Privacy Policy

Last updated: September 13, 2026

Overview

This Privacy Policy explains what information SetEnforce collects when you use our domain security validation platform, why we collect it, how long we keep it, and the choices and rights you have over it. This is a first-pass policy for review, written in plain language, and covers every cookie and third-party request the site actually makes, nothing more.

Information We Collect

  • Account information. If you register for an account, we store your username, email address, and a securely hashed password. We do not store your password in plain text.
  • Login IP address. When you sign in, we record the IP address used for that login.
  • Scan and domain data. When you run a validation, we process the domain name you submit and store the resulting compliance results (RPKI, DANE, DNSSEC, Email Security, and Web Security findings) so you can view your history and download reports.

Cookies We Use

SetEnforce uses only strictly-necessary cookies required to keep you signed in and to protect your account. We do not use any advertising, analytics, or tracking cookies: no analytics script of any kind runs on this site.

Cookie Purpose HttpOnly
access_token Session JWT, the auth carrier for the web UI Yes
csrf_token CSRF double-submit token No (JS-readable)
oauth_state CSRF state nonce during Google/GitHub OAuth sign-in Yes

All three cookies are marked secure in production, use samesite=lax, and are scoped to path=/. Because these cookies are strictly necessary for the service to function, we show a small notice about them rather than a consent banner: there is nothing optional to opt out of.

Third-Party Services

A small number of pages load resources from third-party content delivery networks. These requests may expose your IP address and browser information to those providers, in line with their own privacy policies. No analytics or advertising service is used anywhere on the site.

  • Font Awesome (cdnjs.cloudflare.com), loaded on every public page to render icons.
  • Cloudflare Turnstile (challenges.cloudflare.com), loaded only on the landing page, to verify that anonymous (not-logged-in) domain scans are being requested by a human rather than a bot.
  • highlight.js (cdnjs.cloudflare.com), loaded only on Knowledge Base article pages, to syntax-highlight code examples.

Scan Data Retention

We retain domain validation results and generated reports so you can review your scan history and re-download past reports. If you delete your account, your personal account data is erased as described under Your Rights below. Aggregate, non-identifying statistics derived from scan results (for example, benchmark or Hall of Fame data) may be retained even after account deletion, since they are not tied to your identity.

Your Rights

Depending on your jurisdiction, you may have the right to access, export, correct, or delete the personal data we hold about you. In particular:

  • Access. You can request a copy of the personal data associated with your account.
  • Export. You can request your data in a portable format.
  • Deletion. You can request that your account and personal data be erased. Account deletion on SetEnforce scrubs personal data from your account record as part of our data erasure process.

To exercise any of these rights, please reach out using the contact details below.

Data Security

We use industry-standard measures to protect your data, including password hashing, encrypted session tokens, and access controls on administrative functions. No method of transmission or storage is completely secure, but we work to protect your information using commercially reasonable safeguards.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically.

Contact

If you have questions about this Privacy Policy or wish to exercise any of your privacy rights, please contact us.