1. Scope
This Privacy Policy describes how LawKade Security ("LawKade," "we," "us," or "our") collects, uses, stores, and protects personal information in connection with our corporate website at lawkadesecurity.com and the ARGUS platform. It applies to website visitors, contact form submitters, assessment request submitters, and authorized platform users.
2. Data we collect
Contact and inquiry data: When you submit a contact form or assessment request, we collect your name, email address, organization, role, and the content of your message. This data is used to respond to your inquiry and, if an engagement follows, to establish the engagement record.
Account data: For authorized ARGUS platform users, we collect your name, email address, role within your organization, and a bcrypt-hashed password. We do not store plaintext passwords.
Session data: When you log in to the platform, we create a server-side session. Session identifiers are stored in a HttpOnly, Secure, SameSite=Lax cookie. Sessions expire after a defined period of inactivity.
Server logs: Our servers log standard request metadata — IP address, timestamp, HTTP method, URL path, and response status code — for operational and security purposes. Logs do not contain credentials, session tokens, or request body content.
Engagement data: Authorized platform users interact with engagement data including findings, evidence, assets, and reports associated with their organization's engagement. This data is scoped to the user's organization and is not accessible to other tenants.
3. Purpose and legal basis
We process personal data to:
- Respond to contact and assessment inquiries
- Provision and manage authorized platform accounts
- Deliver security assessment services under an engagement agreement
- Maintain the security and integrity of our systems
- Comply with applicable legal obligations
4. Data retention
Contact and inquiry data is retained for up to twenty-four (24) months from the date of your last communication with us. If an engagement follows, it becomes part of the engagement record and is retained under the engagement retention terms below.
Account data is retained for the duration of the user's authorized access. When an account is deactivated, account data is deleted within ninety (90) days, except where a longer period is required by law or by the terms of an active engagement agreement.
Server logs are retained for ninety (90) days for security and operational purposes, after which they are deleted or anonymized.
Engagement data — findings, evidence, and reports — is retained according to the data-retention terms agreed in the engagement agreement. Absent contrary contractual terms, engagement data is retained for three (3) years following engagement close to support re-testing, dispute resolution, and legal obligations, after which it is securely deleted or returned to the client per the agreed procedure.
5. Evidence handling
Evidence collected during a security engagement is stored with SHA-256 hash verification and chain-of-custody documentation. Evidence is never placed in publicly accessible storage. Access to evidence requires authentication and generates an audit event.
We treat engagement evidence as highly sensitive. It is scoped to the originating organization's tenant and is not accessible to any other user or organization on the platform.
6. Data sharing
We do not sell personal data. We do not share personal data with third parties for marketing purposes.
We use a limited number of service providers — cloud hosting and database infrastructure — who process data on our behalf under data processing agreements. These providers are not permitted to use your data for their own purposes.
We may disclose personal data where required by applicable law, court order, or to protect the safety and integrity of our systems or users.
7. Security controls
We implement technical controls including bcrypt password hashing, HttpOnly session cookies, CSRF protection, rate limiting, role-based access control, and tenant isolation. No security measure is absolute. If you discover a security issue in our systems, see our Responsible Disclosure Policy.
8. Cookies
The public website does not use tracking cookies, advertising cookies, or analytics cookies.
The ARGUS platform uses a single functional session cookie (HttpOnly, Secure, SameSite=Lax) to maintain your authenticated session. This cookie is necessary for platform operation and is not used for tracking.
9. International data transfers
Our systems are hosted in the United States. If you access our website or platform from outside the United States, your personal data will be transferred to, stored in, and processed in the United States.
Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards under applicable law, including the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures such as encryption in transit and at rest and strict access controls. A copy of the relevant safeguards may be requested via the contact method in Section 11.
10. Your rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your data, subject to legal and contractual retention obligations
- Restriction and objection — request that we limit or stop certain processing
- Portability — receive your data in a structured, commonly used, machine-readable format
- Non-discrimination — under the CCPA, we will not discriminate against you for exercising your rights; we do not sell or share personal information as defined by the CCPA
We will verify and respond to requests within thirty (30) days (or the shorter period required by applicable law, such as 45 days under the CCPA with permitted extensions). If we refuse a request, we will explain why and how to appeal.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your local supervisory authority.
11. Contact
For privacy-related questions or to exercise your data rights, use our contact form and indicate that your inquiry is privacy-related.