Before you put a vulnerability decision here, see where its data goes. This inventory covers your records, service identities, account and notification details, with the reason each is held and the controls around it.
Account and billing. Your email, name, and organization for sign-in and seats. Payment details live with Stripe; we never see or store card numbers.
Your subject. The list of what your organization runs: vendors, products, versions, and, on Custody with OTel connected, active service identities: distinct service and version pairs with first-seen and last-seen timestamps, replicas collapsed, retired after 30 days unseen. This is the most sensitive thing we hold and it's treated that way; see the section below.
Your decision records. VDRs, their verdicts and rationale, and the evidence snapshots frozen behind them. This is the product: records you're paying us to keep, dated and re-derivable.
Notification addresses. The email addresses and webhook URLs your alerts go to.
Product analytics. Which features get used, counted by our own self-hosted event counters; no third-party analytics runs on these pages. Analytics never contain your subject entries or the contents of your records.
OpenTelemetry payloads: span, metric, and log data is dropped at ingress, unstored and unlogged, by our own ingest code before anything is written. A collector configuration that keeps that data off the wire entirely is generated for you at sign-in; it is not yet a public document, so this is our commitment to enforce the drop on our side, not something you can independently check today. No third-party fonts or CDN trackers: pages load from us, so your visits don't leak your address to anyone else. No advertising, no data sales, no data sharing for marketing. And we do not train models on your subjects or your records; our models train on public vulnerability data only.
A list of what you run, with versions, is exactly what an attacker wants. We treat subject data accordingly: encrypted in transit and at rest, excluded from analytics and application logs, accessible in production to no one in the ordinary course, and never used for anything except answering your questions, matching your watches, and computing your scorecard. If your policies require that it never leave your network at all, that is what the On-Prem plan is for.
Voxell, Inc. operates the service directly: account, billing and the CVE index run on infrastructure we control ourselves, not a cloud hosting vendor. Decision records live in the vault, a Cloudflare Worker backed by Cloudflare R2 object storage, encrypted at rest by Cloudflare. Subprocessors, in full: Stripe (payments), Cloudflare (network, and R2 storage for the vault), Amazon SES (notification delivery). That is the whole list; we'll update it here before adding anyone.
Production access is limited to named operators with defined roles, used only to operate the service or at your request. When you ask for help with your own records, access happens with your knowledge. Every change to a record is recorded in the record's own chain, which you can review in the vault at any time. And your vendor-risk reviewer will ask the next question, so it is answered here: your records are your property and export on termination (§7, §13), the record format is unlicensed and readable without any software of ours (§8), and every fact carries the public source and the query that re-derives it. The evidence does not depend on this company continuing to exist. See what you keep.
Your records are kept while you subscribe; that's the service. When a paid plan ends, or you ask us to delete your account, your data is purged automatically 30 days later. A purged account can be recovered through a support ticket for one year; after that it is deleted for good.
You can export your data, correct it, or delete it, and you can ask what we hold about you; the answer will match this page. California residents: we do not sell or share personal information as those terms are defined in the CCPA. EU and UK residents: Voxell, Inc. is the controller for account data and the processor for your subject and records; requests go to the address below and are honored within the statutory windows.
If we confirm a breach affecting your data, we will notify you within 72 hours of confirmation with what we know, what it touches, and what we're doing, and we will not make you learn it from the news.
Material changes get 30 days' notice by email or in-product, and the inventory above stays complete: if we start holding something new, it appears here first. Voxell, Inc., 525 Washington Square, Marysville, CA 95901. Privacy requests: [email protected].