This Privacy Notice for CYBEDEFEND SAS ("we," "us," or "our") describes how and why we might access, collect, store, use, and share ("process") your personal information when you use our services ("Services"), including when you:
- visit our website at our website, or any website of ours that links to this Privacy Notice
- use CybeDefend, an MCP-native Application Security Testing (AST) platform delivered as a cloud SaaS. The platform integrates Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure-as-Code (IaC) scanning, container security, and secret detection, combined with AI-powered analysis and automated remediation that runs inside the AI coding agent loop, catching logic flaws and rewriting unsafe code at agent-time, before the pull request is opened. Our compliance scope includes GDPR, NIS2, DORA, and alignment with PCI-DSS and OWASP frameworks.
- engage with us in other related ways, sales, marketing, events, or support.
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at our contact email.
Summary of key points
This summary provides key points from our Privacy Notice. Use the table of contents to jump to any section in full.
- What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us, the choices you make, and the products you use. See section 1 below.
- Do we process any sensitive personal information? No. We do not process special-category data (racial or ethnic origin, sexual orientation, religious beliefs, biometric or genetic data).
- Do we collect any information from third parties? We may collect information from public databases, marketing partners, social media platforms and other outside sources. See section 1.
- How do we process your information? To provide, improve and administer our Services, communicate with you, prevent fraud, and comply with the law. We process your information only when we have a valid legal reason. See section 2.
- In what situations and with whom do we share personal information? Only with vetted vendors, processors and authorities, as detailed in section 4 and our Subprocessors page.
- How do we keep your information safe? We have organizational and technical measures in place, see our Security page, but no electronic transmission can be guaranteed 100% secure.
- What are your rights? Depending on where you live, you may have rights of access, rectification, erasure, portability, and the right to object. See section 12 and exercise your rights here.
1. What information do we collect?
Personal information you disclose to us
In short: we collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you register on the Services, express an interest in our products, participate in activities on the Services, or otherwise contact us.
The personal information we collect may include:
- names
- email addresses
- mailing addresses
- usernames
- billing addresses
- debit/credit card numbers (handled by our payment processor, we never see the full PAN)
- contact or authentication data
- repository identifiers, organization names, and source code submitted to the platform for scanning purposes
Sensitive Information. We do not process sensitive (special-category) personal information.
Payment Data. We may collect data necessary to process your payment if you choose to make a purchase. Payment instrument numbers and security codes are handled and stored by Stripe, Inc. Their privacy notice is available at Stripe's privacy notice.
Social Media Login Data. We may provide you with the option to register using an existing social media account (e.g. Google, GitHub, Microsoft). If you choose to register this way, we will receive the limited profile information described in section 8.
All personal information that you provide to us must be true, complete and accurate, and you must notify us of any changes.
Information automatically collected
In short: some information, such as your IP address and browser characteristics, is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use or navigate the Services. This information does not directly reveal your identity but may include device and usage information such as IP address, browser and device characteristics, operating system, language preferences, referring URLs, country, location, and information about how and when you use our Services.
The information we collect includes:
- Log and Usage Data. Service-related, diagnostic, usage, and performance information our servers automatically collect, IP address, device information, browser type, settings, activity in the Services (timestamps, features used, errors), and event information (system activity, error reports, hardware settings).
- Device Data. Information about the computer, phone, tablet or other device you use, IP address (or proxy), device and application identifiers, location, browser type, hardware model, ISP and/or mobile carrier, operating system, and system configuration.
- Location Data. Location data such as approximate location derived from your IP address. We do not use precise GPS data unless you explicitly grant permission. You can opt out by refusing access on your device.
Information collected from other sources
In short: we may collect limited data from public databases, marketing partners and other outside sources.
To enhance our ability to provide relevant marketing, offers and services and to update our records, we may obtain information about you from sources such as public databases, joint marketing partners, affiliate programs, data providers, social media platforms and other third parties, typically mailing address, job title, email, phone number, intent data, IP address, and social media profile.
If you interact with us on a social media platform using your social media account, we may receive personal information such as your name, email address and gender. The way these platforms use your information is not governed by this Privacy Notice, review their own policies.
2. How do we process your information?
In short: we process your information to provide, improve and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
We process your personal information for purposes including:
- To facilitate account creation and authentication and otherwise manage user accounts.
- To deliver and facilitate delivery of services to the user.
- To respond to user inquiries and offer support.
- To send administrative information about our products, services, terms and policies, or similar.
- To fulfil and manage your orders, payments, returns and exchanges.
- To enable user-to-user communications when you choose to use offerings that allow it.
- To request feedback and contact you about your use of our Services.
- To send you marketing and promotional communications in line with your preferences. You can opt out at any time.
- To deliver targeted advertising that is relevant to your interests.
- To protect our Services, including fraud monitoring and prevention.
- To identify usage trends so we can improve the Services.
- To determine the effectiveness of our marketing and promotional campaigns.
- To save or protect an individual's vital interest when necessary.
3. Legal bases we rely on
In short: we only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law, consent, contract, legitimate interest, legal obligation, or vital interest.
If you are located in the EU or UK, the GDPR and UK GDPR require us to explain the legal bases we rely on. We may rely on the following:
- Consent, when you have given us permission for a specific purpose. You can withdraw consent at any time.
- Performance of a contract, when we need to fulfil our contractual obligations to you, including providing the Services or acting on your request prior to entering into a contract.
- Legitimate interests, when reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights. Examples include: sending users service-related updates, developing relevant content, analyzing how our Services are used, supporting marketing, diagnosing problems, preventing fraud, and improving the user experience.
- Legal obligations, when necessary for compliance with our legal obligations, such as cooperating with a law enforcement body, exercising or defending our legal rights, or disclosing your information as evidence in litigation.
- Vital interests, when necessary to protect your vital interests or the vital interests of a third party.
If you are located in Canada, we may process your information when you have given express or implied consent. In limited cases permitted by Canadian law, we may process information without consent, for fraud detection, legally required disclosures, journalism, or where the information is publicly available.
4. When and with whom we share
In short: we may share information in specific situations described below and/or with the categories of third parties listed.
Vendors, consultants, and other third-party service providers. We may share your data with vendors, service providers, contractors, or agents who perform services on our behalf and require access to do that work. We have written contracts in place with our processors. They cannot do anything with your personal information unless instructed by us, and they will not share it with any organization apart from us. They commit to protect the data they hold on our behalf and to retain it only for the period we instruct.
The categories of third parties we may share personal information with are:
- Cloud computing services (Scaleway in the EU; Google Cloud in the US)
- Self-hosted AI inference layer running open-weight Mistral models on our own EU sovereign infrastructure (no third-party AI provider — no data is sent to OpenAI, Anthropic, Google AI or any other external LLM API; see section 7)
- Affiliate marketing programs
- Ad networks
- Communication & collaboration tools
- Data analytics services
- Data storage service providers
- Finance & accounting tools
- Government entities (when legally compelled)
- Payment processors (Stripe, Inc.)
- Performance monitoring tools
- Product engineering & design tools
- Retargeting platforms
- Sales & marketing tools
- Social networks
- Testing tools
- User account registration & authentication services
- Website hosting service providers
A current list of named subprocessors is published at /legal/subprocessors and updated when material changes occur.
We may also need to share your personal information in the following situations:
- Business transfers, in connection with negotiations of any merger, sale of company assets, financing or acquisition of all or a portion of our business.
- Business partners, to offer you certain products, services or promotions.
- Other users, when you post content publicly within the Services or interact with public areas, that content may be viewable by other users and outside the Services.
5. Third-party websites
In short: we are not responsible for the safety of information you share with third parties that we may link to or who advertise on our Services, but are not affiliated with our Services.
The Services may link to third-party websites, online services or mobile applications, and may contain advertisements from third parties not affiliated with us. We do not guarantee any such third parties and will not be liable for any loss or damage caused by the use of their websites, services or applications. Any data collected by third parties is not covered by this Privacy Notice. Review their policies and contact them directly with any questions.
6. Cookies and tracking technologies
In short: we may use cookies and other tracking technologies to collect and store your information.
We may use cookies and similar tracking technologies (such as web beacons and pixels) to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences and assist with basic site functions.
We also permit third parties and service providers to use online tracking technologies for analytics and advertising, including to help manage and display advertisements, tailor advertisements to your interests, or send abandoned shopping cart reminders.
To the extent these online tracking technologies are deemed to be a "sale" or "sharing" (which includes targeted advertising as defined under applicable laws) under US state laws, you can opt out as described under section 14.
Google Analytics. We may share your information with Google Analytics to track and analyze the use of the Services. To opt out of being tracked by Google Analytics across the Services, visit Google Analytics opt-out. For more information on the privacy practices of Google, please visit the Google Privacy & Terms page.
7. AI-based products
In short: we offer products, features and tools powered by artificial intelligence, machine learning and similar technologies.
As part of our Services, we offer products, features and tools powered by artificial intelligence, machine learning and similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.
Self-hosted AI, no third-party LLM API. We do not rely on third-party AI providers (Anthropic, OpenAI, Google AI, Cohere, Mistral La Plateforme, etc.) to deliver our AI Products. Instead, CybeDefend operates its own AI inference layer using open-weight Mistral-family models that we self-host on Scaleway sovereign EU infrastructure. Customer Code, prompts and completions are processed exclusively by models we operate; no data is sent to any external AI API and nothing you submit is used to train any model, ours or anyone else's.
If a customer chooses to use an external AI coding agent (Claude Code, Cursor, Windsurf, etc.) and connects CybeDefend to it via our MCP server, that agent — operated by the customer's chosen vendor — will of course process the customer's prompts on its own infrastructure. CybeDefend has no role in that data flow other than answering the agent's calls back to our self-hosted layer.
Our AI Products are designed for the following functions:
- AI-powered static and composition analysis
- Verified automated remediation (Cybe AutoFix)
- Cross-tool correlation and prioritization (Cybe Analysis)
- AI security copilot in the IDE (Cybe Security Champion)
- MCP-native verdicts inside the AI coding agent loop
- Natural-language explanations and remediation guidance
How we process your data using AI. All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreements with our AI providers. We instruct our AI providers contractually not to use your inputs or outputs to train their general models. Our model usage is gated by least-privilege scopes.
How to opt out. You can opt out of AI-based features by:
- Logging into your account settings and updating your AI preferences
- Contacting us at our contact email
8. Social logins
In short: if you choose to register or log in to our Services using a social media account, we may have access to certain information about you.
Our Services offer you the ability to register and log in using third-party single sign-on (e.g. Google, GitHub, Microsoft). Where you choose to do this, we will receive certain profile information from the provider, typically your name, email address and profile picture, plus any information you choose to make public on that platform.
We will use the information we receive only for the purposes described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. We do not control, and are not responsible for, other uses of your personal information by your third-party provider.
9. International transfers
In short: we may transfer, store and process your information in countries other than your own.
We operate data regions in the European Union (primary) and the United States. Customers select their preferred region at signup. Our EU region is hosted in the European Economic Area (EU-resident sub-processors only, see our Subprocessors page); our US region is hosted on US infrastructure for customers who require it.
If you are accessing our Services from a region outside your selected data region, your information may be transferred to, stored by, and processed in our facilities and the facilities of our sub-processors. We have implemented appropriate safeguards including the European Commission's Standard Contractual Clauses (SCCs) for transfers of personal information between us and our sub-processors. These clauses require all recipients to protect personal information that originates from the EEA or UK in accordance with European data protection laws. Our SCCs and a current Transfer Impact Assessment can be provided upon request to our legal team.
10. How long do we keep your information?
In short: we keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). No purpose in this notice will require us to keep your personal information longer than the period for which you have an account with us, plus a short grace period for backups.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it. If this is not possible (for example, because the information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
11. How we keep your information safe
In short: we aim to protect your personal information through a system of organizational and technical security measures. See our Security page for details.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process, including encryption in transit (TLS 1.2+) and at rest, role-based access control with least privilege, separated tenancy per data region, audited deployments, and continuous internal monitoring.
However, despite our safeguards and efforts to secure your information, no electronic transmission over the internet or information-storage technology can be guaranteed to be 100% secure, and we cannot promise that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. Please access the Services within a secure environment.
12. Your privacy rights
In short: depending on your state of residence in the US or in some regions such as the EEA, the UK, Switzerland and Canada, you have rights that allow you greater access to and control over your personal information.
In some regions (such as the EEA, UK, Switzerland and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure, (iii) to restrict the processing of your personal information, (iv) where applicable, to data portability, and (v) not to be subject to automated decision-making. In certain circumstances you may also have the right to object to the processing of your personal information.
You can exercise these rights by contacting us using the details in section 16 below or via the form at /contact. We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority. In France, that authority is the CNIL (CNIL). If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent. If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us. This will not affect the lawfulness of processing before its withdrawal.
Opting out of marketing. You can unsubscribe from our marketing and promotional communications at any time by clicking the unsubscribe link in our emails or by contacting us. You will then be removed from the marketing lists. We may still communicate with you for service-related messages necessary for the administration of your account.
Account information. If you would at any time like to review or change the information in your account or terminate your account, contact us using the details below. Upon your request, we will deactivate or delete your account and information from our active databases. We may retain some information in our files to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms, and comply with applicable legal requirements.
13. Controls for Do-Not-Track features
Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honouring DNT signals, we do not respond to them at this time.
14. Do United States residents have specific privacy rights?
In short: if you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.
Categories of personal information we collect. In the past twelve (12) months we may have collected the following categories of personal information:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Real name, alias, postal address, telephone, IP address, email, account name | YES |
| B. Personal information (Cal. Customer Records statute) | Name, contact, financial information | YES |
| C. Protected classification characteristics | Gender, age, demographic data | NO |
| D. Commercial information | Transaction information, purchase history, payment information | YES |
| E. Biometric information | Fingerprints, voiceprints | NO |
| F. Internet or other similar network activity | Browsing history, search history, online behavior, interactions with our Services and applications | YES |
| G. Geolocation data | Approximate device location (from IP) | YES |
| H. Audio, electronic, sensory, or similar information | Images, audio, video or call recordings | NO |
| I. Professional or employment-related information | Business contact details, job title, work history | YES |
| J. Education information | Student records, directory information | NO |
| K. Inferences drawn from collected personal information | Profile or summary about preferences and characteristics | YES |
| L. Sensitive personal information | (See section 1, we do not process special categories) | NO |
Sources of personal information. Learn more in section 1.
How we use and share personal information. Learn more in section 2 and section 4. Categories of third parties we may share with are listed in section 4 and on our Subprocessors page.
Will your information be shared with anyone else? We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" of your personal information.
In the preceding twelve (12) months we may have disclosed personal information to the categories of third parties listed in section 4 for a business or commercial purpose.
We do not sell or share your personal information for cross-context behavioral advertising purposes as those terms are defined under California's CCPA / CPRA.
Your rights. You have rights under certain US state data protection laws. These rights are not absolute and we may decline your request as permitted by law. They include:
- Right to know whether we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies
- Right to request deletion of your personal data
- Right to obtain a copy of the personal data you previously shared
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data for targeted advertising, sale, or profiling that produces legal or similarly significant effects
Depending on the state where you live, you may also have rights to access categories of personal data being processed (Minnesota), to obtain a list of the categories of third parties to which we have disclosed personal data (California, Delaware, Maryland), to obtain a list of specific third parties (Minnesota, Oregon), to review and correct profiling (Minnesota), to limit use and disclosure of sensitive personal data (California), or to opt out of biometric processing (Florida).
How to exercise your rights. Email us at our contact email, visit /contact, or refer to the contact details below. You can opt out from selling, targeted advertising or profiling by disabling cookies in your Cookie Preference Settings. We will honour your opt-out preferences if you enact the Global Privacy Control (GPC) opt-out signal on your browser.
Authorized agents. Under certain US state data protection laws, you can designate an authorized agent to make a request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf.
Request verification. Upon receiving your request, we will need to verify your identity. We will only use personal information provided in your request to verify your identity or authority. If we cannot verify your identity from the information already maintained by us, we may request additional information for verification and security or fraud-prevention purposes.
Appeals. Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at our contact email. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation. If your appeal is denied, you may submit a complaint to your state attorney general.
California "Shine The Light" Law. California Civil Code Section 1798.83 permits California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. To make such a request, please write to us using the contact details below.
15. Updates to this notice
In short: yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes, we may notify you either by prominently posting a notice or by directly sending you a notification. We encourage you to review this Privacy Notice periodically to be informed of how we are protecting your information.
16. How to contact us about this notice
If you have questions or comments about this notice, you may email us at our contact email or contact us by post at:
CYBEDEFEND SAS 177 Allée Clémentine Deman 59000 Lille, France
For data-protection-specific requests, you can also write to our legal team.
17. How to review, update or delete the data we collect
Based on the applicable laws of your country or state of residence, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing. These rights may be limited in some circumstances by applicable law. To request to review, update or delete your personal information, please write to us at our contact email or fill out the form at /contact.
Table of contents
- 01Summary of key points
- 021. What information do we collect?
- 032. How do we process your information?
- 043. Legal bases we rely on
- 054. When and with whom we share
- 065. Third-party websites
- 076. Cookies and tracking technologies
- 087. AI-based products
- 098. Social logins
- 109. International transfers
- 1110. How long do we keep your information?
- 1211. How we keep your information safe
- 1312. Your privacy rights
- 1413. Controls for Do-Not-Track features
- 1514. Do United States residents have specific privacy rights?
- 1615. Updates to this notice
- 1716. How to contact us about this notice
- 1817. How to review, update or delete the data we collect