EFFECTIVE DATE: June 30, 2026
View an older version of this Privacy Notice
ArmorCode Inc. (“ArmorCode”, “we”, “our”, or “us”) provides an Unified Exposure Management Platform that helps security teams unify, prioritize, and remediate vulnerabilities across infrastructure, cloud, containers, and applications. Triage findings based on actual risk to business, and automate remediation workflows to address vulnerabilities faster than ever before.
ArmorCode platform and related SaaS offerings, along with our public website www.armorcode.com (collectively, the “Services”).
We are committed to protecting your privacy and handling personal information responsibly. This Privacy Policy describes what data we collect, how we use it, and the choices available to you.
1. Who We Are and Scope of This Notice
ArmorCode Inc. is the controller of personal data processed in connection with the Services, except where we process personal data on behalf of our customers as a processor (for example, when our customers use the Services to manage application security and vulnerability findings relating to their own personnel or systems). Where we act as a processor, the entity that determines the purposes and means of processing (typically our customer) is the controller, and data subjects should direct their requests to that entity in the first instance; we will support our customers in responding to such requests in accordance with our contractual obligations.
This Notice applies to:
- Visitors to our public website www.armorcode.com
- Authorized users of the ArmorCode SaaS platform;
- Individuals who communicate with us via email, events, webinars, or marketing channels; and
- Prospective, current, and former customers’ authorized personnel who interact with the Services.
Note on customer data: ArmorCode does not collect, process, or store any personal data belonging to our customers’ end clients. Our platform processes only metadata and vulnerability findings as directed by our customers, which does not include personally identifiable information.
2. Categories of Personal Data We Collect
We collect only limited personal data necessary to provide, secure, and improve the Services:
a. Information You Provide Directly
- Identity and contact data: name and email address, used for identification, authentication, and communication;
- Professional data: company name and role/title, used for business context;
- Other information you voluntarily provide: for example, content of support requests, demo requests, or event registrations.
b. Information Collected Automatically
- IP address and device identifiers;
- Browser type and operating system;
- Activity logs and diagnostic data related to authentication, API calls, and security events.
This data is collected to maintain platform security, ensure service reliability, and detect misuse or fraud.
c. Special Category (Sensitive) Data
We do not knowingly collect or process special categories of personal data within the meaning of Article 9 GDPR (e.g., racial or ethnic origin, religious or philosophical beliefs, health data, genetic or biometric data, or data concerning sexual orientation), nor do we collect government identifiers, financial account details, or payment card data. Our systems are not designed to process such data, and customers should not upload or transmit it via the Services.
3. Lawful Bases for Processing (Article 6 GDPR)
We will only process your personal data where we have a valid lawful basis to do so. Depending on the context, we rely on the following lawful bases:
- Performance of a contract (Art. 6(1)(b)) – to provide, deliver, and manage your use of the Services, including account creation and authentication;
- Legitimate interests (Art. 6(1)(f)) – to secure, operate, and improve the Services, prevent fraud and abuse, and conduct internal analytics, provided such interests are not overridden by your rights and freedoms;
- Consent (Art. 6(1)(a)) – where you have given explicit consent, such as for non-essential cookies or marketing communications, which you may withdraw at any time; and
- Legal obligation (Art. 6(1)(c)) – to comply with applicable laws, regulations, or lawful requests from competent authorities.
We will not process your personal data for materially different, unrelated, or incompatible purposes without providing you notice and, where required, obtaining your consent.
4. Purposes of Processing
We use personal data for the following purposes:
- Operating, maintaining, and improving the Services;
- Authenticating users and managing access to the platform;
- Responding to inquiries, support requests, or feedback;
- Sending transactional or service-related communications;
- Analyzing usage trends to improve user experience;
- Detecting, investigating, and preventing fraudulent or unauthorized activity;
- Complying with legal obligations and enforcing our agreements.
We do not sell, rent, or share your personal data with third parties for their own direct marketing purposes.
5. How We Disclose Personal Data
- Processors / sub-processors – trusted vendors who help us operate the platform (e.g., cloud hosting, analytics, bug reporting and email delivery providers), bound by data processing agreements incorporating GDPR-compliant confidentiality and security obligations;
- Legal and regulatory authorities – where required by law, court order, or to protect our rights, property, or the rights of others;
- Business transfer recipients – in connection with a merger, acquisition, or sale of assets, with notice provided as required by law; and
- Marketing partners – limited business contact details of website visitors may be shared with trusted partners to co-host events or campaigns for legitimate B2B marketing purposes, consistent with applicable law.
An up-to-date list of sub-processors is available on request by emailing security@armorcode.io.
6. International Data Transfers
We operate globally and may process personal data in the United States and other jurisdictions outside the EEA, UK, and Switzerland. Where personal data is transferred from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards recognized under Chapter V of the GDPR, including:
- The European Commission’s Standard Contractual Clauses (SCCs);
- The UK International Data Transfer Addendum to the SCCs; and
- Other legally recognized transfer mechanisms, including adequacy decisions, where applicable.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Notice, including to maintain and improve the Services, comply with legal obligations, and resolve disputes or enforce agreements. Basic account and contact data are generally retained for as long as your account is active and deleted within 180 days of account closure, unless a longer period is required for security, audit, or legal purposes. When determining retention periods, we consider the amount, nature, and sensitivity of the data, the purpose of processing, and applicable legal requirements.
8. Data Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit and at rest, role-based access controls, network and infrastructure monitoring, and regular vulnerability assessments and penetration testing. No method of transmission over the internet is completely secure, and we encourage you to use strong credentials and to promptly report any suspected security incident to security@armorcode.io
9. Your Rights as an EU, UK, or Swiss Data Subject
If you are located in the EU, EEA, UK, Switzerland, Liechtenstein, Norway, or Iceland, you have the following rights with respect to your personal data under the GDPR. To exercise any of these rights, please submit a request to privacy@armorcode.io. In some circumstances we may not be able to fully comply with your request – for example, if it is manifestly unfounded or excessive, if it jeopardizes the rights of others, or if it is not required by law – in which case we will notify you of our decision. We may need to request additional information, which may include personal data, to verify your identity before responding.
- Right of Access: Request confirmation of whether we process your personal data and receive a copy of that data, including processing purposes, data categories, and recipients.
- Right to Rectification: Request the correction or supplementation of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): Request the deletion of your personal data, subject to legal exceptions.
- Right to Restriction of Processing: Request that we restrict the processing of your personal data under certain conditions.
- Right to Object: Object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Data Portability: Request a copy of your personal data in a structured, commonly used, machine-readable format, or its transfer to another controller.
- Right to Withdraw Consent: Withdraw your consent at any time for data processed on that legal basis.
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority regarding our data processing practices
Please note that we may process personal data of our customers’ platform users or employees in connection with our provision of services to those customers, in which case we act as a processor rather than a controller. If we are processing your personal data as a processor, you should direct your request to the controller (i.e., the entity that collected your data) in the first instance.
10. Children’s Privacy
The Services are not directed to, and we do not knowingly collect personal data from, individuals under the age of 16. If we become aware that we have collected personal data from a child without appropriate parental or guardian consent, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@armorcode.io.
11. Cookies and Similar Technologies
We use cookies and similar technologies for essential functionality, analytics, and performance monitoring. Non-essential cookies, including analytics cookies such as those used by Google Analytics, are only placed with your consent, which you may withdraw at any time through our cookie settings or your browser controls. Essential cookies necessary for the operation of the Services cannot be disabled.
12. Artificial Intelligence
13. Changes to This Notice
We may update this Notice from time to time to reflect changes in our practices, technologies, or applicable law. Material changes will be indicated by updating the Effective Date above, and, where required, we will provide additional notice via the Services or by email.
14. Additional Disclosures for California Residents (CCPA/CPRA)
This section supplements this Notice for California residents under the CCPA/CPRA. Where it conflicts with another part of this Notice, the more protective provision controls.
Collection and Disclosure
Your Rights
- Know/Access, Delete, Correct: request the categories/specifics of data we hold, its sources and recipients; request deletion or correction, subject to legal exceptions.
- Opt-Out of Sale/Sharing & Limit Sensitive PI Use: not currently applicable, as we do not sell/share personal information or collect sensitive personal information.
- Non-Discrimination: we will not penalize you for exercising any CCPA right.
Authorized Agents, Verification & Do Not Track
You may use an authorized agent with written permission; we may still verify your identity directly..
Exercising Your Rights
Email privacy@armorcode.io with subject “CCPA Request.” We will respond within 45 days, extendable by 45 days with notice.
15. Contact Us
If you have any questions, concerns, or requests regarding this Notice or our processing of your personal data, please contact us at:
Email: privacy@armorcode.io
Subject line: “GDPR Data Subject Request”
We will work to respond to your request within one month, as required under Article 12(3 ) GDPR, which may be extended by a further two months for complex or numerous requests, in which case we will inform you of the extension and the reasons for the delay within the first month.