Legal

Privacy Policy

Effective Date: February 28, 2026 · Last Updated: September 21, 2026

Hudson InfoSec ("Company," "we," "us," or "our") operates the hudsoninfosec.com website, our mobile applications (including the Hudson Infosec iOS app), and the Ayewo and HSEC Sentinel platforms (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect information obtained from users of our Services.

By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our Services.

1. Information We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

1.3 Information from Third Parties

We may receive information from payment processors, identity verification services, or business partners in connection with your use of our Services.

1.4 Mobile Applications

Our mobile applications (including the Hudson Infosec iOS app) collect the information described above to provide the Services, and in particular:

2. How We Use Your Information

We use all information collected through or submitted to our Services for the following purposes:

2.1 Service Delivery and Operations

2.2 Model Training and Product Improvement

Hudson InfoSec develops machine learning models for security analysis. This section states precisely what we do and do not use for that purpose.

2.2.1 On-premises deployments — your data is never used for model development, because we never receive it

Where the Services are deployed on hardware you own and control — including Ayewo nodes and the HSEC On Prem analyzer — scan data, vulnerability findings, network information and generated reports are processed and stored solely on that hardware. They are not transmitted to Hudson InfoSec. Because we never receive this data, it is not used to train, fine-tune or evaluate any model.

2.2.2 We do not train models on data that identifies you

We do not use any of the following to train, fine-tune or evaluate any machine learning model or artificial intelligence system:

2.2.3 We may use de-identified technical security data

Our scanning nodes are provisioned without customer identity: a node does not know, and does not record, which organization owns it. Raw scan output is therefore not attributable to a customer at the point it is generated.

Where such data is held on Hudson InfoSec infrastructure, we may use de-identified technical security indicators derived from it to improve detection accuracy and analytical quality. Before any such use, we:

“De-identified technical security data” means information such as vulnerability patterns, service and version fingerprints, misconfiguration classes and detection outcomes. It does not include the content, topology or identity of any customer environment.

2.2.4 Our models are trained principally on public and synthetic data

The primary training corpora for our security models are public and synthetic: published vulnerability data (including the National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog), public exploit and advisory sources, MITRE ATT&CK, public regulatory and framework text, and test cases we construct ourselves.

2.2.5 We do not send your data to third-party AI services

All inference performed on customer data runs on hardware operated by you or by us. We do not transmit customer data to any third-party artificial intelligence, model or inference provider.

2.2.6 Your agreement and your election prevail

Where your agreement with us, or a regulatory regime applicable to you, restricts or prohibits any use of your data for model development, those terms govern and override this section. You may also direct us in writing not to use de-identified data derived from your environment for model development, and we will honor that direction.

2.3 Internal Business Operations

We may use your information for:

2.4 Legal and Compliance

2.5 Communications

3. Data Sharing and Disclosure

We do not sell your personal information. We may share information in the following circumstances:

4. Data Retention

We retain your information for as long as your account is active or as needed to provide our Services. We may also retain information as necessary to comply with legal obligations, resolve disputes, and enforce agreements.

For Services deployed on hardware you own and control, retention of scan data, findings and reports is determined entirely by you. We hold no copy and set no retention period for that data.

When data is no longer required for any of the purposes described in this Privacy Policy, we will delete or de-identify it in accordance with our data retention procedures.

5. Data Security

We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, access controls, regular security assessments, and infrastructure monitoring.

However, no method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee its absolute security.

6. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

To exercise any of these rights, contact us at privacy@hudsoninfosec.com. We will respond within 30 days of receiving your request.

Note: Exercising certain rights (such as deletion) may limit your ability to use our Services. Deletion requests apply to the personal and customer information we hold about you. They do not extend to de-identified technical security data as described in Section 2.2.3, which carries no association with you or your organization and therefore cannot be located or removed on an individual basis. In addition, data that has already been incorporated into a trained model, an aggregated dataset, or a de-identified analytical output cannot be withdrawn or deleted, because such incorporation is irreversible.

7. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.

8. Third-Party Links

Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.

9. International Users

Our Services are operated from the United States. If you access our Services from outside the United States, your information will be transferred to and processed in the United States. By using our Services, you consent to this transfer and processing.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of our Services after any changes constitutes acceptance of the revised Privacy Policy.

We encourage you to review this Privacy Policy periodically.

11. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Hudson InfoSec

Hudson Valley, New York, U.S.A.

Email: privacy@hudsoninfosec.com

Website: hudsoninfosec.com