PREVIEWCISO360AI is offered as-is while in preview. Features and data may change. Learn more.

Privacy Policy

Last updated: 2026-09-30 — Version: 2026-09-30

1. Who we are

The CISO360AI service (the "Service") is operated by alterSec Limited (NZBN 9429047827035), trading as CISO360AI, a company incorporated in New Zealand. For the purposes of applicable data-protection law we are the controller of personal data we collect about account holders and website visitors, and the processor of data you upload into the Service. Our Privacy Officer can be reached at privacy@ciso360.ai.

2. What we collect

  • Account data: name, corporate email address, organisation name, password (hashed and stored by our identity provider), preferred language, and authentication tokens.
  • Service data: organisations, projects, assets, scan targets, vulnerabilities, findings, controls, evidence, AI-assisted outputs, and any other content you create or upload while using the Service.
  • Usage and diagnostic data: IP address, browser and device information, referring URL, pages and features used, error reports, and audit trails of significant actions.
  • Session recordings: a reconstruction of what was shown on screen and how pages were used (clicks, scrolling, navigation), recorded in the Service and, only with your consent, on our websites. Typed values are masked and secrets such as API keys are excluded.
  • AI Sidekick interactions: prompts and responses, kept so we can operate and troubleshoot the assistant, including copies held by our analytics and diagnostics provider (see §5).
  • Cookies and browser storage: see §9.

The Service is not intended for health information, other sensitive personal information or payment-card data, and customers must not store it there (see our Terms of Service, clause 6A).

3. Why we collect it

We process personal data to:

  • provide, operate, maintain, and improve the Service;
  • authenticate users and protect accounts;
  • provide customer support, including reviewing session recordings of a problem you report;
  • monitor for abuse, fraud, and security incidents;
  • understand how our website and the Service are used, in aggregate;
  • meet legal, regulatory, and audit obligations;
  • process payments for paid plans.

4. Legal basis

We handle personal information under the New Zealand Privacy Act 2020: we collect it only for the lawful purposes in §3 and only as much as they need (IPP 1), we tell you about it in this policy (IPP 3), and we use and disclose it only for those purposes or directly related ones, or as the Act otherwise allows (IPPs 10 and 11). Where the Australian Privacy Act 1988 applies to an Australian customer, we handle its information consistently with the Australian Privacy Principles.

We have also aligned our practices with the GDPR, so each use of personal information rests on one of these grounds:

  • performance of our contract with you or your organisation, for account and Service data;
  • our legitimate interests in running a secure and reliable service, for security monitoring, abuse prevention, and the analytics, error diagnostics and session recording inside the Service. You can object to this processing at any time (see §8);
  • your consent, for optional analytics and session recording on our websites and for marketing communications. You can withdraw consent at any time using the "Cookie settings" link in the footer of each website;
  • compliance with legal obligations.

Where the Service is offered is set out in our Terms of Service (clause 3A). Where the GDPR or UK GDPR applies to your information — for example, when you visit our websites from the European Economic Area or the United Kingdom — these grounds are our lawful bases under Article 6.

5. Sub-processors and sharing

We rely on a small number of trusted sub-processors to deliver the Service. Our principal providers are:

  • Amazon Web Services — cloud hosting and storage (Australia, Sydney region), and the AI models behind the AI Sidekick, which may process requests in other AWS regions;
  • Vercel — hosting, content delivery and edge security for our websites and the Service's web interface (global edge network);
  • PostHog — product analytics, session recording, error diagnostics and monitoring of AI Sidekick requests, including their prompts and responses (United States);
  • GitHub — source-code hosting and delivery of our software (United States). It does not hold the content of your workspace.
  • Cloudflare — network edge protection for our API and sign-in services, and routing of email sent to our addresses (global edge network);
  • Resend — delivery of verification, notification and other service emails (United States);
  • Stripe — payment processing for paid plans. We do not see or store your full card details;
  • Microsoft — our internal collaboration tools, where in-app feedback and support requests are received and handled (Australia).

Identity and authentication, our database and our job scheduling run on our own infrastructure at Amazon Web Services. We also use providers in these categories:

  • AI model providers for the AI Sidekick, reached through our cloud provider so that requests to the models stay within its infrastructure (the monitoring copies are described under PostHog above);
  • security-intelligence data sources used to assess your attack surface, including breach and exposed-credential services that receive the domains and email addresses you ask us to monitor;
  • secure network access for our operations team.

Signing in with Microsoft, or connecting a Microsoft 365 tenant, uses your organisation's own Microsoft account, under your organisation's agreement with Microsoft. Likewise, if you connect your own AI agent or another tool to the Service, what it reads is sent to the provider you chose, under your agreement with them.

Customers can request the full list of sub-processors by emailing privacy@ciso360.ai. We require sub-processors to handle personal data with appropriate safeguards.

We do not sell your personal data. We will only disclose data outside these providers when legally required (for example, in response to a valid court order), to protect the safety of users, or to a successor in a sale or reorganisation of our business, which must then protect it as this policy describes.

6. Data location and transfers

The Service is hosted primarily in Amazon Web Services' Australian (Sydney) region, and our internal collaboration tools hold data in Australia. AI Sidekick requests may be processed in other AWS regions. Analytics, session-recording, diagnostic and AI Sidekick monitoring data, and the service emails we send, are processed in the United States, and our websites are delivered from a global edge network. Where personal data leaves New Zealand, our providers hold it on our behalf under contracts that require them to protect it, consistent with the New Zealand Privacy Act 2020 (including IPP 12). Where the GDPR applies, we rely on appropriate transfer safeguards such as Standard Contractual Clauses.

7. Retention

  • Account data is retained for as long as your account is active, plus a reasonable period afterwards to meet legal, audit, and dispute-resolution obligations.
  • Service data is kept while your account is active. When you delete an organisation, or a locked project, we keep it for 30 days so it can be restored, then delete it permanently; other projects and records you delete are removed straight away. Audit and notification logs are kept for a period set by your plan. Removed user accounts are deleted permanently on request (see §8).
  • Session recordings are deleted after 30 days.
  • Diagnostic logs held by our analytics provider are deleted after 30 days.
  • Usage analytics are kept only as long as they are useful for improving the Service, and are then deleted or aggregated so they no longer identify you.
  • Cookie lifetimes are set out in §9.

On account closure, we delete or anonymise personal data within 30 days, subject to backups and legal-retention requirements.

8. Your rights

Depending on your jurisdiction, you have rights to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request deletion of your data ("right to be forgotten");
  • obtain a portable copy of your data;
  • object to or restrict certain processing, including analytics and session recording based on our legitimate interests;
  • withdraw consent (where consent is the legal basis);
  • lodge a complaint with a data-protection authority.

To exercise these rights, email privacy@ciso360.ai. We may need to verify your identity before acting on a request. Under the New Zealand Privacy Act 2020 we respond to access and correction requests within 20 working days.

If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner in New Zealand, or to the supervisory authority where you live or work in the European Union or United Kingdom.

9. Cookies

We use cookies and similar browser storage in three groups. We do not use advertising or cross-site tracking cookies.

GroupWhat it is forSet byHow longBasis
Strictly necessaryKeeping you signed in, remembering your organisation and project, your display preferences and your cookie choiceUsYour browser session, up to 30 days; stored preferences until you clear themNeeded to provide what you asked for
SecurityProtecting sign-in and connections from forgery and automated abuseUs, Vercel, CloudflareMinutes, up to your browser sessionLegitimate interests (security)
Analytics and session recordingUnderstanding how our websites and the Service are used, fixing faults and supporting youPostHogUp to 12 monthsYour consent on our websites; our legitimate interests in the Service (see §4)

On our websites (ciso360.ai and docs.ciso360.ai), product analytics and session recording (PostHog) run only if you accept them in the cookie banner; until you choose, PostHog records nothing. If you reject, PostHog still counts visits, the pages viewed and the links and buttons clicked, and measures page speed, without storing anything in your browser and without recording your session: it derives a daily, non-reversible value from your IP address and browser details and discards the daily key, so a visit cannot be linked to you or to another day. Separately, our hosting provider (Vercel) counts page views for every visitor, whatever you choose, to give us aggregate traffic statistics; it sets no cookies and discards the value it uses to recognise a visit after 24 hours. If your browser sends a Global Privacy Control signal and you have not yet made a choice, we treat it as a rejection. You can change your choice at any time with , which is also in the footer of each website.

In the Service, analytics, error diagnostics and session recording support and secure the platform. Typed values are masked and secrets such as API keys are excluded from recordings. You can object by emailing privacy@ciso360.ai.

You can also block or delete cookies in your browser settings; blocking strictly necessary cookies will stop sign-in from working.

10. Security

We protect your data through multi-tenant isolation, encryption in transit (TLS) and at rest, JWT-based authentication with PKCE, role-based access control, audit logging, and ongoing security testing. No system is perfectly secure; we cannot guarantee absolute security and you should evaluate the Service's suitability for your sensitivity profile during the preview. To report a security vulnerability, see our Vulnerability Disclosure Policy.

11. Privacy breaches

If a privacy breach is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people as required by Part 6 of the New Zealand Privacy Act 2020, and the relevant supervisory authority and individuals where the GDPR requires it. Where we process data on behalf of your organisation, we will notify your organisation without undue delay.

12. Information from other sources

To assess your organisation's security, the Service may collect information about your people from other sources — for example, public records about your domains and reports of exposed credentials. We do this on your organisation's behalf and under its instructions, and your organisation is responsible for telling its people about it. Where we collect personal information about you from someone else for our own purposes, we will tell you as the New Zealand Privacy Act 2020 requires.

13. AI-assisted outputs

The AI Sidekick suggests and summarises; it does not make decisions that have legal or similarly significant effects on you. A person in your organisation decides what to act on.

14. Children

The Service is for organisations and is not directed at anyone under 18. We do not knowingly collect personal data from children.

15. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email to the address on file for your account. Your continued use of the Service after such notice constitutes acceptance of the updated policy.

16. Contact

Privacy questions and requests can be sent to our Privacy Officer at privacy@ciso360.ai.

alterSec Limited · NZBN 9429047827035 · Auckland, New Zealand