Data Privacy

Privacy policy and confidentiality charter.

How Krylo Security handles confidential assessment data, client systems information, and personal records with absolute technical rigor and legal integrity.

EFFECTIVE DATE: OCTOBER 2024ENTITY: KRYLO SOLUTIONS PRIVATE LIMITEDSTATUS: ACTIVE & ENFORCEABLE
01 //

Entity Identification & Scope

Who we are and our commitment to operational confidentiality.

This Privacy Policy outlines how Krylo Security ('we', 'our', or 'us'), operating as the dedicated cybersecurity division of Krylo Solutions Private Limited (CIN: U62099WB2024PTC269135, registered in West Bengal, India), collects, handles, protects, and retains information provided through our website (krylosecurity.com) and during our professional penetration testing engagements.

As a specialized cybersecurity service provider, we understand the critical sensitivity of the infrastructure, applications, and source code our clients entrust to us. We treat all customer interactions with strict confidentiality and professional discretion.

Division of Krylo Solutions Private Limited (CIN: U62099WB2024PTC269135)
Strict separation between marketing data and offensive testing data
Bilateral NDAs executed prior to technical exchange
02 //

Information We Collect

Transparent categorization of commercial and engagement data.

We collect information strictly necessary to provide penetration testing, vulnerability assessment, and offensive security consulting services:

1. Commercial Inquiries: When you submit an assessment request or contact us via email or our contact forms, we collect your name, business email address, company name, telephone number, and brief description of your project requirements.

2. Engagement Scoping Data: In preparation for a security assessment and following the execution of a Non-Disclosure Agreement (NDA), clients provide technical scoping information including target IP addresses, application URLs, staging access credentials, API documentation, and architecture diagrams.

3. Technical Logs & Website Telemetry: We may collect minimal, anonymized server access logs for cybersecurity defense and uptime monitoring of our own website.

No unnecessary marketing trackers or third-party behavioral analytics
Scoping data accepted only under formal bilateral confidentiality
Explicit consent required for all commercial communications
03 //

Confidentiality & NDA Enforceability

Formal legal protections governing every offensive assessment.

Before initiating any technical testing or receiving sensitive infrastructure specifications, Krylo Security executes a binding Mutual Non-Disclosure Agreement (NDA) or adheres to the client's corporate NDA.

All proprietary information, vulnerability reports, exploit proof-of-concepts, network topology schematics, and test credentials provided by or created for the client are classified as Strictly Confidential.

Our offensive researchers and engineers are bound by strict employment confidentiality agreements and background vetting.

Mutual Non-Disclosure Agreement (NDA) mandatory before scoping
Vulnerability data classified as Strictly Confidential
Zero disclosure to third parties, regulatory bodies, or media
04 //

Data Storage & Cryptographic Protection

How engagement artifacts and vulnerability reports are safeguarded.

We apply technical safeguards to keep client assessment artifacts and vulnerability reports protected at all times:

1. Encryption Standards: All sensitive client documentation, assessment notes, and final reports are stored encrypted using industry-standard AES-256 encryption at rest and TLS 1.3 in transit.

2. Access Restrictions: Access to client assessment deliverables is restricted strictly to the designated security researchers assigned to the engagement on a strict need-to-know basis.

3. Secure Deliverables: Final penetration testing reports and vulnerability registries are transmitted securely via encrypted channels or client-preferred secure vault systems.

AES-256 encryption at rest, TLS 1.3 in transit
Role-based need-to-know access control for researchers
Deliverables distributed exclusively through secure, verified channels
05 //

Data Retention & Secure Purging

Decommissioning of test data at the end of each engagement.

We do not indefinitely retain client technical data or assessment artifacts:

1. Post-Engagement Retention Window: We retain engagement notes and vulnerability documentation only for the period agreed in the contract, after which they are purged as described below.

2. Secure Destruction: At the end of the engagement and following written client sign-off, all staging access credentials, temporary test accounts, target logs, and local working files are securely purged and sanitized from our active systems.

3. Archived Deliverables: Client reports are maintained only in encrypted cold storage as required for contractual audit and statutory tax/accounting compliance, unless the client explicitly requests immediate purge in writing.

Temporary retention only for the period agreed in the contract
Full sanitization of test accounts and staging credentials upon completion
Written confirmation of data purge available upon request
06 //

Zero-Monetization & Third-Party Sharing

We never sell, broker, or monetize client data under any circumstances.

Krylo Security operates on a direct B2B cybersecurity consulting business model. We do not sell, rent, license, or monetize any client contact information, assessment findings, or technical metadata to third parties, data brokers, or advertising networks.

We do not outsource offensive penetration testing to unvetted third-party contractors. All security testing is conducted by vetted members of our team.

Zero data monetization or ad network tracking
No unvetted contractor outsourcing
Strict protection against commercial exploitation of security findings
07 //

Compliance & Data Subject Rights

Adherence to national and international data privacy regulations.

We process personal and organizational data in accordance with applicable data protection legislation, including the Digital Personal Data Protection (DPDP) Act of India, and where applicable, the General Data Protection Regulation (GDPR) for European entities.

You maintain the right to access, rectify, or request the erasure of your personal contact data stored in our commercial systems at any time by contacting our data protection team.

Compliant with Indian DPDP Act and international privacy frameworks
Right to access, rectify, or delete commercial contact records
Dedicated point of contact for data inquiries
08 //

Policy Updates & Contact Information

Direct communication with our security and legal team.

We may update this Privacy Policy from time to time to reflect evolving regulatory requirements or operational improvements. Material updates will be indicated by the 'Last Modified' date at the top of this document.

For questions, privacy inquiries, or requests regarding this Privacy Policy or your assessment data, please reach out to our team directly at [email protected].

Primary Contact: [email protected]
Corporate Entity: Krylo Solutions Private Limited
Official response window within 48 business hours
Ready to engage

Start your security assessment.

Tell us about your application, architecture or compliance requirements. Our team will scope a penetration test around them.

NDA before disclosureScoped to your environmentPlanned for minimal disruption