Privacy Policy

Last updated: August 2026

This Privacy Policy explains what information Aion Security ("we," "us," or "our") collects when you use aionsecurity.io (the "Service"), and how we use, store, and protect it.

1. Information We Collect

  • Account information. If you create an account to use the monitoring dashboard, we collect your email address via our authentication provider (Clerk).
  • Domains you submit. The domain names you enter into the free scanner or add to your monitoring dashboard.
  • Scan results. Technical security data about the domains you submit — SSL/TLS certificate and configuration details, HTTP headers, DNS and email authentication records, blacklist status, cookie security flags, and detected platform/plugin information. This is data about the domain, not about you personally. Our exposed-files check probes a small set of well-known paths (like .env and .git) for accidental public exposure — we only record whether a given path is reachable, never the file's actual contents, so a scan never becomes a place where leaked credentials or source code end up stored.
  • Dependency files you upload. The free dependency vulnerability scanner is deliberately handled differently from everything else on this list: an uploaded package-lock.json, yarn.lock, requirements.txt, or composer.lock is read into memory, parsed into a plain list of package names and versions, checked against OSV.dev's public vulnerability database, and then discarded. We do not write the file to disk, store it in our database, or log its contents or filename — there is no record of it after the scan completes, even for us.
  • Usage and log data. Standard technical data such as IP address and request timestamps, collected to operate rate limiting and prevent abuse of the free scanner.
  • Analytics data. If you accept analytics cookies via the banner shown on your first visit, we use Google Analytics to understand how visitors use the Service — pages viewed, approximate location derived from IP address, device/browser type, and referring site. See Section 4 for how to accept, decline, or change this choice.
  • Aggregate visit data (Cloudflare Web Analytics). We also use Cloudflare Web Analytics for basic traffic metrics (pages viewed, load performance). This one runs automatically rather than behind the cookie banner, because it doesn't use cookies or any other client-side storage: visit counts are derived from a hashed combination of IP address and browser information that Cloudflare discards after processing, not a persistent identifier tied to you. See Section 4 for detail on why this is handled differently from Google Analytics.

We do not use third-party advertising trackers, and do not sell or share personal information with data brokers or advertisers.

2. How We Use Information

We use the information above to:

  • Provide and operate the free scanner and monitoring dashboard
  • Run scheduled scans of domains you've added for monitoring
  • Send email alerts when a monitored domain's security posture changes, if this feature is enabled on your account
  • Email an automatic monthly PDF security report for each domain you have monitored on Starter or Pro
  • Maintain the security and reliability of the Service, including rate limiting and abuse prevention
  • Communicate with you about your account or respond to support requests

3. Third-Party Service Providers

We rely on a small number of trusted providers to operate the Service:

  • Clerk — authentication and account/session management
  • Supabase — hosting of our application database
  • An email delivery provider — used to send monitoring alert emails and monthly PDF report emails, if and when this feature is configured
  • Google Analytics — website usage analytics. Google's use of this data is governed by their own Privacy Policy.
  • Cloudflare Web Analytics — cookieless traffic analytics, covered by Cloudflare's own Privacy Policy.

These providers process data on our behalf and are contractually restricted from using it for any purpose other than helping us operate the Service.

4. Cookies

The Service uses a session cookie set by our authentication provider (Clerk) to keep you signed in — this is strictly necessary for the Service to function and isn't something you can decline while staying signed in.

Google Analytics cookies (typically named _ga and _ga_*) are not set by default. The first time you visit, a banner asks whether to enable analytics; these cookies are only written if you choose Accept. You can change your choice at any time via Cookie Preferences in the footer of any page — declining there also removes any Google Analytics cookies already set. We do not use advertising or third-party retargeting cookies.

Cloudflare Web Analytics, described in Sections 1 and 3, is different: it doesn't set a cookie or use any other client-side storage at all, so it isn't part of the banner above and can't be disabled the same way — there's no cookie to decline. It runs on every visit purely to measure aggregate traffic.

5. Data Retention

We retain account information and scan history for as long as your account remains active. You can remove a domain from monitoring at any time from your dashboard. If you'd like your account and associated data deleted entirely, contact us using the details below.

6. Data Security

We take reasonable technical measures to protect the data we hold, including encrypting traffic to the Service in transit and restricting database access. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Rights

Depending on where you live, you may have rights to access, correct, or delete the personal information we hold about you. To exercise these rights, contact us using the details below and we will respond as required by applicable law.

8. Children's Privacy

The Service is not directed to individuals under 16, and we do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above.

10. Contact

Questions about this Privacy Policy can be sent to us via our Contact page.

This document is provided as a general Privacy Policy template and does not constitute legal advice. We recommend having it reviewed by a qualified attorney, particularly if you plan to process data from users in jurisdictions with specific requirements (such as GDPR or CCPA), before relying on it for your specific business needs.