Hudson InfoSec ("Company," "we," "us," or "our") operates the hudsoninfosec.com website, our mobile applications (including the Hudson Infosec iOS app), and the Ayewo and HSEC Sentinel platforms (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect information obtained from users of our Services.
By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our Services.
We may receive information from payment processors, identity verification services, or business partners in connection with your use of our Services.
Our mobile applications (including the Hudson Infosec iOS app) collect the information described above to provide the Services, and in particular:
We use all information collected through or submitted to our Services for the following purposes:
Hudson InfoSec develops machine learning models for security analysis. This section states precisely what we do and do not use for that purpose.
Where the Services are deployed on hardware you own and control — including Ayewo nodes and the HSEC On Prem analyzer — scan data, vulnerability findings, network information and generated reports are processed and stored solely on that hardware. They are not transmitted to Hudson InfoSec. Because we never receive this data, it is not used to train, fine-tune or evaluate any model.
We do not use any of the following to train, fine-tune or evaluate any machine learning model or artificial intelligence system:
Our scanning nodes are provisioned without customer identity: a node does not know, and does not record, which organization owns it. Raw scan output is therefore not attributable to a customer at the point it is generated.
Where such data is held on Hudson InfoSec infrastructure, we may use de-identified technical security indicators derived from it to improve detection accuracy and analytical quality. Before any such use, we:
“De-identified technical security data” means information such as vulnerability patterns, service and version fingerprints, misconfiguration classes and detection outcomes. It does not include the content, topology or identity of any customer environment.
The primary training corpora for our security models are public and synthetic: published vulnerability data (including the National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog), public exploit and advisory sources, MITRE ATT&CK, public regulatory and framework text, and test cases we construct ourselves.
All inference performed on customer data runs on hardware operated by you or by us. We do not transmit customer data to any third-party artificial intelligence, model or inference provider.
Where your agreement with us, or a regulatory regime applicable to you, restricts or prohibits any use of your data for model development, those terms govern and override this section. You may also direct us in writing not to use de-identified data derived from your environment for model development, and we will honor that direction.
We may use your information for:
We do not sell your personal information. We may share information in the following circumstances:
We retain your information for as long as your account is active or as needed to provide our Services. We may also retain information as necessary to comply with legal obligations, resolve disputes, and enforce agreements.
For Services deployed on hardware you own and control, retention of scan data, findings and reports is determined entirely by you. We hold no copy and set no retention period for that data.
When data is no longer required for any of the purposes described in this Privacy Policy, we will delete or de-identify it in accordance with our data retention procedures.
We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, access controls, regular security assessments, and infrastructure monitoring.
However, no method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee its absolute security.
Depending on your jurisdiction, you may have the following rights:
To exercise any of these rights, contact us at privacy@hudsoninfosec.com. We will respond within 30 days of receiving your request.
Note: Exercising certain rights (such as deletion) may limit your ability to use our Services. Deletion requests apply to the personal and customer information we hold about you. They do not extend to de-identified technical security data as described in Section 2.2.3, which carries no association with you or your organization and therefore cannot be located or removed on an individual basis. In addition, data that has already been incorporated into a trained model, an aggregated dataset, or a de-identified analytical output cannot be withdrawn or deleted, because such incorporation is irreversible.
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.
Our Services are operated from the United States. If you access our Services from outside the United States, your information will be transferred to and processed in the United States. By using our Services, you consent to this transfer and processing.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of our Services after any changes constitutes acceptance of the revised Privacy Policy.
We encourage you to review this Privacy Policy periodically.
If you have questions or concerns about this Privacy Policy, please contact us:
Hudson InfoSec
Hudson Valley, New York, U.S.A.
Email: privacy@hudsoninfosec.com
Website: hudsoninfosec.com