Security & data handling

What we touch. What we don't.

Monitoring your external exposure does not mean entering your systems. Here is precisely what the tool does — and what it refuses to do by design.

No agent installed
No software to deploy on your workstations or servers. KryptaScope works only from the outside, exactly like an attacker. Zero intervention on your IT.
No access to your systems
We never request credentials to your mailboxes, servers, Active Directory, hosting provider, or internal tools. Everything we see is what the Internet sees.
No proxy, no tunnel
No redirection of your network traffic. No eavesdropping. No man-in-the-middle. Requests go from our servers to public sources (DNS, SSL registries, published breach databases) — never to your customers or employees.
No password stored
We detect that email + password pairs have been publicly leaked, but we only store metadata (yes/no, source, date). The password itself is never kept. Same for hashes.
Non-nominal public scan
The /scan page, available without an account, returns only aggregated counters (number of leaks, severity, admin presence). No email exposed, no breach name displayed, nothing an attacker could put to use. The rule is enforced server-side: no named detail ever reaches the browser until the domain has been tied to a verified account.
European hosting
Database hosted in the European Union. Application servers may handle a request from more than one region, but no customer data is stored outside the EU. Error monitoring and product analytics are routed through our own domain: no data is sent directly to a third party from your browser.
Data deletable on request
1-click cancellation from the dashboard. On written request, complete deletion of data associated with your account within 30 days, with written confirmation. Data retained for legal obligation (billing) is anonymised at the end of the retention period.

Technical details

Scan scope
DNS, public SSL certificates, recognized public breach databases, typosquatting registries. No aggressive port scan, no injection.
Storage
PostgreSQL (Supabase EU). User passwords hashed with bcrypt (cost factor 13). 2FA tokens encrypted with AES-256-GCM using a derived key. Sessions use a server-signed token held in an httpOnly cookie, valid for 30 days.
Communications
HTTPS only (HSTS preload). Strict CSP on every page. No advertising trackers. Error monitoring and product analytics are served from our own domain: no data is sent directly to a third party from your browser.
Operator access
Access to your dashboard only on explicit request (support ticket). No silent access. Operator access logs available on request.
Subprocessors
Supabase (database, EU), Vercel (application hosting, multi-region processing, no customer data stored outside the EU), Resend (transactional email), Stripe (payments), Sentry (error monitoring), PostHog (product analytics). DPAs available on request.

Going further

Terms of use
Data collected, retention periods, governing law and GDPR contacts.
System status
Current status of scans, database and third-party services.
Report a vulnerability
security@kryptascope.com — response within 48 business hours. No paid bug bounty program, but an MSP/Pro credit is possible depending on impact.