal basis, and how you can object.

What we process for fraud prevention

Data pointForm storedPurpose
IP address at sign-upkeyed hash only (ip_at_signup_hash, HMAC-SHA256) — we do not store your plain-text IP for this controlsame-IP velocity check (1 free scan per IP per 24 h)
Browser / device fingerprintderived fingerprint identifierdetect one actor cycling through many accounts
User-agent stringas submitted by your browsersession attribution, bot detection
Target domain of the free scanregistrable domainper-domain uniqueness (one free scan per domain, lifetime)
Canonicalised email hashhash only — Gmail dot/+alias normalised, then hasheddetect the same mailbox re-registering under cosmetic variants
Email domain classboolean flag (disposable / temporary vs. durable)block throwaway mailboxes from the free tier; live MX check fails closed

We also enforce a global daily cap of 15 free scans/day across the whole platform as a circuit-breaker against coordinated abuse. None of these data points are used for advertising, marketing, sale, or any purpose other than fraud and abuse prevention, and none are shared outside the sub-processors in §6.

Legal basis

Our legal basis is legitimate interest (Art. 6(1)(f)) — specifically the prevention of fraud and abuse of a free service, which Recital 47 GDPR expressly recognises as a legitimate interest. We have completed and documented a Legitimate Interest Assessment (LIA) balancing our interest against your rights and freedoms; the balancing favours processing because the data is pseudonymised wherever possible (IP and email stored as hashes), the intrusion is minimal, there is no profiling that produces legal effects on you, and the data is never used for any secondary purpose. The LIA is available on request from dpo@assureport.com.

Retention

Fraud-prevention signals — the IP hash, device fingerprint, canonical email hash and free-scan grant records — are retained for 12 months from creation, then deleted. This retention period is separate from and shorter than the 7-year liability-waiver evidence record described in §4; the two records serve different purposes and are not co-mingled.

Automated free-scan eligibility decision & your right to object

The free-scan controls above run automatically. Where our fraud signals (for example a matching device fingerprint or an exceeded velocity limit) indicate likely abuse, the automated outcome is limited to declining the free scan for that request. Importantly:

If your email address is rejected because it belongs to a disposable or temporary mail provider, this is not a judgement about you — it is a category rule that keeps the free tier sustainable. You can complete sign-up with any durable email address (a work address, or a standard consumer provider), or purchase a paid scan, which is available to all addresses.

§12 Anonymous surface preview scan

Our homepage offers an anonymous surface preview: without signing in, a visitor can enter a website address and receive a quick, passive security surface summary. This section explains what that involves, what we process, on what legal basis, and how both the visitor and the owner of the scanned domain can object.

What the preview does — and does not do

The preview is a narrowed, passive reconnaissance only. It reads HTTP response headers, performs a shallow crawl of the homepage and its visible links, fingerprints the technology stack from the response, and reads publicly published files (robots.txt, sitemap.xml, /.well-known/). It is the same class of publicly observable data already exposed by our free, keyless tools at /tools.

The preview does not: send active payloads or exploits, enumerate paths or directories, probe authentication, attempt account enumeration, or run any destructive check. It does not display an exploitable attack-surface target list to the anonymous visitor.

What we process

Data pointForm storedPurpose
Visitor IP at preview timekeyed hash only (HMAC-SHA256) — no plain-text IP for this controlper-IP rate limit, abuse / DoS-facilitation prevention
Device fingerprintderived identifierdetect one actor cycling IPs to mass-scan third parties
Entered target domain + timestampregistrable domain + ISO timestampper-domain dedup, denylist matching, rate counters
Scanned-domain surface summary (headers, fingerprint, robots/sitemap — describes the public domain, not the visitor)short-lived cache, up to 24 hours, then discardeddeduplication & rate control; no long-term storage

Legal basis

Our legal basis is legitimate interest (Art. 6(1)(f)) — delivering the requested preview, and preventing abuse of the feature, which Recital 47 (fraud prevention) and Recital 49 (network and information security) recognise as legitimate interests. A documented Legitimate Interest Assessment and a Data Protection Impact Assessment are on file and available on request from dpo@assureport.com.

If you own a domain someone previewed

If the owner of a scanned domain does not want their site previewed through AssurePort, email abuse@assureport.com and we will denylist the domain from the preview feature. We also respect a machine-readable opt-out: if your site publishes a /.well-known/security.txt stating that automated testing is not permitted, the preview declines to run. The preview already blocks government, military, education, healthcare and brand-protected platforms (see Terms §20).

Your rights

Visitors may object to this legitimate-interest processing at any time (Art. 21) and request human review of a declined preview at dpo@assureport.com. The scanned-domain surface summary describes the public domain rather than the visitor and is held only in a short-lived 24-hour cache; the only visitor personal data we keep is the 12-month abuse signals described above.

Last updated: 23 June 2026 · Version: 1.4 (§12 anonymous surface preview scan) · See also: Terms · DPA · Cookies

Yürürlük tarihi: 11 Ağustos 2026 · Sürüm: 1.5 · Veri Sorumlusu: AssurePort Ekibi · DPO iletişim: dpo@assureport.com

Dil: İngilizce metin esas hukuki metindir. Türkçe / Almanca / Fransızca çeviriler bilgilendirme amaçlıdır; çelişki halinde İngilizce metin geçerlidir.

§1 Hakkımızda ve kapsam

AssurePort, Türkiye merkezli AssurePort Ekibi tarafından işletilen, AI tabanlı bir penetrasyon testi platformudur. Ziyaretçiler, hesap sahipleri ve faturalama irtibat kişileri hakkında topladığımız veriler için veri sorumlusu sıfatıyla hareket ederiz. Müşterilerimizin tarama çalıştırırken yükledikleri veriler (hedef URL'ler, kanıt yakalamaları, tarama raporları) bakımından GDPR'ın 28. maddesi uyarınca veri işleyen olarak hareket ederiz — ayrı Veri İşleme Sözleşmemize bakınız.

Bu politika assureport.com, app.assureport.com ve işlettiğimiz tüm alt alan adlarını kapsar. GDPR'ın 12-14. maddelerini, Türkiye KVKK aydınlatma yükümlülüklerini ve Büyük Britanya'dan gelen ziyaretçiler için UK GDPR karşılıklarını karşılayacak şekilde hazırlanmıştır.

§2 İşlediğimiz veriler

Asgariye indirmek temel ilkemizdir. Hizmeti sunmak için zorunlu olandan fazlasını toplamayız.

KategoriÖrneklerKaynak
Hesape-posta adresi, hashlenmiş magic-link tokenları, oturum çerezi (aprt.session), 2FA gizli anahtarı (hashlenmiş)siz, kayıt olurken
Tarama metaverisihedef ana bilgisayar adı, tarama motoru, rezervasyon kimliği, başlangıç/bitiş zaman damgaları, bulgu sayısı, tarama durumumüşteri tarafından başlatılır
FaturalamaPolar.sh müşteri kimliği, fatura kimliği, plan kademesi, tarama başına rezervasyon tutarı, token bakiye anlık görüntüsü, faturalama defter kayıtları, ödenen tutar, para birimi. Kart numaralarını görmüyoruz — Polar.sh Kayıtlı Satıcı olarak hareket eder.Polar.sh webhook
Teknik telemetritakma adlandırılmış IP (son oktet kesilmiş), kesilmiş user agent, istek yolu, yanıt kodu, istek kimliğiCloudflare edge logları
Destek yazışmalarıe-posta gövdesi, ekler, bilet numarasısiz, iletişime geçtiğinizde
Motor lansman bekleme listesi (v1.26.58, opsiyonel)e-posta adresiniz, ilgilendiğiniz motor (AD Security Assessment / SAP Pentest / Email Security), listeye katılma tarihiniz, IP'niz ve tarayıcı User-Agent'iniz. Yalnızca (a) motor yayına çıktığında sizi bilgilendirmek ve (b) lansman sonrası 14 gün geçerli tek seferlik WAITLIST20 promo kodu teslim etmek için kullanılır. Cloudflare D1'de (AB bölgesi) saklanır. Motor yayına çıktıktan 90 gün sonra silinir. E-postalarımızdaki abonelikten çık bağlantısı veya dpo@assureport.com ile her zaman vazgeçebilirsiniz.siz, açık bekleme formu
"Saha notları" bülteni (2026-08-11, opsiyonel)e-posta adresi, kayıt kaynağı, rıza zamanı ve rıza metninin özeti (hash), kayıt IP'sinin özeti (hiçbir zaman açık metin), tarayıcı User-Agent. Hukuki dayanak açık rıza (Md. 6/1-a) olup çift onay ile doğrulanır: adres, onay bağlantısına tıklanmadan listeye eklenmez; onaylanmayan kayıtlar 30 gün sonra silinir. Her e-postada tek tıkla abonelikten çıkma bağlantısı bulunur. Cloudflare D1'de (AB bölgesi) saklanır. Rızanızı istediğiniz zaman abonelikten çıkma bağlantısıyla veya dpo@assureport.com adresine yazarak geri alabilirsiniz.siz, bülten formu üzerinden
Kayıt profili (v1.26.58, opsiyonel)ad, soyad, ülke, şehir, kurum — yinelenen hesapları tespit etmek, dolandırıcılığı caydırmak ve hesap bütünlüğü konularında size ulaşabilmek için hesap oluşturma sırasında toplanır. Her alan opsiyoneldir ve boş bırakılabilir; hesap yalnızca e-posta ile oluşturulabilir.siz, kayıt olurken
Kayıt ağ meta verisi (v1.26.58, zorunlu)kayıt anındaki IP adresi, user-agent dizesi, Cloudflare istek meta verileri (CF-Ray, CF-IPCountry), kabul edilen arayüz dili. Sorumluluk feragatnamesi kabulünü doğrulanabilir bir oturuma bağlamak için otomatik olarak yakalanır.Cloudflare edge
Sorumluluk feragatnamesi kabulü (v1.26.58, zorunlu)feragatname metin hash'i (SHA-256), feragatname sürümü (v1.0), feragatname dili (en/tr/de/fr), kabul zaman damgası (ISO 8601), atıfta bulunulan Hizmet Koşulları sürümü (v1.2) ve maddeleri (§19, §20). Bilgilendirilmiş kabulün hukuki delili olarak yalnızca-ekle (append-only) denetim günlüğünde saklanır.siz, kayıt olurken

§3 Hukuki dayanaklar (GDPR Md. 6)

GDPR'ın 22. maddesi anlamında otomatik karar verme kullanmamaktayız. Tarama AI ajanları, müşterinin gözden geçirdiği bulgular üretir; tarama tamamlandığında token tahsilatı muhasebe işlemidir; gerçek kişi üzerinde hukuki veya benzer şekilde önemli etki doğuran bir karar değildir.

Müşteri tarama verilerini hiçbir üçüncü tarafla paylaşmıyoruz, §6'daki alt işleyici listesi dışında. AssurePort hâlihazırda webhook, üçüncü taraf entegrasyonları, çoklu oturum açma (SAML/SCIM/OIDC) veya white-label / MSSP ortaklık programı sunmamaktadır — mimari taahhüt için Hizmet Koşulları §10'a bakınız.

§4 Saklama süreleri

VeriSüreSebep
Hesap profili (e-posta, hashlenmiş kimlik bilgileri)son girişten itibaren 1 yıl, sonra silmesözleşme + kötüye kullanım savunması
Tarama raporları ve kanıtlartarama tamamlanmasından itibaren 2 yılmüşteri denetim saklaması
Yüklenen ham materyal (üçüncü taraf tarayıcı raporları, mobil uygulama dosyaları)yüklenen tarayıcı raporları için 30 gün, uygulama dosyaları için 60 gün, sonra otomatik silme. Bunlardan ürettiğimiz rapor etkilenmez; yukarıdaki 2 yıllık satıra tabidir.veri minimizasyonu — ham dosya yalnızca tarama sürerken gerekli
Anonim yüzey önizlemesi (sonuç, hedef URL, tarayıcı bilgisi)24 saat, sonra içerik silinir. Kötüye kullanımı önlemek için asgari bir iskelet (önizleme kimliği, alan adı, özetlenmiş IP, zaman damgaları, rıza kaydı) 12 ay tutulur, sonra silinir.hız sınırı ve kötüye kullanım savunması; rıza kanıtı
Denetim günlüğü (girişler, taramalar, ayar değişiklikleri)7 yıl. Denetim günlüğü tasarımı gereği yalnızca-ekle çalışır — kayıtlar HMAC özet zinciriyle birbirine bağlıdır; ne biz ne de bir saldırgan zinciri kırmadan bir kaydı değiştirebilir veya silebilir. Günlüğün varlık sebebi bu değiştirilemezlik olduğu için tekil kayıtlar hiçbir zaman silinmez; aynı kayıt yukarıda açıklanan sorumluluk feragatnamesi kabul delilini de taşır ve bu süreyi paylaşır.değiştirilemez olay kaydı; DORA Md. 21 operasyonel risk delili; hukuki taleplerin tesisi, kullanılması veya savunulması (Md. 17(3)(e))
Faturalama defteri (token rezervasyonları, tahsilatlar, iadeler, hediyeler)10 yılVUK / AB VAT yükümlülüğü
Polar.sh faturaları ve ödeme olayları10 yılmuhasebe / VAT yükümlülüğü
Destek e-posta yazışmaları2 yılsüreklilik, uyuşmazlık savunması
Cloudflare edge logları (takma adlandırılmış)dönen 30 güngüvenlik + çalışma süresi
Kayıt profili alanları (ad, soyad, ülke, şehir, kurum)son girişten itibaren 1 yıl, hesapla birlikte silmehesap bütünlüğü / yinelenen hesap tespiti
Kayıt ağ meta verisi (IP, user-agent, Cloudflare CF-Ray / CF-IPCountry)kayıttan itibaren 7 yılDORA Md. 21 operasyonel risk delili + hukuki taleplerin tesisi, kullanılması veya savunulması (Md. 17(3)(e))
Sorumluluk feragatnamesi kabul kaydı (hash, sürüm, dil, zaman damgası, ToS referansı)kayıttan itibaren 7 yılHizmet Koşulları §19 (Müşteri Beyan ve Tekeffülleri) ve §20 (Tazminat) için sözleşme delili
Anonim önizleme — taranan alan adı yüzey özeti (header, parmak izi, robots/sitemap özeti — ziyaretçiyi değil herkese açık alan adını tanımlar)kısa ömürlü önbellekte en fazla 24 saat, sonra atılırtekilleştirme ve hız kontrolü; uzun süreli saklama yok
Anonim önizleme — ziyaretçi kötüye kullanım sinyalleri (IP anahtarlı hash, cihaz parmak izi, girilen alan adı, zaman damgası, hız sayaçları)oluşturulmasından itibaren 12 ay, sonra silmekötüye kullanım / DoS kolaylaştırma önleme (Md. 6(1)(f))

Hesap silme talebinde, tarama raporları ve kanıtları 30 gün içinde silinir; yasa daha uzun süreli saklama gerektirdiği durumlar (faturalama defteri, Polar.sh faturaları, kayıt ağ meta verisi ve sorumluluk feragatnamesi kabul kaydı) hariç.

§5 Haklarınız (GDPR Md. 15-22)

Hak taleplerinizi dpo@assureport.com adresine gönderin. Bir ay içinde yanıt veririz (karmaşık taleplerde bildirimle birlikte üç aya kadar uzatılabilir).

§6 Alt işleyiciler

Aşağıdaki alt işleyiciler müşteri verilerini bizim adımıza işler. Her biri ile uygun veri işleme şartları imzalarız ve eşdeğer GDPR taahhütleri talep ederiz. Bu listedeki güncellemeler en az 30 gün öncesinden duyurulur; yeni bir alt işleyiciye itiraz edebilir ve gereksinimleri karşılayamıyorsak cezasız fesih yapabilirsiniz.

SağlayıcıAmaçVeri düzlemi
Cloudflare, Inc. (ABD'de tescilli)Edge compute, DNS, DDoS, Workers KVAB veri düzlemi, SCC (Modül 3)
Anthropic, PBC (ABD)Tarama ajanları için AI çıkarımıSCC (Modül 3), sıfır saklama kurumsal sözleşmesi
Polar.sh (AB)Kayıtlı Satıcı, fatura düzenleme, VAT aktarımı, token ekonomisi işleyicisiAB (Hollanda)
Resend (AB)İşlemsel e-posta gönderimi (magic-link, faturalar)AB (İrlanda)
Fly.io, Inc. (ABD)Tarama yürütmesi için sandbox runner'larAB bölgesi (Frankfurt), SCC
Entegrasyon yok, MSSP ortağı yok. AssurePort hâlihazırda webhook, üçüncü taraf entegrasyonları (Slack, Microsoft Teams, Jira, Linear, GitHub Issues, ZenDesk), Çoklu Oturum Açma (SAML/SCIM/OIDC) veya white-label / MSSP ortaklık programı sunmamaktadır. Bu bilinçli bir tasarım tercihidir: tarama bulgularınızın, hedef metaverinizin ve rapor içeriğinizin AssurePort platform sınırı içinde kalmasını ve yukarıda listelenen alt işleyiciler dışında hiçbir üçüncü tarafa aktarılmamasını garanti eder. Gelecekte entegrasyonlar sunarsak bunları opsiyonel özellikler olarak ekler, uygun olduğunda hedefi alt işleyici olarak tanımlar ve aktif hesapları en az 30 gün öncesinden bilgilendiririz.

§7 Uluslararası aktarımlar

Müşteri verisi AB bölgelerinde saklanır. Bir alt işleyici AEA dışında tescilli ise (Cloudflare, Anthropic, Fly.io), aktarımlar Standart Sözleşme Maddeleri (Komisyon Uygulama Kararı (AB) 2021/914) ile tamamlayıcı teknik tedbirler (iletim ve depolama sırasında şifreleme, AB ile sınırlı veri düzlemleri) altında yapılır. Bir aktarım etki değerlendirmesi dosyamızdadır ve talep üzerine paylaşılır.

§8 Çocuklar

AssurePort bir B2B güvenlik hizmetidir. 18 yaş altı kişilerden bilerek veri toplamayız. Bir küçüğün hesap oluşturduğunu düşünüyorsanız dpo@assureport.com adresine bildirin; hesabı 72 saat içinde sileceğiz.

§9 İhlal bildirimi

Bir kişisel veri ihlali gerçek kişilerin hak ve özgürlüklerine yönelik risk doğurması muhtemel ise, baş denetim makamımıza 72 saat içinde bildiririz (Md. 33). Risk yüksekse ilgili kişiler gecikmesiz olarak bilgilendirilir (Md. 34). Bildirim, ihlalin niteliğini, etkilenen kayıt kategori ve yaklaşık sayılarını, DPO iletişim bilgisini, olası sonuçları ve alınan/önerilen önlemleri içerir.

§10 İletişim ve değişiklikler

Gizlilik soruları için: dpo@assureport.com. Diğer hukuki konular için: legal@assureport.com. Posta adresi talep üzerine paylaşılır.

Hizmet evrildikçe bu politikayı revize edebiliriz. Esaslı değişiklikler en az 30 gün önceden aktif hesaplara e-posta ile bildirilir. Sayfanın üst kısmındaki "Yürürlük" tarihi mevcut sürümü yansıtır.

§11 Dolandırıcılık önleme ve ücretsiz katman kötüye kullanımı

3 Ağustos 2026 güncellemesi: ücretsiz tam web penetrasyon testi artık sunulmamaktadır. Aşağıda açıklanan kötüye kullanım kontrolleri yürürlükte kalır; bu sinyaller kayıt sırasında hâlâ toplanmaktadır. Geri çekilen yalnızca korudukları ücretsiz haktır.

Her yeni kullanıcıya bir ücretsiz tam web penetrasyon testi sunuyoruz. Gerçek bir pentest önemli ölçüde işlem gücü tükettiği ve hedefe karşı aktif kontroller çalıştırdığı için, ücretsiz katmanı sürdürülebilir tutmak ve tek bir kişinin sınırsız ücretsiz tarama elde etmek amacıyla çok sayıda hesap açmasını engellemek için kötüye kullanım kontrolleri uygularız. Bu bölüm, bu amaçla tam olarak neyi işlediğimizi, hangi hukuki dayanağa dayandığımızı ve nasıl itiraz edebileceğinizi açıklar.

Dolandırıcılık önleme için işlediklerimiz

VeriSaklanan biçimAmaç
Kayıt anındaki IP adresiyalnızca anahtarlı hash (ip_at_signup_hash, HMAC-SHA256) — bu kontrol için açık metin IP'nizi saklamayızaynı IP hız kontrolü (IP başına 24 saatte 1 ücretsiz tarama)
Tarayıcı / cihaz parmak izitüretilmiş parmak izi tanımlayıcısıçok sayıda hesap arasında dönen tek bir aktörü tespit etme
User-agent dizesitarayıcınızın gönderdiği biçimdeoturum atfı, bot tespiti
Ücretsiz taramanın hedef alan adıkayıt edilebilir alan adıalan adı başına teklik (alan adı başına ömür boyu bir ücretsiz tarama)
Kanonikleştirilmiş e-posta hash'iyalnızca hash — Gmail nokta/+alias normalize edilir, sonra hashleniraynı posta kutusunun kozmetik varyantlarla yeniden kayıt olmasını tespit etme
E-posta alan adı sınıfıboolean bayrak (tek kullanımlık / geçici vs. kalıcı)tek kullanımlık posta kutularını ücretsiz katmandan engelleme; canlı MX kontrolü güvenli-kapalı (fail-closed) davranır

Ayrıca koordineli kötüye kullanıma karşı devre kesici olarak tüm platform genelinde günlük 15 ücretsiz tarama küresel üst sınırı uygularız. Bu veri noktalarının hiçbiri reklam, pazarlama, satış veya dolandırıcılık ve kötüye kullanım önleme dışında herhangi bir amaçla kullanılmaz ve hiçbiri §6'daki alt işleyiciler dışında paylaşılmaz.

Hukuki dayanak

Hukuki dayanağımız meşru menfaattir (Md. 6(1)(f)) — özellikle ücretsiz bir hizmetin dolandırılması ve kötüye kullanılmasının önlenmesi; bunu GDPR Gerekçe 47 açıkça meşru bir menfaat olarak tanır. Menfaatimizi haklarınız ve özgürlüklerinizle dengeleyen bir Meşru Menfaat Değerlendirmesi (LIA) tamamladık ve belgeledik; denge, verinin mümkün olan her yerde takma adlandırılması (IP ve e-posta hash olarak saklanır), müdahalenin asgari olması, üzerinizde hukuki etki doğuran bir profilleme bulunmaması ve verinin asla ikincil bir amaçla kullanılmaması nedeniyle işleme lehinedir. LIA, dpo@assureport.com adresinden talep üzerine paylaşılır.

Saklama

Dolandırıcılık önleme sinyalleri — IP hash'i, cihaz parmak izi, kanonik e-posta hash'i ve ücretsiz tarama hakkı kayıtları — oluşturulmasından itibaren 12 ay saklanır, sonra silinir. Bu saklama süresi, §4'te açıklanan 7 yıllık sorumluluk feragatnamesi delil kaydından ayrı ve daha kısadır; iki kayıt farklı amaçlara hizmet eder ve birbirine karıştırılmaz.

Otomatik ücretsiz tarama uygunluk kararı ve itiraz hakkınız

Yukarıdaki ücretsiz tarama kontrolleri otomatik çalışır. Dolandırıcılık sinyallerimiz (örneğin eşleşen bir cihaz parmak izi veya aşılmış bir hız sınırı) olası kötüye kullanıma işaret ettiğinde, otomatik sonuç yalnızca o istek için ücretsiz taramayı reddetmekle sınırlıdır. Önemle:

E-posta adresiniz tek kullanımlık veya geçici bir posta sağlayıcısına ait olduğu için reddedilirse, bu sizinle ilgili bir yargı değildir — ücretsiz katmanı sürdürülebilir tutan bir kategori kuralıdır. Kalıcı herhangi bir e-posta adresiyle (bir iş adresi veya standart bir tüketici sağlayıcı) kayıt işlemini tamamlayabilir ya da tüm adreslere açık olan ücretli bir tarama satın alabilirsiniz.

§12 Anonim yüzey önizleme taraması

Ana sayfamız bir anonim yüzey önizlemesi sunar: oturum açmadan, bir ziyaretçi bir web sitesi adresi girip hızlı, pasif bir güvenlik yüzeyi özeti alabilir. Bu bölüm, bunun ne içerdiğini, neyi işlediğimizi, hangi hukuki dayanağa dayandığımızı ve hem ziyaretçinin hem de taranan alan adı sahibinin nasıl itiraz edebileceğini açıklar.

Önizlemenin yaptığı ve yapmadığı

Önizleme yalnızca daraltılmış, pasif bir keşiftir. HTTP yanıt başlıklarını okur, ana sayfanın ve görünür bağlantılarının sığ bir taramasını yapar, yanıttan teknoloji yığınının parmak izini çıkarır ve herkese açık yayınlanmış dosyaları (robots.txt, sitemap.xml, /.well-known/) okur. Bu, /tools adresindeki ücretsiz, anahtarsız araçlarımızın halihazırda açığa çıkardığı, herkese açık gözlemlenebilir veri sınıfının aynısıdır.

Önizleme şunları yapmaz: aktif payload veya exploit göndermez, yol veya dizin numaralandırması yapmaz, kimlik doğrulamayı yoklamaz, hesap numaralandırması denemez veya herhangi bir yıkıcı kontrol çalıştırmaz. Anonim ziyaretçiye istismar edilebilir bir saldırı yüzeyi hedef listesi göstermez.

İşlediklerimiz

VeriSaklanan biçimAmaç
Önizleme anındaki ziyaretçi IP'siyalnızca anahtarlı hash (HMAC-SHA256) — bu kontrol için açık metin IP yokIP başına hız sınırı, kötüye kullanım / DoS kolaylaştırma önleme
Cihaz parmak izitüretilmiş tanımlayıcıüçüncü tarafları toplu taramak için IP değiştiren tek bir aktörü tespit etme
Girilen hedef alan adı + zaman damgasıkayıt edilebilir alan adı + ISO zaman damgasıalan adı başına tekilleştirme, engelleme listesi eşleştirme, hız sayaçları
Taranan alan adı yüzey özeti (header, parmak izi, robots/sitemap — ziyaretçiyi değil herkese açık alan adını tanımlar)kısa ömürlü önbellek, en fazla 24 saat, sonra atılırtekilleştirme ve hız kontrolü; uzun süreli saklama yok

Hukuki dayanak

Hukuki dayanağımız meşru menfaattir (Md. 6(1)(f)) — talep edilen önizlemeyi sunmak ve özelliğin kötüye kullanılmasını önlemek; bunları Gerekçe 47 (dolandırıcılık önleme) ve Gerekçe 49 (ağ ve bilgi güvenliği) meşru menfaat olarak tanır. Belgelenmiş bir Meşru Menfaat Değerlendirmesi ve bir Veri Koruma Etki Değerlendirmesi dosyamızdadır ve dpo@assureport.com üzerinden talep üzerine paylaşılır.

Önizlenen bir alan adının sahibiyseniz

Taranan bir alan adının sahibi, sitesinin AssurePort üzerinden önizlenmesini istemiyorsa abuse@assureport.com adresine e-posta gönderin; alan adını önizleme özelliğinin engelleme listesine ekleriz. Ayrıca makine tarafından okunabilir bir vazgeçmeye saygı gösteririz: siteniz otomatik testlere izin verilmediğini belirten bir /.well-known/security.txt yayınlıyorsa, önizleme çalışmayı reddeder. Önizleme zaten devlet, askeri, eğitim, sağlık ve marka-korumalı platformları engeller (bkz. Hizmet Koşulları §20).

Haklarınız

Ziyaretçiler bu meşru menfaat temelli işlemeye istedikleri zaman itiraz edebilir (Md. 21) ve reddedilen bir önizleme için dpo@assureport.com üzerinden insan incelemesi talep edebilir. Taranan alan adı yüzey özeti, ziyaretçiyi değil herkese açık alan adını tanımlar ve yalnızca kısa ömürlü 24 saatlik bir önbellekte tutulur; tuttuğumuz tek ziyaretçi kişisel verisi, yukarıda açıklanan 12 aylık kötüye kullanım sinyalleridir.

Son güncelleme: 23 Haziran 2026 · Sürüm: 1.4 (§12 anonim yüzey önizleme taraması) · Ayrıca bkz.: Koşullar · DPA · Çerezler

Gültig ab: 11. August 2026 · Version: 1.5 · Verantwortlicher: AssurePort-Team · DSB-Kontakt: dpo@assureport.com

Sprache: Die englische Fassung ist die maßgebliche Rechtsfassung. Die Übersetzungen ins Türkische / Deutsche / Französische dienen Ihrer Bequemlichkeit; im Konfliktfall geht die englische Fassung vor.

§1 Wer wir sind und Anwendungsbereich

AssurePort ist eine KI-gestützte Penetrationstest-Plattform, betrieben vom AssurePort-Team mit Sitz in der Türkei. Für Daten, die wir über Besucher, Kontoinhaber und Rechnungsempfänger erheben, sind wir Verantwortlicher. Für Daten, die unsere Kunden während der Scans hochladen (Ziel-URLs, Beweisaufzeichnungen, Scan-Berichte), agieren wir als Auftragsverarbeiter gemäß Artikel 28 DSGVO — siehe unsere gesonderte Auftragsverarbeitungsvereinbarung.

Diese Erklärung gilt für assureport.com, app.assureport.com und alle von uns betriebenen Subdomains. Sie ist so abgefasst, dass sie die Artikel 12-14 DSGVO, die Transparenzpflichten des türkischen KVKK und die UK-GDPR-Pendants für Besucher aus Großbritannien erfüllt.

§2 Verarbeitete Daten

Wir minimieren. Wir erheben nur, was zur Leistungserbringung erforderlich ist.

KategorieBeispieleQuelle
KontoE-Mail-Adresse, gehashte Magic-Link-Tokens, Sitzungs-Cookie (aprt.session), 2FA-Geheimnis (gehasht)Sie, bei der Registrierung
Scan-MetadatenZiel-Hostname, Scan-Engine, Reservierungs-ID, Start-/End-Zeitstempel, Befundanzahl, Scan-Statuskundeninitiiert
AbrechnungPolar.sh-Kunden-ID, Rechnungs-ID, Tarif, Reservierungsbetrag pro Scan, Token-Saldo-Snapshot, Abrechnungsregister-Einträge, gezahlter Betrag, Währung. Wir sehen keine Kartennummern — Polar.sh ist Merchant of Record.Polar.sh-Webhook
Technische Telemetriepseudonymisierte IP (letztes Oktett gekürzt), gekürzter User-Agent, Anfragepfad, Antwortcode, Anfrage-IDCloudflare-Edge-Logs
Support-KorrespondenzE-Mail-Körper, Anhänge, TicketnummerSie, bei Kontaktaufnahme
Engine-Launch-Warteliste (v1.26.58, optional)Ihre E-Mail, die Engine, an der Sie interessiert sind (AD Security Assessment / SAP Pentest / Email Security), das Datum Ihrer Anmeldung, Ihre IP und Ihr Browser-User-Agent. Wird ausschließlich verwendet, um (a) Sie beim Start der Engine zu benachrichtigen und (b) einen einmaligen WAITLIST20-Promo-Code zu liefern, der 14 Tage nach dem Launch gültig ist. Gespeichert in Cloudflare D1 (EU-Region). Wird 90 Tage nach dem Engine-Launch gelöscht. Jederzeit über den Abmeldelink in unseren E-Mails oder per Anfrage an dpo@assureport.com abbestellbar.Sie, beim öffentlichen Warteformular
Newsletter „Feldnotizen" (2026-08-11, optional)E-Mail-Adresse, Anmeldequelle, Zeitpunkt der Einwilligung und ein Hash des Einwilligungstextes, gehashte Anmelde-IP (nie im Klartext), User-Agent. Rechtsgrundlage ist die Einwilligung (Art. 6 Abs. 1 lit. a), bestätigt im Double-Opt-in: Eine Adresse wird erst nach Klick auf den Bestätigungslink aufgenommen; unbestätigte Einträge werden nach 30 Tagen gelöscht. Jede E-Mail enthält einen Ein-Klick-Abmeldelink. Gespeichert in Cloudflare D1 (EU-Region). Widerruf jederzeit über den Abmeldelink oder dpo@assureport.com.Sie, über das Newsletter-Formular
Registrierungsprofil (v1.26.58, optional)Vorname, Nachname, Land, Stadt, Organisation — bei der Kontoerstellung erhoben, um Mehrfachkonten zu erkennen, Betrug abzuschrecken und Sie in Fragen der Kontointegrität kontaktieren zu können. Jedes Feld ist optional und kann leer bleiben; das Konto kann allein mit der E-Mail-Adresse erstellt werden.Sie, bei Anmeldung
Registrierungs-Netzwerk-Metadaten (v1.26.58, verpflichtend)IP-Adresse zum Zeitpunkt der Anmeldung, User-Agent-String, Cloudflare-Anfrage-Metadaten (CF-Ray, CF-IPCountry), akzeptierte Oberflächensprache. Automatisch erfasst, um die Annahme der Haftungserklärung einer überprüfbaren Sitzung zuzuordnen.Cloudflare Edge
Haftungserklärungs-Annahme (v1.26.58, verpflichtend)Hash des Erklärungstexts (SHA-256), Erklärungsversion (v1.0), Erklärungssprache (en/tr/de/fr), Annahme-Zeitstempel (ISO 8601), referenzierte AGB-Version (v1.2) und Abschnitte (§19, §20). Im nur-anhängenden Audit-Log als rechtlicher Nachweis der informierten Zustimmung gespeichert.Sie, bei Anmeldung

§3 Rechtsgrundlagen (Art. 6 DSGVO)

Wir verwenden keine automatisierte Entscheidungsfindung im Sinne des Artikels 22 DSGVO. Scan-KI-Agenten erzeugen Befunde, die der Kunde überprüft; die Token-Belastung bei Scan-Abschluss ist eine Buchhaltungsoperation, keine Entscheidung mit rechtlicher oder ähnlich erheblicher Wirkung gegenüber einer natürlichen Person.

Wir geben Kunden-Scandaten an keinen Dritten weiter, außer an die in §6 aufgeführten Unterauftragsverarbeiter. AssurePort bietet derzeit weder Webhooks, Integrationen Dritter, Single Sign-On (SAML/SCIM/OIDC) noch White-Label-/MSSP-Partnerprogramme an — siehe Nutzungsbedingungen §10 für die architektonische Verpflichtung.

§4 Aufbewahrungsfristen

WasWie langeWarum
Kontoprofil (E-Mail, gehashte Anmeldedaten)1 Jahr ab letzter Anmeldung, danach LöschungVertrag + Missbrauchsabwehr
Scan-Berichte und Beweise2 Jahre ab Scan-AbschlussKunden-Audit-Aufbewahrung
Hochgeladenes Rohmaterial (Scanner-Berichte Dritter, mobile App-Binärdateien)30 Tage für hochgeladene Scanner-Berichte, 60 Tage für App-Binärdateien, danach automatische Löschung. Der daraus erzeugte Bericht bleibt unberührt und unterliegt der 2-Jahres-Zeile oben.Datenminimierung — die Rohdatei wird nur während des Scans benötigt
Anonyme Oberflächen-Vorschau (Ergebnis, Ziel-URL, User-Agent)24 Stunden, danach wird der Inhalt gelöscht. Ein minimales Missbrauchsschutz-Gerüst (Vorschau-ID, Domain, gehashte IP, Zeitstempel, Einwilligungsnachweis) wird 12 Monate aufbewahrt und dann gelöscht.Ratenbegrenzung und Missbrauchsabwehr; Einwilligungsnachweis
Audit-Log (Anmeldungen, Scans, Einstellungsänderungen)7 Jahre. Das Audit-Log ist konstruktionsbedingt nur-anhängend — Einträge sind über eine HMAC-Hashkette verbunden, sodass weder wir noch ein Angreifer einen Eintrag ändern oder entfernen können, ohne die Kette zu brechen. Diese Manipulationssicherheit ist der Zweck des Logs, daher werden einzelne Einträge nie gelöscht; derselbe Datensatz enthält auch den oben beschriebenen Nachweis der Haftungserklärung und teilt diese Frist.manipulationssicherer Vorfallnachweis; DORA Art. 21 Nachweis operationeller Risiken; Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen (Art. 17(3)(e))
Abrechnungsregister (Token-Reservierungen, Belastungen, Freigaben, Zuteilungen)10 Jahretürkisches VUK / EU-USt.-Pflicht
Polar.sh-Rechnungen und Zahlungsereignisse10 JahreBuchhaltungs- / USt.-Pflicht
Support-E-Mail-Korrespondenz2 JahreKontinuität, Streitabwehr
Cloudflare-Edge-Logs (pseudonymisiert)rollierend 30 TageSicherheit + Verfügbarkeit
Registrierungsprofilfelder (Vorname, Nachname, Land, Stadt, Organisation)1 Jahr ab letzter Anmeldung, dann Löschung zusammen mit dem KontoKontointegrität / Erkennung von Mehrfachkonten
Registrierungs-Netzwerk-Metadaten (IP, User-Agent, Cloudflare CF-Ray / CF-IPCountry)7 Jahre ab AnmeldungDORA Art. 21 Betriebsrisikonachweis + Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen (Art. 17 Abs. 3 lit. e)
Haftungserklärungs-Annahmedatensatz (Hash, Version, Sprache, Zeitstempel, AGB-Verweis)7 Jahre ab AnmeldungVertragsnachweis für AGB §19 (Zusicherungen des Kunden) und §20 (Freistellung)
Anonyme Vorschau — Oberflächen-Zusammenfassung der gescannten Domain (Header, Fingerabdruck, robots/sitemap — beschreibt die öffentliche Domain, nicht den Besucher)bis zu 24 Stunden in einem kurzlebigen Cache, dann verworfenDeduplizierung & Ratensteuerung; keine langfristige Speicherung
Anonyme Vorschau — Missbrauchssignale des Besuchers (IP-Hash, Geräte-Fingerabdruck, eingegebene Domain, Zeitstempel, Ratenzähler)12 Monate ab Erstellung, danach LöschungMissbrauchs- / DoS-Erleichterungsprävention (Art. 6 Abs. 1 lit. f)

Bei Kontolöschung werden Scan-Berichte und Beweise binnen 30 Tagen gelöscht, ausgenommen Fälle, in denen das Gesetz eine längere Aufbewahrung verlangt (Abrechnungsregister, Polar.sh-Rechnungen, Registrierungs-Netzwerk-Metadaten und Haftungserklärungs-Annahmedatensatz).

§5 Ihre Rechte (Art. 15-22 DSGVO)

Senden Sie Auskunftsanfragen an dpo@assureport.com. Wir antworten binnen eines Monats (bei komplexen Anfragen mit Hinweis auf bis zu drei Monate verlängerbar).

§6 Unterauftragsverarbeiter

Die folgenden Unterauftragsverarbeiter verarbeiten Kundendaten in unserem Auftrag. Mit jedem schließen wir entsprechende Auftragsverarbeitungsverträge und verlangen gleichwertige DSGVO-Zusagen. Aktualisierungen dieser Liste werden mit mindestens 30 Tagen Vorankündigung veröffentlicht; Sie können einem neuen Unterauftragsverarbeiter widersprechen und, falls wir keine Lösung anbieten können, ohne Vertragsstrafe kündigen.

AnbieterZweckDatenebene
Cloudflare, Inc. (US-eingetragen)Edge Compute, DNS, DDoS, Workers KVEU-Datenebene, SCC (Modul 3)
Anthropic, PBC (USA)KI-Inferenz für Scan-AgentenSCC (Modul 3), Enterprise-Vertrag mit Null-Speicherung
Polar.sh (EU)Merchant of Record, Rechnungsstellung, USt.-Abführung, Token-Ökonomie-VerarbeiterEU (Niederlande)
Resend (EU)Transaktions-E-Mail-Versand (Magic-Links, Rechnungen)EU (Irland)
Fly.io, Inc. (USA)Sandbox-Runner für Scan-AusführungEU-Region (Frankfurt), SCC
Keine Integrationen, keine MSSP-Partner. AssurePort bietet derzeit weder Webhooks, Integrationen Dritter (Slack, Microsoft Teams, Jira, Linear, GitHub Issues, ZenDesk), Single Sign-On (SAML/SCIM/OIDC) noch White-Label-/MSSP-Partnerprogramme an. Dies ist eine bewusste Design-Entscheidung: Sie gewährleistet, dass Ihre Scan-Befunde, Ziel-Metadaten und Berichtsinhalte innerhalb der AssurePort-Plattformgrenzen verbleiben und an keinen Dritten über die oben gelisteten Unterauftragsverarbeiter hinaus fließen. Sollten wir künftig Integrationen einführen, werden wir diese als opt-in-Funktionen hinzufügen, die Zieladresse ggf. als Unterauftragsverarbeiter behandeln und aktive Konten mindestens 30 Tage vorher benachrichtigen.

§7 Internationale Übermittlungen

Kundendaten werden in EU-Regionen gespeichert. Soweit ein Unterauftragsverarbeiter außerhalb des EWR eingetragen ist (Cloudflare, Anthropic, Fly.io), erfolgen Übermittlungen auf der Grundlage der Standardvertragsklauseln (Durchführungsbeschluss (EU) 2021/914 der Kommission) zuzüglich ergänzender technischer Maßnahmen (Verschlüsselung bei der Übertragung und im Ruhezustand, EU-beschränkte Datenebenen). Eine Transfer-Folgenabschätzung liegt vor und wird auf Anfrage bereitgestellt.

§8 Kinder

AssurePort ist ein B2B-Sicherheitsdienst. Wir erheben wissentlich keine Daten von Personen unter 18 Jahren. Sollten Sie der Auffassung sein, dass ein Minderjähriger ein Konto erstellt hat, kontaktieren Sie dpo@assureport.com; wir löschen das Konto binnen 72 Stunden.

§9 Meldung von Verletzungen

Sofern eine Verletzung des Schutzes personenbezogener Daten voraussichtlich zu einem Risiko für die Rechte und Freiheiten natürlicher Personen führt, melden wir dies unserer federführenden Aufsichtsbehörde binnen 72 Stunden (Art. 33). Bei hohem Risiko werden Betroffene unverzüglich informiert (Art. 34). Die Meldung umfasst Art der Verletzung, Kategorien und ungefähre Anzahl betroffener Datensätze, DSB-Kontakt, voraussichtliche Folgen sowie ergriffene oder geplante Abhilfemaßnahmen.

§10 Kontakt und Änderungen

Für Datenschutzfragen: dpo@assureport.com. Für sonstige rechtliche Angelegenheiten: legal@assureport.com. Postadresse auf Anfrage.

Wir können diese Erklärung anlässlich der Weiterentwicklung des Dienstes anpassen. Wesentliche Änderungen werden aktiven Konten mindestens 30 Tage vor Wirksamwerden per E-Mail mitgeteilt. Das Datum „Gültig ab" oben auf dieser Seite spiegelt die jeweils aktuelle Version wider.

§11 Betrugsprävention & Missbrauch der kostenlosen Stufe

Stand 3. August 2026: der kostenlose vollständige Web-Penetrationstest wird nicht mehr angeboten. Die nachfolgend beschriebenen Missbrauchskontrollen gelten weiterhin, da diese Signale weiterhin bei der Anmeldung erhoben werden; zurückgezogen wurde nur die kostenlose Leistung, die sie geschützt haben.

Wir bieten einen kostenlosen vollständigen Web-Penetrationstest pro neuem Nutzer an. Um diese kostenlose Stufe nachhaltig zu halten und zu verhindern, dass eine Person zahlreiche Konten anlegt, verarbeiten wir Missbrauchssignale: einen gehashten Anmelde-IP-Wert (kein Klartext), einen Geräte-Fingerabdruck, die User-Agent-Zeichenfolge, die Zieldomain des Scans und einen gehashten, kanonisierten E-Mail-Wert, sowie eine Klassifizierung von Wegwerf-E-Mail-Adressen. Rechtsgrundlage ist das berechtigte Interesse (Art. 6 Abs. 1 lit. f, Erwägungsgrund 47 DSGVO); eine dokumentierte Interessenabwägung (LIA) liegt vor. Aufbewahrung: 12 Monate (getrennt von der 7-jährigen Haftungsverzichts-Aufbewahrung in §4). Die automatische Entscheidung beschränkt sich darauf, den kostenlosen Scan abzulehnen — sie löscht weder Ihr Konto noch entfaltet sie Rechtswirkung im Sinne von Art. 22 DSGVO. Sie haben das Widerspruchsrecht (Art. 21) und das Recht auf menschliche Überprüfung: dpo@assureport.com.

Hinweis: Die vollständige, maßgebliche Fassung dieses Abschnitts ist die englische Version (§11). Bei Abweichungen gilt der englische Wortlaut.

§12 Anonyme Oberflächen-Vorschau

Unsere Startseite bietet eine anonyme Oberflächen-Vorschau: Ohne Anmeldung kann ein Besucher eine Website-Adresse eingeben und eine schnelle, passive Sicherheits-Oberflächen-Zusammenfassung erhalten. Die Vorschau ist ausschließlich passive Aufklärung (HTTP-Header, oberflächliches Crawling, Technologie-Fingerabdruck und öffentlich veröffentlichte robots.txt / sitemap.xml / /.well-known/); sie sendet keine aktiven Payloads, führt keine Pfad-Enumeration durch und prüft keine Authentifizierung. Wir verarbeiten einen gehashten Wert der Besucher-IP (kein Klartext), einen Geräte-Fingerabdruck, die eingegebene Zieldomain und Zeitstempel zur Missbrauchsprävention. Rechtsgrundlage ist das berechtigte Interesse (Art. 6 Abs. 1 lit. f; Erwägungsgründe 47 und 49 DSGVO); eine dokumentierte Interessenabwägung (LIA) und eine Datenschutz-Folgenabschätzung (DSFA) liegen vor. Die Oberflächen-Zusammenfassung der gescannten Domain (sie beschreibt die öffentliche Domain, nicht den Besucher) wird nur in einem kurzlebigen Cache von bis zu 24 Stunden gehalten und dann verworfen; besucherseitige Missbrauchssignale werden 12 Monate aufbewahrt. Inhaber gescannter Domains können unter abuse@assureport.com eine Sperrung beantragen oder per /.well-known/security.txt widersprechen, was die Vorschau respektiert. Besucher haben das Widerspruchsrecht (Art. 21) und können eine menschliche Überprüfung anfordern: dpo@assureport.com.

Hinweis: Die vollständige, maßgebliche Fassung dieses Abschnitts ist die englische Version (§12). Bei Abweichungen gilt der englische Wortlaut.

Zuletzt aktualisiert: 23. Juni 2026 · Version: 1.4 (§12 anonyme Oberflächen-Vorschau) · Siehe auch: Bedingungen · AVV · Cookies

Date d'effet : 11 août 2026 · Version : 1.5 · Responsable de traitement : Équipe AssurePort · Contact DPO : dpo@assureport.com

Langue : La version anglaise fait foi sur le plan juridique. Les traductions en turc / allemand / français sont fournies pour votre commodité ; en cas de conflit, la version anglaise prévaut.

§1 Qui sommes-nous et champ d'application

AssurePort est une plateforme de tests d'intrusion alimentée par IA, exploitée par l'Équipe AssurePort, basée en Turquie. Nous sommes responsable de traitement pour les données collectées sur les visiteurs, titulaires de compte et contacts de facturation. Pour les données téléchargées par nos clients lors des scans (URL cibles, captures de preuves, rapports de scan), nous agissons en qualité de sous-traitant au sens de l'article 28 RGPD — voir notre Accord de Traitement des Données.

Cette politique couvre assureport.com, app.assureport.com et tous les sous-domaines que nous exploitons. Elle est rédigée pour satisfaire aux articles 12-14 RGPD, aux obligations de transparence de la KVKK turque et aux équivalents UK-GDPR pour les visiteurs depuis la Grande-Bretagne.

§2 Données traitées

Nous minimisons. Nous ne collectons que ce qui est nécessaire à la fourniture du service.

CatégorieExemplesSource
Compteadresse e-mail, jetons magic-link hachés, cookie de session (aprt.session), secret 2FA (haché)vous, à l'inscription
Métadonnées de scannom d'hôte cible, moteur de scan, identifiant de réservation, horodatages de début/fin, nombre de constatations, statut du scandéclenché par le client
Facturationidentifiant client Polar.sh, identifiant de facture, formule, montant de réservation par scan, instantané du solde de jetons, écritures du grand-livre de facturation, montant payé, devise. Nous ne voyons pas les numéros de carte — Polar.sh agit en tant que Merchant of Record.webhook Polar.sh
Télémétrie techniqueIP pseudonymisée (dernier octet tronqué), user agent tronqué, chemin de la requête, code de réponse, identifiant de requêtelogs edge Cloudflare
Correspondance supportcorps du courriel, pièces jointes, numéro de ticketvous, lors du contact
Liste d'attente de lancement des moteurs (v1.26.58, facultatif)votre e-mail, le moteur qui vous intéresse (AD Security Assessment / SAP Pentest / Email Security), la date d'inscription, votre IP et le User-Agent de votre navigateur. Utilisé uniquement pour (a) vous notifier au lancement du moteur et (b) délivrer un code promo unique WAITLIST20 valable 14 jours après le lancement. Stocké dans Cloudflare D1 (région UE). Supprimé 90 jours après le lancement du moteur. Désinscription possible à tout moment via le lien dans nos e-mails ou en écrivant à dpo@assureport.com.vous, sur formulaire public
Newsletter « notes de terrain » (2026-08-11, facultatif)adresse e-mail, source d'inscription, horodatage du consentement et empreinte (hachage) du texte de consentement, hachage de l'IP d'inscription (jamais en clair), User-Agent. La base légale est le consentement (art. 6, §1, a), confirmé par double opt-in : une adresse n'est ajoutée qu'après clic sur le lien de confirmation ; les inscriptions non confirmées sont supprimées après 30 jours. Chaque e-mail comporte un lien de désabonnement en un clic. Stocké dans Cloudflare D1 (région UE). Retrait du consentement à tout moment via ce lien ou en écrivant à dpo@assureport.com.vous, via le formulaire newsletter
Profil d'inscription (v1.26.58, facultatif)prénom, nom, pays, ville, organisation — collectés lors de la création du compte afin de détecter les comptes en double, dissuader la fraude et vous contacter pour des questions d'intégrité du compte. Chaque champ est facultatif et peut être laissé vide ; le compte peut être créé avec la seule adresse e-mail.vous, à l'inscription
Métadonnées réseau d'inscription (v1.26.58, obligatoire)adresse IP au moment de l'inscription, chaîne user-agent, métadonnées de requête Cloudflare (CF-Ray, CF-IPCountry), langue d'interface acceptée. Capturées automatiquement pour rattacher l'acceptation de la décharge de responsabilité à une session vérifiable.Cloudflare Edge
Acceptation de la décharge de responsabilité (v1.26.58, obligatoire)hash du texte de la décharge (SHA-256), version de la décharge (v1.0), langue de la décharge (en/tr/de/fr), horodatage d'acceptation (ISO 8601), version des CGU référencée (v1.2) et sections (§19, §20). Conservée dans le journal d'audit en mode ajout uniquement comme preuve juridique d'acceptation éclairée.vous, à l'inscription

§3 Bases légales (RGPD Art. 6)

Nous n'employons aucune décision automatisée au sens de l'article 22 RGPD. Les agents IA de scan produisent des constatations que le client examine ; la facturation des jetons à l'achèvement du scan est une opération comptable, et non une décision produisant des effets juridiques ou significatifs sur une personne physique.

Nous ne partageons pas les données de scan client avec un tiers, hors la liste des sous-traitants ultérieurs au §6. AssurePort n'expose actuellement pas de webhooks, d'intégrations tierces, d'authentification unique (SAML/SCIM/OIDC) ni de programme de partenariat en marque blanche / MSSP — voir nos Conditions §10 pour l'engagement architectural.

§4 Calendrier de conservation

QuoiDuréePourquoi
Profil de compte (e-mail, identifiants hachés)1 an depuis la dernière connexion, puis suppressioncontrat + défense contre les abus
Rapports de scan et preuves2 ans à compter de l'achèvement du scanconservation d'audit client
Matériel brut téléversé (rapports de scanners tiers, binaires d'applications mobiles)30 jours pour les rapports de scanners téléversés, 60 jours pour les binaires d'applications, puis suppression automatique. Le rapport que nous en produisons n'est pas concerné et relève de la ligne « 2 ans » ci-dessus.minimisation des données — le fichier brut n'est nécessaire que pendant le scan
Aperçu de surface anonyme (résultat, URL cible, user-agent)24 heures, puis le contenu est effacé. Un squelette minimal anti-abus (identifiant d'aperçu, domaine, IP hachée, horodatages, preuve de consentement) est conservé 12 mois, puis supprimé.limitation de débit et défense anti-abus ; preuve de consentement
Journal d'audit (connexions, scans, modifications de paramètres)7 ans. Le journal d'audit est en ajout seul par conception — les entrées sont chaînées par un hachage HMAC, de sorte que ni nous ni un intrus ne pouvons modifier ou supprimer une entrée sans rompre la chaîne. Cette inviolabilité est la raison d'être du journal : les entrées individuelles ne sont donc jamais supprimées ; le même enregistrement porte également la preuve d'acceptation de la clause de non-responsabilité décrite ci-dessus et partage cette durée.enregistrement d'incident inviolable ; preuve de risque opérationnel DORA art. 21 ; constatation, exercice ou défense de droits en justice (art. 17(3)(e))
Grand-livre de facturation (réservations de jetons, prélèvements, libérations, attributions)10 ansobligation VUK turc / TVA UE
Factures Polar.sh et événements de paiement10 ansobligation comptable / TVA
Correspondance e-mail support2 anscontinuité, défense en cas de litige
Logs edge Cloudflare (pseudonymisés)30 jours glissantssécurité + disponibilité
Champs du profil d'inscription (prénom, nom, pays, ville, organisation)1 an à compter de la dernière connexion, puis suppression avec le compteintégrité du compte / détection des comptes en double
Métadonnées réseau d'inscription (IP, user-agent, Cloudflare CF-Ray / CF-IPCountry)7 ans à compter de l'inscriptionpreuve du risque opérationnel DORA Art. 21 + constatation, exercice ou défense de droits en justice (Art. 17.3.e)
Enregistrement d'acceptation de la décharge de responsabilité (hash, version, langue, horodatage, référence des CGU)7 ans à compter de l'inscriptionpreuve contractuelle pour les §19 (Déclarations et garanties du client) et §20 (Indemnisation) des CGU
Aperçu anonyme — résumé de surface du domaine scanné (en-têtes, empreinte, résumé robots/sitemap — décrit le domaine public, non le visiteur)jusqu'à 24 heures dans un cache de courte durée, puis supprimédéduplication & contrôle de débit ; aucune conservation à long terme
Aperçu anonyme — signaux d'abus du visiteur (hachage à clé de l'IP, empreinte d'appareil, domaine saisi, horodatage, compteurs de débit)12 mois à compter de la création, puis suppressionprévention de l'abus / de la facilitation de DoS (Art. 6.1.f)

À la suppression du compte, les rapports de scan et les preuves sont purgés sous 30 jours, sauf si la loi exige une conservation plus longue (grand-livre de facturation, factures Polar.sh, métadonnées réseau d'inscription et enregistrement d'acceptation de la décharge de responsabilité).

§5 Vos droits (RGPD Art. 15-22)

Adressez vos demandes à dpo@assureport.com. Nous répondons sous un mois (extensible à trois mois pour les demandes complexes, avec notification).

§6 Sous-traitants ultérieurs

Les sous-traitants ultérieurs ci-après traitent les données client pour notre compte. Nous signons avec chacun les conditions de traitement appropriées et exigeons des engagements équivalents au RGPD. Les mises à jour de cette liste sont publiées avec un préavis minimum de 30 jours ; vous pouvez vous opposer à un nouveau sous-traitant et, si nous ne pouvons accommoder, résilier sans pénalité.

PrestataireFinalitéPlan de données
Cloudflare, Inc. (constituée aux États-Unis)Edge compute, DNS, DDoS, Workers KVplan de données UE, CSC (Module 3)
Anthropic, PBC (États-Unis)Inférence IA pour agents de scanCSC (Module 3), contrat entreprise zéro rétention
Polar.sh (UE)Merchant of Record, émission de factures, reversement de TVA, processeur d'économie de jetonsUE (Pays-Bas)
Resend (UE)Envoi d'e-mails transactionnels (magic-links, factures)UE (Irlande)
Fly.io, Inc. (États-Unis)Runners sandbox pour l'exécution des scansrégion UE (Francfort), CSC
Aucune intégration, aucun partenaire MSSP. AssurePort n'expose actuellement pas de webhooks, d'intégrations tierces (Slack, Microsoft Teams, Jira, Linear, GitHub Issues, ZenDesk), d'authentification unique (SAML/SCIM/OIDC) ni de programme de partenariat en marque blanche / MSSP. Il s'agit d'un choix de conception délibéré : il garantit que vos constatations de scan, métadonnées de cible et contenus de rapport restent dans le périmètre de la plateforme AssurePort et ne sont pas transmis à un tiers au-delà des sous-traitants ultérieurs ci-dessus. Si nous introduisons des intégrations à l'avenir, nous les ajouterons en opt-in, traiterons la destination comme un sous-traitant ultérieur le cas échéant et notifierons les comptes actifs au moins 30 jours à l'avance.

§7 Transferts internationaux

Les données client sont stockées dans des régions UE. Lorsqu'un sous-traitant ultérieur est constitué hors EEE (Cloudflare, Anthropic, Fly.io), les transferts sont régis par les Clauses Contractuelles Types (Décision d'Exécution (UE) 2021/914 de la Commission) assorties de mesures techniques complémentaires (chiffrement en transit et au repos, plans de données restreints à l'UE). Une évaluation d'impact de transfert est tenue et disponible sur demande.

§8 Enfants

AssurePort est un service de sécurité B2B. Nous ne collectons pas sciemment de données auprès de personnes de moins de 18 ans. Si vous estimez qu'un mineur a créé un compte, contactez dpo@assureport.com ; nous supprimerons le compte sous 72 heures.

§9 Notification de violation

Lorsqu'une violation de données à caractère personnel est susceptible d'engendrer un risque pour les droits et libertés des personnes physiques, nous notifions notre autorité de contrôle chef de file sous 72 heures (Art. 33). Les personnes concernées sont informées sans délai indu en cas de risque élevé (Art. 34). La notification indique la nature de la violation, les catégories et le nombre approximatif d'enregistrements affectés, le contact DPO, les conséquences probables et les mesures prises ou proposées.

§10 Contact et modifications

Pour les questions de confidentialité : dpo@assureport.com. Pour les autres questions juridiques : legal@assureport.com. Adresse postale sur demande.

Nous pouvons réviser cette politique au fil de l'évolution du service. Les modifications matérielles sont notifiées par e-mail aux comptes actifs au moins 30 jours avant leur entrée en vigueur. La date d'effet en haut de cette page reflète la version courante.

§11 Prévention de la fraude et abus de l'offre gratuite

Mise à jour du 3 août 2026 : le test d'intrusion web complet gratuit n'est plus proposé. Les traitements anti-abus décrits ci-dessous restent en vigueur, car ces signaux sont toujours collectés à l'inscription ; seule l'offre gratuite qu'ils protégeaient a été retirée.

Nous offrons un test d'intrusion web complet gratuit par nouvel utilisateur. Pour préserver la viabilité de cette offre gratuite et empêcher une même personne de créer de nombreux comptes, nous traitons des signaux anti-abus : une empreinte hachée de l'adresse IP d'inscription (jamais en clair), une empreinte d'appareil, la chaîne User-Agent, le domaine cible du scan et un hachage canonisé de l'e-mail, ainsi qu'une classification des adresses e-mail jetables. La base légale est l'intérêt légitime (art. 6, §1, f ; considérant 47 du RGPD) ; une analyse d'intérêt légitime (LIA) documentée est disponible. Conservation : 12 mois (distincte de la conservation de 7 ans de la renonciation de responsabilité au §4). La décision automatisée se limite à refuser le scan gratuit — elle ne supprime pas votre compte et ne produit pas d'effet juridique au sens de l'art. 22 du RGPD. Vous disposez du droit d'opposition (art. 21) et d'un réexamen humain : dpo@assureport.com.

Remarque : la version intégrale et faisant foi de cette section est la version anglaise (§11). En cas de divergence, le texte anglais prévaut.

§12 Aperçu de surface anonyme

Notre page d'accueil propose un aperçu de surface anonyme : sans connexion, un visiteur peut saisir une adresse de site web et recevoir un résumé de surface de sécurité rapide et passif. L'aperçu est une reconnaissance passive uniquement (en-têtes HTTP, exploration superficielle, empreinte technologique et fichiers publics robots.txt / sitemap.xml / /.well-known/) ; il n'envoie aucune charge utile active, n'effectue aucune énumération de chemins et ne teste pas l'authentification. Nous traitons un hachage à clé de l'IP du visiteur (jamais en clair), une empreinte d'appareil, le domaine cible saisi et des horodatages à des fins de prévention des abus. La base légale est l'intérêt légitime (Art. 6.1.f ; considérants 47 et 49 du RGPD) ; une analyse d'intérêt légitime (LIA) documentée et une analyse d'impact relative à la protection des données (AIPD) sont disponibles. Le résumé de surface du domaine scanné (il décrit le domaine public, non le visiteur) n'est conservé que dans un cache de courte durée pouvant aller jusqu'à 24 heures, puis supprimé ; les signaux anti-abus côté visiteur sont conservés 12 mois. Les propriétaires de domaines scannés peuvent demander une mise en liste de blocage à abuse@assureport.com ou s'y opposer via /.well-known/security.txt, ce que l'aperçu respecte. Les visiteurs disposent du droit d'opposition (Art. 21) et peuvent demander un réexamen humain : dpo@assureport.com.

Remarque : la version intégrale et faisant foi de cette section est la version anglaise (§12). En cas de divergence, le texte anglais prévaut.

Dernière mise à jour : 23 juin 2026 · Version : 1.4 (§12 aperçu de surface anonyme) · Voir aussi : Conditions · DPA · Cookies