Privacy Policy
Last updated: 5 October 2026
This policy explains how CVESignal handles information when you visit the site or use an account. CVESignal is the service name. For privacy questions, contact support@cvesignal.com.
Information we handle
When you create or use an account, we handle your name and email address, a password hash, your organisation and role, and account security details such as session identifiers. We also store the products and versions your organisation chooses to monitor, related alerts and their status, and any comments or activity recorded by members.
If an organisation invites you, we handle the invited email address and invitation details. If you contact support, we handle the information you include in your message.
Your browser receives an essential session cookie when you sign in. The app also uses browser local storage to cache basic profile and organisation details so the interface can load promptly. You can clear this storage in your browser; signing out clears the app’s profile cache.
How we use information
We use this information to create and secure accounts, verify email addresses, send account and invitation emails, provide monitoring and alerts to your organisation, keep an activity history, respond to support requests, and maintain and protect the service.
Do not put passwords, access tokens, or other secrets in alert comments or support messages.
Where information comes from
We collect account, organisation, monitoring, and comment information from you and other members of your organisation. The service also retrieves public vulnerability and security news information from sources such as CISA, NVD, and security news feeds. Those scheduled requests are made by the service and do not include your account details or selected products.
Service providers and international handling
CVESignal uses Cloudflare to run the application and store account and organisation data, and Resend to deliver verification and invitation emails. Email addresses and the contents of those transactional emails are sent to Resend. Resend states that stored data is held in the United States; its sending region does not change that storage location. Cloudflare D1 database location depends on its configuration, so your data may be handled outside your country.
We may also disclose information if required by law or when reasonably necessary to protect the service, its users, or their rights. We do not sell personal information.
Storage and security
Account information is stored in Cloudflare D1. Passwords are stored as salted password hashes rather than readable passwords. Sign-in sessions use secure, HTTP-only cookies. We use service-provider security controls, but no online service can guarantee absolute security.
Retention and deletion
We keep account information while the account is active. You can request deletion from the account menu. Deleting an account removes that user’s account and sign-in sessions. If the organisation continues, organisation-level monitored products and alerts remain available to its other members. Some activity records may remain without the deleted user’s identity. Provider logs and backups may persist for periods controlled by those providers or required for security and legal purposes.
Verification codes expire after 10 minutes, and inactive sign-in sessions expire after one hour.
Access, correction, and questions
You can ask to access or correct your personal information, or raise a privacy concern, by emailing support@cvesignal.com. We will review and respond to your request. If Australian privacy law applies to you and your concern is not resolved, you may be able to complain to the Office of the Australian Information Commissioner.
Changes to this policy
We may update this policy as the service changes. We will publish the current version here and update the date above.