Privacy

Last updated: 28 September 2026

Who we are

This notice is given by Falkyra Security Pvt Ltd, a company incorporated in India and based in Chennai. If you need our registered office address or company identification number for a formal request, write to contact@falkyra.com and we will provide them.

What we hold

Your account

When someone is given access to Falkyra, we store a login identifier, a display name, and a password that is stored only as a hash. We also record failed sign-in attempts and lock state, so an account can be protected against guessing.

What you scan, and what we find

Falkyra holds the assets you ask it to test, the findings it produces, and the evidence behind each finding.

Credentials you give us

To test the parts of an application that sit behind a login, Falkyra needs a credential for that application. These are the most sensitive thing on the platform.

Logs

Artificial intelligence

Falkyra uses language models to explain findings and draft remediation wording. They do not decide whether a finding is real, and they do not set its severity — that is calculated from the CVSS vector, and a test enforces that no model-generated severity exists anywhere in the product.

Who else sees it

RecipientWhat is sentWhy
Your own systems The test traffic itself That is the product
FIRST.org CVE identifiers only, to retrieve public exploit-probability (EPSS) scores. No customer data is sent. Exploit likelihood
Your notification channels Finding summaries and links Only where you configure email, Slack, Teams or a webhook — you choose the destination and it is your processor, not ours
Amazon Web Services (AWS), Asia Pacific (Mumbai) — ap-south-1 Everything, at rest Infrastructure

We do not sell personal data, and we do not share it for advertising. There is no advertising network, data broker or marketing platform in this product.

How long we keep it

We keep your data until you ask us to delete it. We do not apply a fixed retention period to your account, your findings, the evidence attached to them, your scan configuration or your assets. They remain available to you for as long as your account exists, and they are removed when you delete them or when you ask us to close your account.

We would rather describe this accurately than quote a period we do not enforce. The one automatic expiry in the product is a sign-in refresh token, which expires after seven days. Nothing else expires on a timer.

If we introduce automatic deletion after a set period, we will say so here before it takes effect, and we will tell account holders — see Changes to this notice.

Your rights

How to exercise them

Write to contact@falkyra.com. Tell us what you are asking for and which account it concerns. We will acknowledge your request and respond within 30 days.

How deletion works today. You can delete most things yourself, from within the product: assets, notification channels, chat sessions and connected cloud accounts each have a delete action, and deleting them removes them from our database.

Deleting an entire account is a manual process. There is no self-service button that erases everything at once. When you ask us to close your account and delete your data, an operator carries it out against the database, and we confirm to you when it is done. We are telling you this plainly because a manual process described honestly is a commitment we can keep, and an automated one we do not have would not be.

Grievance Officer

If you are not satisfied with how we have handled a request or a complaint about your personal data, you can escalate it to our Grievance Officer at contact@falkyra.com. Write Grievance Officer in the subject line. We will respond within 30 days.

Cookies and tracking

This public site sets no cookies and runs no analytics. There is no tracking script, no advertising pixel and no third-party font on these pages.

The signed-in application does not use cookies either. Your access token is held in memory for the life of the browser tab, and a refresh token is stored in your browser's local storage under the key falkyra.refresh so that reloading the page does not sign you out. That refresh token expires after seven days. Signing out removes it, and so does clearing your browser's site data.

Children

Falkyra is a business product. Accounts are issued to organisations, and the service is not directed at children. We do not knowingly collect personal data of children. If you believe a child's personal data has reached us, write to contact@falkyra.com and we will delete it.

Changes to this notice

If we change this notice materially, we will update the date at the top and publish the change here before it takes effect, and we will tell account holders. Minor corrections — wording, typographical fixes — are made without notice.