Privacy Policy

Effective date: September 20, 2026

This Privacy Policy describes how Melcosoft LLC, a Colorado limited liability company, operating the CVE.GMBH platform ("CVE.GMBH", "we", "us"), collects, uses, discloses, and protects information in connection with the CVE.GMBH external attack-surface analysis service (the "Service").

The Service is offered for use within the United States only. By creating an account or otherwise using the Service, you agree to the collection and use of information as described in this Policy.

1. Information We Collect

Account information: name, first and last name, email address, password (stored as a salted hash, never in plaintext), role, and — where you provide it — your organization's legal name and registered address.

Target and scan data: the domains, IP addresses, and IP ranges you submit for analysis; results of passive reconnaissance (DNS, Certificate Transparency, WHOIS/RDAP, reverse-DNS) and, once authorized, active scan results (open ports, service banners, matched CVEs, CVSS/EPSS/KEV data); service preview captures you request (screenshots of authorized hosts).

Authorization and attestation records: when you attest ownership of a target or sign a consent to automatic re-authorization, we record the full text you signed, a cryptographic hash of that text, your account email and name, the IP address and browser user-agent from which you signed, and the date and time. These records exist specifically so that responsibility for a scan can be verified later, including in response to a law-enforcement inquiry or a complaint from a third party — see Section 5.

Encrypted credentials you choose to provide: your own AI provider API key or Cloudflare API token, if you enable those integrations. These are encrypted at rest and are never logged or displayed in full.

Audit and usage data: an append-only log of security-relevant actions on your account (target submissions, authorization checks, scan starts/results, report generation, access to findings), together with timestamps and the acting user.

Technical data collected automatically: IP address, browser and device information, and session cookies used solely to keep you signed in. We do not use third-party advertising trackers.

Payment information (once billing is enabled): processed by a third-party payment processor. We do not store full payment card numbers ourselves.

2. How We Use Information

To provide the Service: operate your account, run the analyses you request, generate reports, and provide AI-assisted remediation guidance for findings in your account.

To operate the authorization gateway: verify that you own or are authorized to scan a given target before any active scan runs, and to maintain the attestation/consent records described above.

To secure the Service: detect abuse, enforce rate limits, investigate suspected violations of the Terms of Service, and maintain the audit log.

To communicate with you about your account, security notices, and (only if you opt in) product updates.

To comply with legal obligations, including responding to lawful requests from government or law-enforcement authorities.

3. How We Share Information

We do not sell your personal information.

Service providers: we share limited data with providers that help us operate the Service, including AI processing (submitted findings data is sent to the AI provider that powers this feature, under that provider’s data-processing terms, and is not used to train that provider’s models; if you configure your own AI API key in Settings, that data goes to the provider you selected instead), public DNS/WHOIS/RDAP/certificate-transparency lookup services, IP geolocation (processed locally against an offline database, not sent to a third party), and — only for organizations that connect it themselves — the Cloudflare API.

Legal disclosures: we may disclose information, including attestation and consent records, in response to a valid subpoena, court order, or other lawful request, or where we believe in good faith that disclosure is necessary to prevent harm, investigate a suspected violation of law (including the Computer Fraud and Abuse Act), or protect the rights, property, or safety of CVE.GMBH, our users, or the public.

Business transfers: if we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction, subject to this Policy.

4. Data Retention

Audit log entries and authorization/attestation/consent records are retained indefinitely as an append-only record, even if the underlying target or account is later deleted, because they may be needed to establish who was responsible for a given scan.

Scan results and findings are retained for the life of your account and for a reasonable period after deletion for legal and audit purposes, consistent with our internal data retention policy.

You may request deletion of your account; this removes it from active use but does not remove append-only audit and authorization records described above.

5. Why We Keep Authorization Records

Active scanning of a computer system without authorization can be a federal crime in the United States under the Computer Fraud and Abuse Act. CVE.GMBH requires every user to affirmatively attest ownership or written authorization before we scan a target, and we keep a durable, hash-verified record of that attestation, including the signer's identity, IP address, and the exact text agreed to.

These records let us — and, where legally compelled, courts or law-enforcement authorities — verify after the fact who represented that a scan was authorized and on what basis. This protects legitimate users and helps us respond responsibly if a scan is ever challenged.

6. Security

We encrypt sensitive credentials (your own AI/Cloudflare API keys) at rest using AES-256-GCM, and we never store passwords in plaintext. Traffic to the Service is encrypted in transit (TLS). Access to findings and scan data is scoped to your organization's account and is not visible to other customers.

No system is perfectly secure, and we cannot guarantee absolute security.

7. Your Choices and Rights

You can review and update your account and organization information at any time in Settings. You may request a copy of your data or deletion of your account by contacting [email protected], subject to the retention described in Section 4.

Depending on your state of residence, you may have additional rights under state privacy law; we will honor applicable requests as required by law.

8. Children's Privacy

The Service is not directed at, and is not intended for use by, anyone under 18 years of age. We do not knowingly collect information from children.

9. United States Only

The Service is designed for use within the United States. If you access it from elsewhere, you do so at your own risk and consent to your information being processed in the United States.

10. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new effective date; material changes will be highlighted.

11. Contact Us

Questions about this Policy can be sent to [email protected].

The Service is operated by Melcosoft LLC, a Colorado limited liability company (Colorado entity ID 20238101618). Legal notices may be sent to [email protected]; our registered address is provided on request at the same address.