XSEECloud attack intelligence
PlatformEnginesWhy UsFree ScanDemoPricingContact
All systems operational
Under Attack?Sign in
Get a demoStart Free Trial →Launch App
PlatformEnginesWhy UsFree ScanDemoPricingContact
LEGAL · PRIVACY POLICY

Privacy Policy

Last updated: March 26, 2026
On this page
1Introduction2Data We Collect3How We Use Data4AI Processing5Legal Basis6Data Sharing7International Transfers8Your Rights9Retention10Security11Cookies12Children13Contact
Other legal pages
Terms of ServiceRefund Policy
1

Introduction

This Privacy Policy explains how XSEE ("we," "us") collects, uses, discloses, and protects information when you use our website, products, and services (collectively, the "Service").

By using the Service, you agree to this policy. If you do not agree, please do not use the Service.

2

Data We Collect

Account Information

  • Name, email address, and company name
  • Billing details processed securely by our payment partner Paddle (we do not store full card numbers)

Usage Data

  • Scan results, feature usage, and product analytics
  • Technical logs (e.g. IP, user agent) for security and reliability

AWS Scan Data

  • Asset metadata, IAM structure, and network topology as observed via read-only access
  • Attack-path analysis outputs derived from that metadata
We NEVER read file contents, database records, or S3 object contents as part of our standard read-only AWS integration. We work from metadata and API-validated signals described in our Security documentation.
3

How We Use Data

We use information to:

  • Provide, operate, and improve the Service
  • Authenticate users, prevent fraud, and secure our platform
  • Communicate about the Service, billing, and policy updates
  • Comply with legal obligations and enforce our terms
4

AI Processing

When you use AI-powered features, structured security metadata from your scan (attack paths, validation results, asset types, risk scores) is sent to Anthropic's Claude API to generate explanations and summaries. This data does not include raw file contents, database records, passwords, or credentials. Anthropic's privacy policy applies to data processed through their API. We do not use your data to train AI models.

5

Legal Basis (EEA/UK)

Where GDPR or UK GDPR applies, we rely on appropriate bases such as: performance of a contract, legitimate interests (e.g. securing the Service, product improvement, provided we balance your rights), consent where required, and legal obligation.

6

Data Sharing & Processors

We do NOT sell your data. No advertising partners. Ever.

We share data only with:

  • Payment processing: Paddle (merchant of record) for subscriptions, invoicing, and tax compliance as applicable.
  • Infrastructure providers: e.g. cloud hosting and database services under strict agreements.
  • Professional advisors or authorities when required by law or to protect rights and safety.
7

International Transfers

We may process data in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for transfers from the EEA, UK, or Switzerland.

8

Your Rights

Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing or withdraw consent where processing is consent-based.

AccessCorrectDeleteExportOpt-out of marketing

To exercise rights, contact sales@xsee.io. You may also lodge a complaint with your local supervisory authority.

9

Retention

We retain personal data as long as needed to provide the Service, meet legal, tax, and accounting requirements, and resolve disputes. Scan-related outputs are retained according to your plan and account settings, and as described at account closure.

10

Security

We implement technical and organizational measures designed to protect data, including encryption in transit, access controls, and organizational isolation. See our Security page for an overview.

11

Cookies & Similar Technologies

We use cookies and similar technologies for essential site operation, preferences, analytics, and (where applicable) security. You can control cookies through your browser settings; some features may not work if essential cookies are disabled.

12

Children

The Service is not directed to children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal data from children. Contact us if you believe we have done so in error.

13

Contact

Privacy inquiries: sales@xsee.io

For payment data handled by Paddle, you may also exercise rights through Paddle as described in their privacy policy and your checkout experience.

Questions about this policy?

Our team responds within 2 business days.

sales@xsee.io
Terms of ServicePrivacy PolicyRefund Policy
XSEECloud Attack Intelligence

Discover. Validate. Simulate. Fix. Certify. Built for the age of AI attackers.

Security & Trust →
SOC 2 Type II (in progress)CSA STAR (in progress)GDPR CompliantAWS HostedBuilt on Anthropic Claude
All Systems Operational
Product
How It WorksEnginesPricingChangelogFree ScanUnder Attack?vs. Wiz
Company
AboutSecurity & TrustBlogCareersContactsales@xsee.io
Resources
DocumentationAPI ReferenceStatusTermsPrivacyRefunds
© 2026 XSEE. All rights reserved.
TermsPrivacySecurity & TrustRefunds
v1.4.0 · All systems operational