Who we are
This notice is given by Falkyra Security Pvt Ltd, a company incorporated in India and based in Chennai. If you need our registered office address or company identification number for a formal request, write to contact@falkyra.com and we will provide them.
What we hold
Your account
When someone is given access to Falkyra, we store a login identifier, a display name, and a password that is stored only as a hash. We also record failed sign-in attempts and lock state, so an account can be protected against guessing.
What you scan, and what we find
Falkyra holds the assets you ask it to test, the findings it produces, and the evidence behind each finding.
Credentials you give us
To test the parts of an application that sit behind a login, Falkyra needs a credential for that application. These are the most sensitive thing on the platform.
Logs
Artificial intelligence
Falkyra uses language models to explain findings and draft remediation wording. They do not decide whether a finding is real, and they do not set its severity — that is calculated from the CVSS vector, and a test enforces that no model-generated severity exists anywhere in the product.
Who else sees it
| Recipient | What is sent | Why |
|---|---|---|
| Your own systems | The test traffic itself | That is the product |
| FIRST.org | CVE identifiers only, to retrieve public exploit-probability (EPSS) scores. No customer data is sent. | Exploit likelihood |
| Your notification channels | Finding summaries and links | Only where you configure email, Slack, Teams or a webhook — you choose the destination and it is your processor, not ours |
Amazon Web Services (AWS), Asia Pacific (Mumbai) — ap-south-1 |
Everything, at rest | Infrastructure |
We do not sell personal data, and we do not share it for advertising. There is no advertising network, data broker or marketing platform in this product.
How long we keep it
We keep your data until you ask us to delete it. We do not apply a fixed retention period to your account, your findings, the evidence attached to them, your scan configuration or your assets. They remain available to you for as long as your account exists, and they are removed when you delete them or when you ask us to close your account.
We would rather describe this accurately than quote a period we do not enforce. The one automatic expiry in the product is a sign-in refresh token, which expires after seven days. Nothing else expires on a timer.
If we introduce automatic deletion after a set period, we will say so here before it takes effect, and we will tell account holders — see Changes to this notice.
Your rights
How to exercise them
Write to contact@falkyra.com. Tell us what you are asking for and which account it concerns. We will acknowledge your request and respond within 30 days.
How deletion works today. You can delete most things yourself, from within the product: assets, notification channels, chat sessions and connected cloud accounts each have a delete action, and deleting them removes them from our database.
Deleting an entire account is a manual process. There is no self-service button that erases everything at once. When you ask us to close your account and delete your data, an operator carries it out against the database, and we confirm to you when it is done. We are telling you this plainly because a manual process described honestly is a commitment we can keep, and an automated one we do not have would not be.
Grievance Officer
If you are not satisfied with how we have handled a request or a complaint about your personal data, you can escalate it to our Grievance Officer at contact@falkyra.com. Write Grievance Officer in the subject line. We will respond within 30 days.
Cookies and tracking
This public site sets no cookies and runs no analytics. There is no tracking script, no advertising pixel and no third-party font on these pages.
The signed-in application does not use cookies either. Your access token is held in
memory for the life of the browser tab, and a refresh token is stored in your browser's
local storage under the key falkyra.refresh so that reloading the page does
not sign you out. That refresh token expires after seven days. Signing
out removes it, and so does clearing your browser's site data.
Children
Falkyra is a business product. Accounts are issued to organisations, and the service is not directed at children. We do not knowingly collect personal data of children. If you believe a child's personal data has reached us, write to contact@falkyra.com and we will delete it.
Changes to this notice
If we change this notice materially, we will update the date at the top and publish the change here before it takes effect, and we will tell account holders. Minor corrections — wording, typographical fixes — are made without notice.