Legal

Privacy Policy

Insight Recon is a product and service of Breach Point, Inc. We build security tooling for organizations that care deeply about protecting sensitive data, and we treat your information with the same seriousness.

Effective Date: January 1, 2024 Last Updated: August 26, 2026 Questions? [email protected]

This Privacy Policy explains how Breach Point, Inc., through its Insight Recon products and services ("Breach Point," "Insight Recon," "we," "us," or "our") collects, uses, discloses, and protects personal information. This Policy applies to personal information collected through our websites, portals, web applications, software, SaaS platforms, marketing activities, customer support, sales communications, and third-party sources acting on our behalf (collectively, the "Services").

Section 01

Scope and Applicability

This Privacy Policy applies to users of the Services, including visitors, customers, prospects, partners, and job applicants. Certain individuals, including residents of the European Economic Area ("EEA"), United Kingdom, California, or other jurisdictions, may have additional rights under applicable data protection laws.

This Policy describes our privacy practices. The contractual terms governing the Insight Recon software, customer platform, and subscriptions are set out in the End User License Agreement and applicable Subscription Terms. Use of our public website is governed by the Terms of Use.

Section 02

Personal Information We Collect

"Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual. The categories we may collect depend on how you interact with Insight Recon. Information relating to Active Directory environments you assess is addressed separately in Section 03.

A. Information you provide directly

Contact and business information — including name, business email, phone number, company name, role, and mailing or billing address.

Account and service information — including login credentials, user roles and permissions, support requests, and communications.

Payment and billing information — including billing contact details and transaction metadata.

Note: Insight Recon does not store full payment card or banking details. Payment processing may be handled by third-party payment processors or merchants of record subject to their own privacy and security obligations.

Employment and recruiting information — including résumé or CV information, application materials, and interview communications.

Voluntary submissions — including surveys, product feedback, reviews, and event participation.

B. Automatically collected information

When you access our Services, we may automatically collect technical and usage information such as IP address, device identifiers, browser type, operating system, language and regional settings, pages viewed, actions taken, date and time stamps, referring URLs, and limited email engagement data.

We use this information to operate and secure the Services, improve functionality, detect abuse or fraud, and understand usage trends.

C. Information from third parties

We may receive Personal Information from business partners, resellers, merchants of record, marketing providers, publicly available sources, recruiting platforms, and service providers acting on our behalf where permitted by law.

Section 03

Assessment and Scan Data

Insight Recon's core function is assessing the security posture of Active Directory environments. This section explains how assessment data is collected, processed, stored, and retained.

A. What the scanner collects

The Insight Recon scanner runs locally within an environment, on a machine controlled by the customer or authorized operator, using credentials supplied by the customer. It reads and enumerates Active Directory configuration metadata, which may include object attributes for users, groups, and computers; access-control and permission relationships; group memberships; Group Policy configuration; certificate services configuration; trust relationships; and similar directory configuration state.

B. What the scanner does not collect

The scanner is designed to perform read-only assessment activity. As currently offered, it does not collect, extract, or transmit raw credential material such as plaintext passwords, password hashes, Kerberos keys or tickets, or the contents of the NTDS.dit database, and it does not perform credential extraction or exploitation of the assessed Active Directory environment.

If this changes: If we materially change what the scanner collects, we will update this Privacy Policy and the "Last Updated" date above, and provide additional notice where required by applicable law.

C. How scan data reaches our platform

The scan runs locally and generates Active Directory metadata. That metadata is uploaded to the Insight Recon platform, automatically or manually depending on configuration, where it is processed to generate reports, findings, and risk information.

D. Hosting, encryption, and access

The Insight Recon platform is currently hosted on Microsoft Azure. Scan metadata is encrypted in transit and at rest. Scan data is accessible to authorized users within the applicable customer account. A limited number of authorized Breach Point personnel may access customer data when reasonably necessary to operate, support, secure, troubleshoot, or maintain the Services.

E. Retention and deletion

On the Free plan, we retain the most recent scan in the active account. Paid plans may retain scan history to support posture tracking over time. Customers may delete scan data from within their account, which removes it from active account views promptly.

Following deletion, or following expiration or termination of an account or subscription, scan data is removed from active systems within thirty (30) days, except to the extent a longer retention period is required by applicable law or reasonably necessary to establish, exercise, or defend legal claims.

Residual copies of scan data contained in routine backup or archival systems may be retained until overwritten or deleted in accordance with our standard backup-retention practices. Those copies remain access-restricted and are not restored or otherwise processed except as reasonably necessary for disaster recovery, security, legal compliance, or the establishment, exercise, or defense of legal claims.

F. Aggregated and de-identified data

We may generate aggregated and de-identified statistics and insights from scan data across our customer base, such as the average number of findings per assessment, prevalence of particular security conditions, or changes in security posture over time.

We use this information to operate, secure, analyze, research, and improve the Services and to produce industry research, aggregate statistics, trend reports, educational materials, and marketing materials.

Aggregated and de-identified information will not identify you, your organization, an individual user, or a specific assessed environment and will not reasonably be capable of being used to do so. We do not sell or disclose individual customer scan results or identifiable environment data for advertising or marketing purposes.

Customers using Insight Recon to assess environments owned or operated by third parties are responsible for obtaining the rights and authorizations necessary for Breach Point to process scan data as described in this Privacy Policy and the applicable End User License Agreement.

Section 04

How We Use Personal Information

We use Personal Information for legitimate business purposes, including to:

  • Provide, operate, and maintain the Services
  • Create and manage accounts
  • Process transactions and billing
  • Deliver reports, findings, and support services
  • Respond to inquiries and requests
  • Communicate service-related updates
  • Improve and develop products and features
  • Conduct analytics and research
  • Market and promote our Services using contact information you provide and aggregated, de-identified insights
  • Administer events, surveys, and promotions
  • Protect against fraud, misuse, or security threats
  • Comply with legal, regulatory, and contractual obligations
  • Enforce our terms, policies, and agreements
Important: We do not use individual identifiable customer scan results for advertising or marketing profiling. We may use aggregated and de-identified information as described in Section 03.
Section 05

Disclosure of Personal Information

A. Corporate affiliates

Within Breach Point and its affiliates where reasonably necessary for legitimate business and operational purposes.

B. Service providers

With trusted vendors and subprocessors that provide cloud infrastructure, payment processing, analytics, communications, customer support, auditing, legal, accounting, and other services on our behalf.

C. Business transactions

In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction.

D. Legal and compliance obligations

Where required to comply with applicable law, regulation, legal process, or government request.

E. With your direction

When you instruct us to disclose information or intentionally make information available to another party.

Note: We do not sell Personal Information, and we do not disclose individual customer scan results except to authorized users, at the customer's direction, or as required by law.
Section 06

Analytics, Cookies, and Similar Technologies

We may use cookies, pixels, web beacons, and similar technologies to understand usage patterns, improve user experience, measure marketing effectiveness, and secure and operate the Services.

Most browsers allow you to manage cookie preferences. Disabling cookies may affect certain features. We may use third-party analytics services subject to their own privacy terms.

Section 07

Third-Party Services and Links

Our Services may include links to third-party websites or integrations. This Privacy Policy does not govern those third parties, and we are not responsible for their privacy practices or content.

Section 08

Do Not Track Signals

At this time, we do not respond to browser "Do Not Track" signals because there is no consistent industry standard governing those signals.

Section 09

Security Safeguards

We implement commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Information and scan data from unauthorized access, loss, misuse, or disclosure.

Scan metadata is encrypted in transit and at rest, and the Insight Recon platform is hosted on Microsoft Azure. Access to customer data by Breach Point personnel is limited to personnel with a legitimate need to operate, support, secure, or maintain the Services.

If we become aware of a security incident involving unauthorized access to or acquisition of customer scan data in our possession or control, we will provide notifications as required by applicable law and applicable contractual commitments, including Section 7.6 of the End User License Agreement and any applicable Data Processing Addendum.

No information system is completely secure, and we cannot guarantee absolute security.

Section 10

Data Retention

We retain Personal Information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Scan and assessment data is retained according to the applicable plan. The Free plan retains the most recent active scan, while paid plans may retain scan history to support posture tracking over time.

Customers may delete scan data from within their account. Deleted scan data, and scan data associated with an expired or terminated account or subscription, is removed from active systems within thirty (30) days, except to the extent a longer retention period is required by applicable law or reasonably necessary to establish, exercise, or defend legal claims.

Residual copies contained in routine backup or archival systems may be retained until overwritten or deleted in accordance with our standard backup-retention practices. Those copies remain access-restricted and are not restored or otherwise processed except as reasonably necessary for disaster recovery, security, legal compliance, or the establishment, exercise, or defense of legal claims.

Section 11

Children's Privacy

The Services are intended for business and professional use by adults age 18 or older. They are not directed to children, and we do not knowingly collect Personal Information from children.

If you believe a child has provided us with Personal Information, contact [email protected] and we will take steps to delete it.

Section 12

Your Rights and Choices

A. Updating or correcting information

You may request updates or corrections to Personal Information by contacting [email protected].

B. Accessing or deleting scan data

Authorized users can view, export, or delete applicable scan data through the Insight Recon account interface. You may also contact us for assistance.

C. Marketing communications

You may unsubscribe from marketing emails using the unsubscribe link in those communications. Transactional, account, security, billing, or service-related communications may still be sent.

Section 13

California Privacy Rights

California residents may have rights under applicable law, including rights to:

  • Know what Personal Information we collect and disclose
  • Request correction or deletion of Personal Information, subject to exceptions
  • Receive information about our privacy practices
  • Not be discriminated against for exercising applicable privacy rights

We do not sell Personal Information. Requests may be submitted to [email protected].

Section 14

European Economic Area and UK Rights

Where applicable, individuals in the EEA or United Kingdom may have rights to access, correct, delete, restrict, or object to processing of Personal Information and may have rights to data portability.

To exercise applicable rights, contact [email protected].

Our Services may process information in the United States or other countries. Where required by applicable law, we use appropriate safeguards for international transfers.

Where we act as a processor of personal data contained in scan data on a customer's behalf, that processing is governed by the applicable Data Processing Addendum and Section 7.4 of the End User License Agreement.

Section 15

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or Services. When we make changes, we will update the "Last Updated" date above. Where required by applicable law, we will provide additional notice of material changes.