How we handle the data you trust us with.
ShadowMap watches your organisation from the outside, continuously. That produces a standing body of data about your estate — and, in places, about people. This policy explains what we collect, why we are allowed to, who else touches it, where it sits and how long we keep it.
1. Who we are
ShadowMap is a continuous external attack-surface and exposure-intelligence platform operated by Security Brigade InfoSec Private Limited ("Security Brigade", "we", "us", "our"), a company incorporated in India with its registered office in Mumbai, Maharashtra. There is no separate ShadowMap legal entity: the company behind ShadowMap is the same CERT-In empanelled cybersecurity firm that has operated since 2006, with offices in India, the United Kingdom, the United States and Singapore.
This policy applies to the ShadowMap platform, to this website (shadowmap.com), and to any enquiry, demand-generation or support interaction that reaches us through either. Where you engage Security Brigade for consulting services rather than the platform, the policy published at securitybrigade.com applies to that engagement instead.
For the purposes of the EU and UK General Data Protection Regulation ("GDPR") and India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the controller and data fiduciary is:
Security Brigade InfoSec Private Limited
Registered Office: Mumbai, Maharashtra, India
CIN: available on request
Data Protection Officer: dpo@securitybrigade.com
Privacy enquiries: privacy@securitybrigade.com
2. Two very different kinds of data
Almost every question people ask us about privacy resolves once this distinction is clear. ShadowMap handles two categories of information, and our legal role is different for each.
- Data about you, collected by us, for us. Website visits, demo requests, enquiry forms, platform user accounts, support correspondence, commercial records. Here we decide why and how the data is processed, so we are the controller (data fiduciary under the DPDP Act).
- Exposure data about a customer's estate, collected by us, for them. Discovered assets, exposed services, leaked code and secrets, brand abuse, credential and dark-web exposure, vendor exposure, validation evidence. This is produced under the customer's instructions and against a scope the customer authorises, so for that material we are a processor (data processor under the DPDP Act) and the customer is the controller.
The second category is where a monitoring platform differs materially from a consulting engagement. A penetration test ends; a monitoring platform does not. ShadowMap keeps looking, keeps recording what changed, and retains the history so that a finding today can be compared against the estate as it stood months ago. Section 4 deals with the consequences of that honestly.
3. What we collect as controller
When we are acting for ourselves rather than for a customer, we collect:
- Enquiry and contact data. The demo and contact form on this site collects your first and last name, work email address, company, role, the apex domain you would like us to look at, your selected area of interest and any free-text message. It also records the page you submitted from, the referring page and any campaign parameters in the URL so we can tell which of our own pages are useful.
- Platform account and authentication data. Names, work email addresses, role assignments, session records and in-product activity and audit logs for users your organisation provisions into its ShadowMap tenant. Authentication secrets are stored hashed; we never store passwords in plaintext. Where your organisation uses SSO, authentication happens at your identity provider and we receive only the assertion and the attributes it carries.
- Commercial and contractual records. Order forms, agreements, billing contacts, invoices, and the correspondence around them.
- Support and onboarding correspondence. Emails, tickets, meeting notes and the configuration decisions taken during onboarding.
- Technical and usage data for this website. IP address, user agent, pages viewed, session duration and referral source, collected via server logs and — subject to your cookie choice — analytics.
We do not deliberately collect special-category personal data (Article 9 GDPR) about you, and we do not buy contact lists or enrich the data you give us from third-party data brokers.
4. Personal data inside exposure intelligence
ShadowMap's job is to find what an attacker can already see. Some of what an attacker can already see is personal data, and pretending otherwise would make this document useless. So, plainly:
- Attack-surface and brand material — hostnames, certificates, exposed services, publicly reachable documents and impersonating domains or profiles — regularly contains names, work email addresses, employee identifiers and similar business-contact data belonging to the customer's own people.
- Source-code and data-exposure material — public repositories, misconfigured storage, exposed configuration — regularly contains credentials, keys and, incidentally, personal data belonging to the customer's employees, contractors, customers or end users.
- Dark-web and stealer-log material is the sharpest case. Infostealer malware output is device-level: a single infected machine yields credentials, session cookies and tokens, autofill entries, browser history, payment and wallet artefacts and machine information. ShadowMap assembles that into a coherent compromise case rather than a flat credential list, because a security team needs to distinguish a stale personal password from a live session against your cloud tenant. That material can and does contain personal data about individuals who are not our customers, have no relationship with us, and did not choose for their machine to be compromised.
How we constrain that:
- Attribution before exposure. A customer tenant surfaces material that has been correlated to that customer's identities and assets. The platform is not a search engine over the corpus, and customers cannot query it for arbitrary individuals or unrelated organisations.
- Purpose limitation. This material is processed for one purpose: detecting, evidencing and helping remediate exposure that affects the customer's estate. We do not sell it, licence it as a data product, use it to build marketing profiles, or use it to enrich anyone's contact database.
- No credential use. Recovered credentials are treated as compromised and reported for rotation or revocation. They are used to test access only where a customer has authorised validation against its own in-scope estate, and never against a third party.
- Aggregate learning only. Where we use engagement data to improve detection quality, we use anonymised, aggregated and de-identified information from which no customer, individual or estate can be identified.
- No transmission to third-party model providers. ShadowMap's AI features do not send customer personal data to third-party large language model providers. This is a contractual commitment recorded in our Data Processing Agreement, not just a practice.
If your personal data appears in ShadowMap because of a breach elsewhere: write to dpo@securitybrigade.com. Where we hold that material as a processor for a customer, we will route your request to that customer as the controller and tell you we have done so. Where we hold it as controller of the underlying corpus, we will handle the request ourselves under Section 11.
5. Legal bases for processing
When acting as controller, we rely on:
- Contractual necessity (Art. 6(1)(b) GDPR). Provisioning and operating your ShadowMap tenant, supporting your users, and administering the subscription.
- Legitimate interests (Art. 6(1)(f) GDPR). Marketing the platform to enterprise prospects, product analytics, fraud prevention, and securing our own network and services. Recital 49 GDPR expressly recognises processing strictly necessary for network and information security as a legitimate interest, and that is the basis on which the exposure corpus described in Section 4 is maintained. We carry out and record balancing assessments for each of these activities, and you may object at any time.
- Consent (Art. 6(1)(a) GDPR / Sec. 6 DPDP Act). Non-essential cookies and marketing subscriptions. Consent can be withdrawn at any time without affecting processing carried out before withdrawal.
- Legal obligation (Art. 6(1)(c) GDPR). Tax and company-law records, and statutory reporting including CERT-In incident reporting under the Information Technology Act, 2000.
Under India's Digital Personal Data Protection Act, 2023 the structure is different rather than parallel. The Act recognises consent (Section 6) and a closed list of "certain legitimate uses" (Section 7); it has no contractual-necessity or legal-obligation ground of the kind GDPR Article 6 provides. Where we process personal data of individuals in India as a Data Fiduciary, we rely on consent under Section 6, on the voluntary-provision legitimate use in Section 7(a), and — for employee data — on Section 7(i). Retention required by other Indian law is handled as an exception to the erasure obligation under Section 8(7), not as a processing ground. Our DPDP compliance page sets this out in full.
When acting as processor, we do not choose a legal basis at all — we process on your documented instructions under the Data Processing Agreement, and the lawful basis for the underlying processing is yours to determine as controller.
6. How we use your data
- Operating the ShadowMap platform: discovery, monitoring, correlation, validation, alerting, reporting and takedown workflow.
- Provisioning users, applying role-based access control, and producing the activity and audit records your own auditors ask for.
- Responding to enquiries, scheduling demonstrations, scoping evaluations and issuing quotations.
- Delivering analyst-led onboarding and ongoing support.
- Sending service and security notifications, and — where you have asked for them — research and threat updates.
- Understanding which pages and campaigns are useful, so we publish less and better.
- Meeting legal, regulatory and contractual obligations, and defending legal claims.
- Protecting the security and integrity of the platform, our infrastructure and our customers' data.
7. Cookies and analytics
This website uses a small number of cookies and similar technologies:
- Strictly necessary — session integrity and security. These cannot be switched off.
- Analytics — how visitors move through the site, so we can improve it.
- Functional — remembering preferences such as your cookie choice itself.
Analytics and any advertising-platform tags are gated behind the consent banner. Until you accept, Google Consent Mode keeps analytics storage and all advertising storage denied, no analytics or advertising cookies are written, and the only signal leaving the page is a cookieless ping. Declining leaves that state in place. You can change your mind at any time by clearing site data in your browser and choosing again.
8. Sharing and sub-processors
We do not sell personal data, and we do not share exposure intelligence between customers. We disclose personal data only to the following categories of recipient:
- Our own group offices in India, the United Kingdom, the United States and Singapore, for delivery, support and operational coordination.
- Sub-processors, listed below, each bound by written data-protection obligations no less protective than those we owe you.
- Professional advisors — legal counsel, auditors and insurers — where necessary and under confidentiality.
- Regulatory and law-enforcement authorities where required by applicable law, court order or regulation, including CERT-In under the Information Technology Act, 2000.
- Takedown providers, registrars, hosts and platform abuse desks, where you instruct us to file a takedown. A takedown request necessarily discloses the material complained of and the identity of the complaining organisation. Every request passes a human approval gate before dispatch.
Our current sub-processors, as recorded in Annex C of the Data Processing Agreement, are:
| Sub-processor | Role | Region |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, edge security, WAF | Global edge |
| Amazon Web Services, Inc. | Encrypted backup storage | Region-locked per customer election |
| SendGrid (Twilio Inc.) | Transactional email | United States |
| Mailtrap | Transactional email (non-production) | European Union |
| Twilio Inc. | Voice and SMS to customer-designated contacts | United States / global |
| Exotel Techcom Pvt. Ltd. | Voice to Indian-jurisdiction contacts | India |
| Microsoft Corporation | Operational email (Microsoft 365) | European Union / India |
| Google LLC | Operational email (Google Workspace) | European Union / India |
We give customers at least thirty days' notice before adding or replacing a sub-processor, and a customer may object on reasonable data-protection grounds. The authoritative list is Annex C of the Data Processing Agreement.
Deliberately not sub-processors: our source control, error tracking, internal audit management and CRM systems are self-hosted on our own infrastructure. Large language model providers are not sub-processors because we do not transmit customer personal data to them. Colocation operators provide physical hosting and environmental security only and do not process personal data; their names and facility details are disclosed under non-disclosure on request. Background-check vendors process our own personnel data, not yours.
9. Transfers and data residency
We operate across four countries, so personal data may move between India, the United Kingdom, the United States and Singapore. For transfers of EEA or UK data to countries without an adequacy decision we rely on:
- the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two, controller to processor;
- the UK International Data Transfer Addendum (Version B1.0, in force 21 March 2022) for UK personal data;
- transfer impact assessments consistent with the Schrems II judgment (Case C-311/18), with supplementary technical measures where an assessment calls for them.
Under Section 16 of the DPDP Act, transfers out of India are permitted other than to jurisdictions the Central Government notifies as restricted. We monitor those notifications and do not transfer to restricted jurisdictions.
Residency is configurable. Where you elect data localisation, we configure storage and backup locations accordingly. Regions currently available are Mumbai, Paris, Singapore and Dubai, with further regions on request, and a customer-specific private-cloud deployment is available where region-level separation is not enough. Deployment and residency arrangements are confirmed during onboarding and recorded in your order form.
10. Retention and destruction
We keep personal data only as long as the purpose requires, or as law requires:
- Customer tenant data — findings, assets, evidence and platform records — for the term of the subscription. On termination or expiry, destruction completes within thirty days for live production systems and copies, and within ninety days for backup and archival systems.
- Customer-supplied personal data returned on request. You may elect, in writing before termination or within thirty days after it, to have customer-supplied personal data returned in a machine-readable format before destruction. This does not extend the destruction windows above.
- Data retained under statutory or regulatory obligation — including audit trails required by Indian law or by your own regulator — for the shorter of the legally required period and seven years.
- Commercial and tax records — seven years from the last transaction, as required under Indian tax and company law.
- Dark-web and stealer-log source material is retained on a permanent basis as a research corpus, held outside customer tenants. This is deliberate: material collected years ago is reprocessed against new customer identifiers, which is how a compromise that predates a customer relationship becomes visible at all. Individual rights over this material are dealt with in Sections 4 and 11.
- Marketing-site enquiry data — for as long as the enquiry is live plus the period needed to answer follow-up correspondence, then archived or deleted.
- Website analytics — aggregated data indefinitely; individual-level data purged after 26 months.
- Marketing consent records — for the duration of your consent plus three years, to evidence compliance.
Digital destruction follows standards consistent with NIST SP 800-88 (Guidelines for Media Sanitization), and written certification of destruction is provided on request.
11. Your rights
Depending on where you are, you have some or all of the following rights over your personal data:
- Access — confirmation of whether we process your data, and a copy of it.
- Rectification — correction of inaccurate data and completion of incomplete data.
- Erasure — deletion where there is no overriding reason for us to continue.
- Restriction — pausing processing in defined circumstances, such as while accuracy is verified.
- Portability — receiving data you gave us in a structured, machine-readable format.
- Objection — to processing based on legitimate interests, and unconditionally to direct marketing.
- Withdrawal of consent — at any time, where consent is the basis.
- Nomination — under Section 14 of the DPDP Act, nominating someone to exercise your rights in the event of death or incapacity.
- Complaint — to a supervisory authority (see Section 13).
Write to dpo@securitybrigade.com. We will verify your identity first, and respond within one calendar month for GDPR requests and within the periods prescribed by the DPDP Act and its rules for DPDP requests. Complex or numerous requests may be extended by up to two further months, and we will tell you within the first month if that applies.
Where we hold the data as a processor on a customer's behalf, we will forward your request to that customer and acknowledge to you that we have done so, as Article 28(3)(e) GDPR requires. We acknowledge customer requests relating to data subjects within forty-eight hours and respond substantively within ten business days.
Rights are not absolute. Erasure of exposure evidence may be constrained where the material is needed to evidence a security incident, to meet a statutory retention obligation, or to establish or defend a legal claim; where we refuse or restrict, we will tell you why.
12. Security of personal data
Personal data is encrypted at rest using AES-256 or equivalent, and in transit using TLS 1.2 or higher with strong cipher suites. Access is role-based and least-privilege, multi-factor authentication is required for all production systems and for any access to customer personal data, privileged access is logged and reviewed, and access is revoked within one business day of someone leaving or changing role. A full account of how the platform is secured, including tenancy separation, monitoring, secure development and incident response, is on our security page.
13. Supervisory authorities and complaints
Please contact dpo@securitybrigade.com first — most concerns are resolved faster that way. You nonetheless have the right to complain to:
- India — the Data Protection Board of India, once constituted under the DPDP Act, 2023.
- EU / EEA — your local Data Protection Authority.
- United Kingdom — the Information Commissioner's Office.
- Singapore — the Personal Data Protection Commission.
14. Children
ShadowMap is an enterprise platform sold to organisations. It is not directed at children, and we do not knowingly collect personal data of children through this website or the platform. If you believe a child's personal data has reached us through either, contact dpo@securitybrigade.com and we will delete it.
15. Changes to this policy
We update this policy when our practices, technologies, sub-processors or legal obligations change. The revised version is posted here with a new "last updated" date. Where a change is material and affects customers, we notify the relevant contacts directly; sub-processor changes follow the thirty-day notice process in Section 8.
16. Contact
Data Protection Officer
Security Brigade InfoSec Private Limited
Registered Office: Mumbai, Maharashtra, India
Email: dpo@securitybrigade.com
Privacy enquiries: privacy@securitybrigade.com
Contractual and legal enquiries: legal@securitybrigade.com
Security reports: security@shadowmap.com
Anything else: contact@shadowmap.com
Questions a policy page cannot answer.
Procurement, privacy and security reviews are part of our normal onboarding. Send us your questionnaire, or take the 30-minute technical walkthrough first — bring your apex domain, keep the report either way.