Skip to content
Lyratasecurity
What we testOur approachInsightsTrust
Let’s talk
What we testOur approachInsightsTrustLet’s talk
HomePrivacy policy
YOUR INFORMATION, HANDLED WITH CARE

Privacy policy

Effective and last updated: October 5, 2026

ON THIS PAGE1. Information we receive2. How we use information3. Service providers and sharing4. Cookies and analytics5. Retention and security6. Your choices and rights7. International processing8. Client assessment information9. Children10. Updates and contact

This policy describes personal information connected with the Lyrata Security website at lyratasecurity.com and inquiries sent to our team. Client assessment data is handled under the applicable engagement agreement.

1. Information we receive

When you contact us by email, we receive the information you choose to send, such as your name, email address, company, project description, and related correspondence.

The inquiry form prepares a draft locally in your browser. It does not submit its fields to a website server, store them in browser storage, or add them to a mailing list. If you choose to send the prepared email, your email provider transmits it and we receive it through our email service.

Our hosting and security providers may process technical request information to deliver and protect the website, such as an IP address, requested URL, time of request, browser information, and security events.

InformationHow it is receivedPurpose
Contact and project detailsEmail you choose to sendRespond to your inquiry and discuss services
Technical request informationHosting and security infrastructureDeliver, maintain, and protect the website
Follow-up correspondenceCommunications with our teamManage the conversation and relevant business records

2. How we use information

We use information to respond to requests, discuss potential engagements, communicate about services, maintain relevant business records, and protect the website and our communications.

Where a legal basis is required, the applicable basis depends on the activity. It may include taking steps at your request before an agreement, performing an agreement, our legitimate interests in business communications and security, complying with legal obligations, or consent where needed.

We do not use the inquiry form to enroll you in marketing emails. We do not sell personal information or use website data for targeted advertising.

3. Service providers and sharing

Service providers supporting hosting, email, and security may process information needed for those services. The public website is designed for hosting on Cloudflare. Cloudflare’s processing is also described in its privacy policy.

We may disclose information when required by law, to protect legal rights or security, or in connection with a business reorganization subject to appropriate protections. We do not publish your inquiry or share it as a customer testimonial without your permission.

Links to other websites are subject to those websites’ policies. This policy does not control an external service you choose to use.

4. Cookies and analytics

This website does not include advertising trackers, third-party analytics scripts, or application cookies. Fonts and visual assets are served with the site rather than loaded from third-party font or image services.

Hosting or security infrastructure may use necessary mechanisms to operate and protect the service. If optional analytics or tracking is added, we will update this policy and provide choices where required before using those technologies.

5. Retention and security

We retain inquiry correspondence only for as long as needed for the conversation, relevant business purposes, and applicable legal obligations. Retention of technical request information depends on the hosting or security service and its configured practices. Client engagement retention is defined separately.

We use appropriate safeguards for information we handle, but no method of transmission or storage guarantees absolute security. Please do not include credentials, sensitive customer data, or vulnerability evidence in an initial inquiry. We can agree on a suitable channel for sensitive assessment material.

6. Your choices and rights

You can contact us directly without using the draft form. You can also ask us to correct or delete information you have sent, subject to information we need to retain for legitimate or legal purposes.

Depending on where you live and the law that applies, you may have rights to access, correct, delete, or receive a copy of your personal information, restrict or object to processing, or withdraw consent where processing depends on consent. You may also be able to complain to a relevant privacy regulator.

Send requests to [email protected]. We may need to verify your identity before fulfilling a request, and will respond as required by applicable law. We will not treat you adversely for exercising an applicable privacy right.

7. International processing

Our service providers may process information in countries other than your own. Where applicable law requires protections for international transfers, the relevant contractual or other lawful safeguards must apply. Contact us with questions about processing relevant to your inquiry or engagement.

8. Client assessment information

Systems, credentials, technical evidence, and personal data encountered during an assessment require engagement-specific handling. The written agreement defines authorized access, confidentiality, approved tools and providers, retention, deletion, and any necessary data protection terms.

The website inquiry is not an approved channel for submitting assessment data. Contact us first to agree on how it will be shared.

9. Children

This website is intended for business users and is not directed to children under 16. We do not knowingly solicit personal information from children. If you believe a child has sent us personal information, contact us so we can address it.

10. Updates and contact

We may update this policy when our website or information practices change. The effective date at the top identifies the current version. Questions and privacy requests can be sent to [email protected].

Lyratasecurity

Confidence in what you build.
Clarity in how you protect it.

[email protected]
ExpertiseSaaS penetration testingAI adversarial testingOur methodology
ExploreSecurity insightsTrust & practicesStart a conversation
Depth. Rigor. Clarity.

Thorough testing.
Findings you can act on.

Built on OWASP guidance
© 2026 Lyrata Security
Terms of servicePrivacy policyFramework alignment
Test deeper. Build stronger.