Privacy Policy
How we collect, use, and protect your information.
Effective date: July 27, 2026 · Last updated: July 27, 2026
1. Introduction
Lorikeet Security ("we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website at lorikeetsecurity.com, use our client or partner portal, contact us by phone or email, or engage with our cybersecurity services.
By using our website or services, you agree to the collection and use of information in accordance with this policy.
Two different roles
It matters which one applies to you:
- We are the controller of information collected through our website, our marketing, our phone and email channels, and the administration of your account. We decide why and how that data is processed, and this policy governs it.
- We are a processor of the data we handle on a client's behalf during a security engagement — scan results, findings, evidence, test credentials, and anything in a client system we are authorized to test. That processing is governed by the client's Statement of Work and Data Processing Agreement, not by this policy. If you are an individual whose data appears in a client's systems, please contact that client; we will support them in responding.
Related policies
Our AI Usage Policy explains how our AI system, Lory, processes data, which model providers receive it, and what human oversight applies. Our Terms of Service govern your use of the site and services.
2. Information We Collect
Information You Provide
We may collect information that you voluntarily provide to us, including:
- Name, email address, and phone number when you contact us or book a consultation
- Company name and job title
- Information submitted through our contact forms or booking system
- Email address when you subscribe to our newsletter or blog
- Any other information you choose to provide in communications with us
Information Collected Automatically
When you visit our website, we may automatically collect certain information, including:
- IP address and approximate geographic location
- Browser type and version
- Operating system
- Referring website or source
- Pages visited and time spent on each page
- Date and time of your visit
Account and Portal Data
If you hold an account in our client portal or partner portal, we process your name, work email address, organization, role and permissions, authentication events, session and device metadata, and an audit log of actions taken in the portal. The client portal is used to request engagements, view findings, and manage assets and scope.
Communications
- Chat. Transcripts of conversations with our AI assistant on the website, in the client portal, and in the partner portal.
- Calls. Call audio, recordings, transcripts, phone numbers, and call metadata. Calls are recorded and recording is disclosed to all parties before it begins — in the greeting on inbound calls and by announcement on outbound calls. If you do not consent, tell us and we will end the call or continue by another channel.
- Email. Correspondence you send to our mailboxes, including threads handled by our AI email agent.
- Meetings. Calendar entries and invitations for scheduled consultations.
Billing Information
Billing contact details, purchase history, invoices, and subscription status. Card details are collected and processed directly by Stripe and do not transit or rest on our systems.
Engagement Data
Where you are a client, we process the scope and asset inventory you declare, credentials you supply for testing, findings and evidence produced during an engagement, and the per-engagement activity log recording what was tested and what the result was. Test credentials are encrypted at rest with AES-256-GCM. Secret values are redacted out of logs, transcripts, and finding evidence.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve our cybersecurity services
- To operate your account and the client and partner portals, including authentication and access control
- To respond to your inquiries and schedule consultations
- To scope, perform, and report on security engagements you have authorized
- To process payments, issue invoices, and manage subscriptions
- To send you relevant security insights, blog updates, or service information (with your consent, where consent is required)
- To analyze website usage and improve our content and user experience
- To detect, prevent, and address technical issues, fraud, abuse, or security threats to our own systems
- To maintain audit and quality records of work performed, including per-engagement activity logs
- To comply with legal obligations and enforce our agreements
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use client data to train AI models — see our AI Usage Policy.
4. Legal Bases for Processing
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data on the following legal bases under the GDPR and UK GDPR:
| Purpose | Legal basis |
|---|---|
| Delivering services under a contract, operating your account, billing | Performance of a contract |
| Responding to inquiries and sales conversations you initiate | Legitimate interests, or steps taken at your request prior to a contract |
| Site security, fraud prevention, service integrity, analytics on aggregate usage | Legitimate interests |
| Non-essential cookies, marketing email, call recording where consent is required | Consent |
| Retaining engagement and financial records | Legal obligation and legitimate interests |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal. Where we rely on legitimate interests, you may object as described in the Your Rights section.
5. AI Features and Automated Processing
We operate an AI system called Lory that answers questions across our website and portals, handles some phone and email correspondence, and runs authorized penetration testing engagements. Using an AI feature means the content of that interaction is sent to a third-party model provider for inference.
- Lory always identifies itself as AI and you can ask for a human at any point in any channel.
- What is sent: conversation content, engagement context, finding text, and any personal data you include in a prompt are sent to Anthropic for inference. Call audio and spoken text are sent to ElevenLabs for speech recognition and synthesis. Inference is performed in the United States.
- Training: under our commercial agreements, data we send for inference is not used to train the providers' models, and we do not use it to train any model of our own.
- Provider-side retention of inference logs is governed by our agreements with those providers rather than by our retention schedule below.
- Redaction: secret values are stripped from tool output, logs, transcripts, and finding evidence before storage.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. AI proposes security findings; a human security engineer decides whether any finding is released to a client, and that gate is enforced in our data layer rather than by process. AI is not used for hiring, credit, insurance, or eligibility decisions.
Full detail — models used, the autonomy boundary, safety controls, and known failure modes including prompt injection — is in our AI Usage Policy.
Customers who cannot send data to a third-party model provider under any terms cannot currently use Lory; we do not offer a self-hosted deployment today, and human-only engagements are available instead.
6. Cookies and Tracking Technologies
Essential Cookies
We use essential cookies that are necessary for the basic functionality of our website. These cannot be disabled as they are required for the site to operate properly.
Analytics Cookies
With your consent, we use analytics tools (including Google Analytics and Plausible Analytics) to understand how visitors interact with our website. These tools may collect anonymized data about your browsing behavior.
Managing Cookies
When you first visit our site, you will be presented with a cookie consent banner. You can accept or decline non-essential cookies. You can change your preference at any time by clicking "Cookie Settings" in the footer of any page.
You can also control cookies through your browser settings. Note that disabling cookies may affect your experience on our website.
7. How We Share Your Information
We do not sell, trade, or rent your personal information to third parties. We may share your data only in the following limited circumstances:
- Subprocessors and service providers - Third-party vendors who process data on our behalf to operate our website, platform, and services. These providers are contractually bound to protect your information and to process it only on our instructions.
- Legal requirements - When required by law, regulation, legal process, or enforceable governmental request.
- Business transfers - In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- With your consent - We may share information for any other purpose with your explicit consent.
Current subprocessors
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic | Model inference for all Lory surfaces | Conversation content, engagement context, finding text, data included in prompts | United States |
| ElevenLabs | Speech synthesis and recognition for the voice agent | Call audio, spoken text | United States |
| Twilio | Telephony: inbound and outbound calls, call recording | Phone numbers, call audio, call metadata | United States |
| Stripe | Payments, invoicing, subscriptions, partner payouts | Billing contact details and payment metadata. Card data goes directly to Stripe and does not transit our systems. | United States |
| Microsoft (Microsoft 365 / Graph) | Email, calendar, Teams meetings, the Lory mailbox | Email content, calendar entries, meeting invitations | United States |
| Mailgun | Transactional email delivery | Recipient addresses, email content | United States |
| Linode / Akamai | Application and database hosting | All platform data | United States |
| Amazon Web Services (S3) | Compliance evidence and document storage | Uploaded compliance documents and evidence files | United States |
We give customers 30 days' notice before adding a subprocessor that processes customer data, by email to account contacts and by updating this page. Customers with a signed Data Processing Agreement may object within that window. An up-to-date list is available on request from security@lorikeetsecurity.com.
8. International Data Transfers
Lorikeet Security is based in the United States, and our infrastructure and subprocessors are located in the United States. If you are outside the United States, using our website or services means your personal data is transferred to and processed in the United States, where data protection law may differ from that of your jurisdiction.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary technical measures including encryption in transit and at rest and access controls. A copy of the relevant transfer mechanism is available on request from security@lorikeetsecurity.com.
9. Data Security
As a cybersecurity company, we take data protection seriously. We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS)
- AES-256-GCM encryption at rest for client test credentials
- Secure hosting infrastructure
- Access controls, multi-factor authentication, and least-privilege access limited to staff with a business need
- Logging of staff access to client data
- Automatic redaction of secret values from logs, transcripts, and finding evidence
- Regular security assessments of our own systems
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
Breach notification
If a breach affects your personal data, we will notify affected individuals and, where required, the relevant supervisory authority without undue delay and within the timeframes required by applicable law — within 72 hours of becoming aware, where the GDPR applies. Client notification obligations for engagement data are set out in the applicable Data Processing Agreement.
Reporting a vulnerability
If you believe you have found a security issue in our website or platform, please report it through /.well-known/security.txt or to security@lorikeetsecurity.com.
10. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. When your data is no longer needed, we securely delete or anonymize it.
| Data | Retained | Why |
|---|---|---|
| Findings (title, evidence, remediation) | Life of the client relationship plus 12 months | Retest history, trend reporting, audit evidence |
| Engagement records (scope, dates, depth, status) | 7 years | Contractual and audit record; underpins attestation letters |
| Engagement activity logs (tool calls, targets, outcomes) | 24 months | The record of what was done against a client system |
| Test credentials | Until deleted by the client, or 90 days after the last engagement using them | Highest-risk data we hold; not kept "just in case" |
| Chat transcripts (site, client portal, partner portal) | 24 months | Support history and sales context |
| Call recordings and voice transcripts | 12 months | Quality, training, and dispute resolution |
| Email threads handled by our AI agent | Per mailbox retention, currently 24 months | Business correspondence |
| Lead and contact records | Until deletion is requested | Ordinary CRM data |
| Billing and tax records | 7 years | Legal and accounting obligations |
| Website analytics | 26 months | Trend analysis |
| Aggregate quality metrics | Indefinite, aggregate form only with no client-identifying content | Measuring and improving detection quality |
| Model inference logs at Anthropic | Per our commercial agreement with Anthropic | Governed by that agreement, not by our schedule |
Test credentials are deleted immediately on request, not within the standard 30-day window, and within 7 days of a client relationship ending. There is no reason to hold a credential someone wants gone.
11. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access - Request a copy of the personal data we hold about you, and information about how it is processed
- Correction - Request correction of inaccurate or incomplete data
- Deletion - Request deletion of your personal data
- Objection - Object to our processing of your personal data, including processing based on legitimate interests
- Restriction - Request that we limit processing while a dispute about accuracy or lawfulness is resolved
- Portability - Request transfer of your data in a structured, machine-readable format
- Withdraw consent - Withdraw consent for data processing where consent was the legal basis
- Non-discrimination - Exercise these rights without being denied service, charged a different price, or given a lower quality of service
How to exercise them
Email security@lorikeetsecurity.com or support@lorikeetsecurity.com. We will:
- Acknowledge your request within 2 business days
- Verify your identity, in proportion to the sensitivity of the request
- Complete the request within 30 days, or tell you why we need longer, up to the extension permitted by applicable law
- Confirm in writing what was done
An authorized agent may submit a request on your behalf with written proof of authorization. There is no fee for a reasonable request.
What we cannot delete on request: engagement records required for our own audit and contractual obligations, records subject to a legal hold, and financial records we are required to keep. We will tell you specifically what is being retained and on what basis, rather than declining in general terms.
If you are in the EEA, the UK, or Switzerland
The rights above are those granted by the GDPR and UK GDPR. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. We ask that you contact us first so we have the chance to resolve it.
If you are in California
Under the CCPA as amended by the CPRA, you have the rights to know, delete, correct, and to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out to exercise — but you may still submit a request and we will confirm this in writing. In the preceding 12 months we collected the categories of information described in Section 2 for the purposes described in Section 3, and disclosed them for business purposes only to the subprocessors listed in Section 7. If we deny a request, you may appeal by replying to our response.
Other U.S. state privacy laws
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, and Texas — have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. We honor these requests through the same process, and we provide an appeal route if a request is denied. We do not conduct targeted advertising or profiling with legal effects.
If your data is in a client's systems
Where we process personal data as a processor on behalf of a client during a security engagement, we forward requests to that client and support them in responding. We cannot act on that data unilaterally.
12. Third-Party Links
Our website may contain links to third-party websites or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites. We encourage you to review the privacy policy of every site you visit.
13. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete that information promptly.
14. Data Processing Agreements and Security Documentation
Business customers may request a Data Processing Agreement, including the Standard Contractual Clauses where required, before an engagement begins. We also sign mutual Non-Disclosure Agreements and complete vendor security questionnaires.
Available on request from security@lorikeetsecurity.com: our Data Processing Agreement, the current subprocessor list, our AI transparency documentation, our data retention and deletion policy, and our human-in-the-loop review standard. Some of this is published on our Trust Center.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the effective date at the top. Where a change materially affects how we use your personal data, or adds a subprocessor that processes customer data, we will notify account contacts by email at least 30 days in advance. We encourage you to review this page periodically.
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Privacy, data protection, and deletion requests: security@lorikeetsecurity.com
- General support: support@lorikeetsecurity.com
- Phone: +1 (888) 652-6479
- Website: lorikeetsecurity.com/contact