Privacy Policy
One policy for three surfaces: this website, the netvuln-tool scanner you run on your own infrastructure, and the Bullium collection portal. In short: scan data stays with you unless you send it to us, no cookies on this site, and no data sales.
Last updated: August 2026
Scan Data Stays Local
The scanner runs entirely on your infrastructure. Nothing leaves your systems unless you configure an outbound connection.
No Cookies on This Site
netvulntool.com sets no cookies. Analytics are cookieless and aggregate-only via Plausible.
No Data Sales
We never sell or share your information with advertisers, on any surface.
Bullium Consulting LLC ("we," "us," or "our") operates the website netvulntool.com, builds the netvuln-tool network scanner, and runs the collection portal at portal.netvulntool.com/collect. This one policy covers all three surfaces, and each section says which surface it applies to. The short version: scan results are generated on your systems and belong to you. We only receive them if you choose to upload them to the portal.
What This Policy Covers
- The website: this marketing and pricing site, including the contact form on the pricing page and the installation booking form
- The scanner: the netvuln-tool software (Apache-2.0 core) you install and run on your own infrastructure
- The collection portal: the optional portal at portal.netvulntool.com/collect where you can upload scan sessions for centralized reporting
Scan output is generated on your systems and stored on your systems. We process uploaded results on your behalf only after you upload them. Information you submit through the contact form is given directly to us.
The Website (netvulntool.com)
Information You Provide
When you submit the contact form on our pricing page, you voluntarily provide:
- Your name
- Your work email address
- The tier or option you are interested in
- Any message you write describing what you want to assess
We use those details only to respond to your inquiry, discuss the tier or option you asked about, and provide onboarding and a license key if you decide to proceed. We do not add you to a marketing list from a contact-form submission, and we do not use your message for any purpose other than replying to you.
Installation Booking
The installation booking page collects the entitlement token from your invoice, your name, work email, an optional phone number, the fleet details you enter (node count, site count, and target networks), your chosen appointment time, and the timezone your browser reports. Booking requests are sent to the netvuln-portal booking service, operated by Bullium Consulting, to check open times and confirm your appointment.
Confirming a booking creates an appointment on our technician's Google Calendar, opens a service ticket in Syncro to track delivery of the session, and sends you a confirmation email through Resend with the appointment details and a link to manage it. See Third-Party Services below for what each of these processors receives.
What We Do Not Collect
- We do not run tag managers, advertising pixels, or session-recording scripts on this site
- We do not set tracking cookies or persistent identifiers
- We do not engage in cross-site or cross-device tracking
- We do not sell, rent, or share personal information with third-party advertisers
- Our only measurement is Plausible Analytics, which is cookieless and aggregate-only (see Third-Party Services below)
The Scanner (netvuln-tool)
What a Scan Collects (Stored on Your Systems)
- Host inventory: IP addresses, hostnames, MAC addresses, OS guesses, open ports and services
- Vulnerability findings with supporting evidence, which can include service banners, certificate details, and any default SNMP community strings a device accepted
- DNS and WHOIS records for the domains you assess
- Session metadata: session id, target, assessor username, client name, and client id
The scanner does not capture passwords from the systems it assesses. Results are
stored under ~/netvuln-tool/sessions/
on the machine that ran the scan, under the account that ran it; the scan pipeline
applies owner-only permissions (modes 700 and 600) to the session directories and
files it manages. You control retention: completed scan results are never deleted
automatically, and the tool removes only temporary working files at the end of a run.
No Telemetry, and You Control Every Connection
The scanner has no telemetry, no analytics beacon, and no automatic update check. One outbound feature is enabled by default: CVE enrichment, which sends bare CVE identifiers and never scan data, and which you can turn off with a single flag. Every other outbound connection listed below exists only when you configure it.
Outbound Connections and How You Control Them
- CVE enrichment (on by default): sends bare CVE identifiers, and no scan data, to NVD, MITRE, and cvedetails.com to enrich findings; requests carry only the CVE id and the tool's user-agent string; disable with the
--no-cve-lookupflag - Portal upload (off until configured): sends the session results JSON, and optionally the pipeline log and HTML reports, to the portal URL you configured, authenticated with your license key; uploads are capped at 25 MB
- License validation (runs when a portal is configured): the scanner checks your license once per pipeline run; the local cache stores only a SHA-256 fingerprint prefix of the key, never the key itself
- Agent heartbeat (agent mode only): reports its agent id, tool version, schedules, client id, and a system profile covering OS, hostname, hardware (CPU, memory, disk), network interfaces and internal IP addresses, DNS resolver, installed scan-tool versions, scanner configuration, and a public IP address obtained from ifconfig.me; it also probes 1.1.1.1 to test connectivity, and on the Business tier and up, heartbeat responses can carry command-dispatch instructions from the portal
- Alert notifications (off until configured): Slack, webhook, or email destinations you configure receive the target and risk metadata, not the full finding set
The scanner never logs your license key, and its validation cache stores only a
SHA-256 fingerprint prefix. The key itself lives in
~/.netvuln/license.key
(and optionally your scan configuration) with owner-only file permissions.
The Collection Portal
What We Store and Where
- Structured session metadata (session id, client name and id, target, assessor, risk scores and summaries, share token) in a Neon PostgreSQL database, connected over TLS
- Uploaded files (the full results JSON, pipeline log, HTML report, and executive summary) in Netlify Blobs storage
Tenant Isolation
- Every session uploaded with a license key is stamped with that key's client id: the license key is the tenant boundary
- Portal users sign in with Netlify Identity; accounts are provisioned with either administrator scope or a restricted set of client ids, and restricted accounts can list, download, and delete only sessions for their own client ids
- License management requires administrator scope
License Keys and Share Links
- License keys are stored only as a SHA-256 hash plus a short lookup prefix and compared with timing-safe checks; the full key is shown once at creation and cannot be retrieved afterward
- Report share links use unguessable 64-character random tokens and are served with no-store caching
Third-Party Services
We use a small set of infrastructure providers to run these services. We do not sell, rent, or share your data with advertisers or data brokers, on any surface.
Netlify
Hosts this website and the portal, processes contact-form submissions, runs the portal's backend functions, stores uploaded report files (Blobs), and handles portal sign-in (Identity). Netlify receives standard server-request data (such as your IP address) and stores the details you submit through the form or upload to the portal. See the Netlify Privacy Policy.
Neon
Hosts the portal's PostgreSQL database, which stores the session metadata described above. Connections to the database require TLS. See the Neon Privacy Policy.
Plausible Analytics
We use Plausible Analytics, a privacy-first, open-source analytics tool, to count page views on this website and see which pages are useful. Plausible does not use cookies and does not store personal data: it derives a hash from your IP address and browser user agent that rotates daily, so visits cannot be profiled over time or across sites. We see aggregate counts only, never individual visitors. See the Plausible Data Policy.
Google Fonts
We load the Inter typeface from Google Fonts, which means your browser requests font files from Google and Google receives your IP address as part of that request. No cookies are set for this. See the Google Privacy Policy.
Google Calendar
When you confirm an installation booking, our technician's Google Calendar receives the appointment: your name, email, and the session time. See the Google Privacy Policy.
Syncro
Confirmed installation bookings open a service ticket in Syncro, our service-ticketing platform, carrying your contact details and the fleet information you submitted so we can deliver the session. See the Syncro Privacy Policy.
Resend
Installation booking confirmation and manage-appointment emails are delivered through Resend, our email delivery provider, which processes your name, email address, and appointment details to send those messages. See the Resend Privacy Policy.
Scanner Endpoints You Control
The scanner reaches a small set of public endpoints; each can be turned off:
- NVD, MITRE, and cvedetails.com receive bare CVE identifiers only, never scan data (CVE enrichment is on by default; disable with
--no-cve-lookup) - ifconfig.me (public IP lookup) and 1.1.1.1 (connectivity probe) are reached in agent mode only
- Alert destinations (Slack, webhooks, email) are ones you configure yourself
Data Retention and Deletion
- The website: contact-form submissions are retained as long as needed to respond to your inquiry and, if you become a customer, to support your account; you can ask us to delete your submission at any time
- The scanner: results live on your systems and you control retention entirely; completed scan results are never deleted automatically (only temporary working files are cleaned up at the end of a run)
- The portal: session data and uploaded reports are retained until deletion is requested or performed; deletion is a deliberate two-step action (archive, then delete) that removes the database records and the stored files, and portal audit events have a 90-day retention target after which older events are pruned
Uploaded reports are not deleted automatically. The 30-day report validity shown in the portal is a freshness indicator, not a deletion mechanism.
Your Rights and Choices
You may:
- Request access to the information we hold about you
- Request correction or deletion of that information
- Ask what we have done with a contact-form submission
- Request deletion of any session your organization uploaded to the portal
Portal tenant scoping means users only ever see sessions for their own organization, and every outbound scanner connection is a configuration choice you can turn off.
Because this website sets no cookies and its analytics are cookieless and aggregate-only, there is no consent banner to manage.
Data Security
- The website: served only over HTTPS with HTTP Strict Transport Security, a strict Content Security Policy, X-Frame-Options, X-Content-Type-Options, a Referrer-Policy, and a Permissions-Policy; no payment or credential data is collected on this site
- The scanner: the scan pipeline applies owner-only permissions (modes 700 and 600) to the session directories and files it manages; the scanner never logs your license key, and its validation cache stores only a SHA-256 fingerprint prefix
- The portal: all transport uses HTTPS/TLS, including the database connection; license keys are stored as SHA-256 hashes and compared timing-safely; share tokens are unguessable and served with no-store caching; access is role-scoped per tenant
Stored data resides on Netlify and Neon infrastructure and relies on those providers' platform encryption.
Children's Privacy
This site and its services are directed at businesses, not children under 13, and we do not knowingly collect information from children. If you believe a child has submitted information, contact us and we will delete it promptly.
Changes to This Policy
We may update this policy from time to time. Changes are posted on this page with an updated revision date. Please review it periodically.
Contact Us
For any question about this policy or your information, contact us at:
Bullium Consulting LLC