Privacy
What we collect, and what we do with it
This site sets no cookies, runs no analytics and makes no third-party requests. The only personal data that reaches us is what you put in an email and what an engagement requires, and the second of those is the one worth reading about.
This website
The site itself collects nothing
It is static HTML, CSS, a few images and one script. There is no application behind it and no request leaves your browser for anyone but us.
No cookies are set, no local storage is written, and no analytics, tag manager, session recorder, advertising pixel or embedded font runs here. The content security policy blocks anything from a third-party origin, so a tracker cannot be added later by accident.
The one script is the assistant in the corner of this page. It is served from this domain, it answers from a fixed list of answers written into the file itself rather than from a language model, and it makes no request of its own. Nothing you type into it is sent anywhere, stored anywhere or seen by us, and the conversation is gone the moment you close the page. Blocking scripts leaves the rest of the site exactly as it is.
No form on this site submits anything to a server. Every way of contacting us is a mail link that opens your own mail client, and the assistant's message box is wired to the page rather than to an endpoint, so nothing arrives in a CRM.
The site is served by Cloudflare, which records the usual server-side request logs (IP address, time, URL, user agent) for delivery, caching and abuse prevention. We do not build profiles from those logs, and Cloudflare's own retention applies to them. That is the whole of what a visit produces.
Enquiries
When you email us
We get whatever you put in the message: your name, your address, the company you work for, and the description of the application you are asking about.
We use it to answer you, to work out whether we are the right people for the work, and to scope and quote it if we are. That is the only use it has. You are not added to a mailing list, and we do not send marketing to an address that reached us this way.
Mail is held with our email provider and on our own machines. Threads that do not turn into work are deleted within twelve months. If you would rather we did not keep a description of your application on file at all, say so and we will delete the thread once the conversation ends.
If you want an NDA in place before describing the system in detail, ask in the first email and we will deal with that before anything else.
Engagements
Testing data is the part that matters
A penetration test puts us inside a system other people depend on. This is what we hold while that is true, and what happens to it afterwards.
-
What we are given
Scope documents, test accounts and their credentials, API keys or tokens issued for the test, and whatever you send us to describe the application. Where testing runs against production, the requests we make may return live data belonging to your users.
-
What we produce
Request and response logs from our own testing, notes, proof that a finding is real, and the report itself. Screenshots and captured responses are redacted where the finding does not depend on the data in them.
-
Where it is kept
On encrypted disks under our own control, reachable by the people working on your engagement and nobody else. Reports are delivered to the people you name and are not posted to a shared drive, a portal or a ticketing system.
-
How long it is kept
Credentials and tokens are destroyed as soon as the retest window closes, and we ask you to revoke them at the same time. Testing data and the report are deleted twelve months after the engagement ends, unless your contract or NDA sets a different period, in which case that one applies.
-
What we do not do with it
Nothing from an engagement is published without your written permission: not as a case study, a talk or a marketing line, and not anonymised on the argument that anonymised is not really you. If we ever ask, you will see the exact words before anyone else does, and no is an ordinary answer. Nothing from an engagement trains anything, and nothing is sold.
We test only what the owner has authorised in writing. Where the system belongs to a third party, their sign-off covers our access to whatever data that system holds, which is why we ask for it before anything starts rather than after.
Sharing
Who else sees any of it
Nobody buys data from us, because none of it is for sale. There are no subcontractors: the testing is done in house, so no third party is handed your application, your credentials or your report in order for us to deliver an engagement.
The suppliers that necessarily touch data are the ones any company has: the provider that carries our email, the hosting for this website, and the tools we use to write and encrypt reports. They process it to provide their service and for nothing else. Reports and testing data stay on our own machines, and nothing you send us passes through this website, which is a brochure with no application behind it.
We would disclose something only where the law requires it. If we are ever compelled to hand over material from your engagement, we will tell you unless we are prohibited from doing so.
Your rights
Asking what we hold
Email us and ask. We will tell you what we have, correct it if it is wrong, or delete it.
Where the GDPR, the UK GDPR or a comparable law applies to you, it gives you rights of access, correction, erasure, restriction, portability and objection. We do not require you to invoke a statute to use them: a plain email to contact@skullsploit.com is enough, and we answer within thirty days.
The one limit is a contractual one. Where an engagement's records are held to a period your own contract or NDA sets, we keep them for that period, and we will say so rather than delete something you may later need to prove a test happened.
SkullSploit is a brand of Skull Solutions, which is based in the Maldives, so data you send us is handled there and Skull Solutions is the controller of it.
Changes
If this policy changes
The date at the top of this page is the date it last changed. A change applies to work agreed after it, not retrospectively to an engagement already under way. The terms you agreed to are the ones that govern your data.
Questions about any of it go to contact@skullsploit.com and reach us directly.
Still have a question
If something here is unclear, ask before you start a conversation rather than after.