This Privacy Policy explains how Breach Point, Inc., through its Insight Recon products and services ("Breach Point," "Insight Recon," "we," "us," or "our") collects, uses, discloses, and protects personal information. This Policy applies to personal information collected through our websites, portals, web applications, software, SaaS platforms, marketing activities, customer support, sales communications, and third-party sources acting on our behalf (collectively, the "Services").
Scope and Applicability
This Privacy Policy applies to users of the Services, including visitors, customers, prospects, partners, and job applicants. Certain individuals, including residents of the European Economic Area ("EEA"), United Kingdom, California, or other jurisdictions, may have additional rights under applicable data protection laws.
This Policy describes our privacy practices. The contractual terms governing the Insight Recon software, customer platform, and subscriptions are set out in the End User License Agreement and applicable Subscription Terms. Use of our public website is governed by the Terms of Use.
Personal Information We Collect
"Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual. The categories we may collect depend on how you interact with Insight Recon. Information relating to Active Directory environments you assess is addressed separately in Section 03.
A. Information you provide directly
Contact and business information — including name, business email, phone number, company name, role, and mailing or billing address.
Account and service information — including login credentials, user roles and permissions, support requests, and communications.
Payment and billing information — including billing contact details and transaction metadata.
Employment and recruiting information — including résumé or CV information, application materials, and interview communications.
Voluntary submissions — including surveys, product feedback, reviews, and event participation.
B. Automatically collected information
When you access our Services, we may automatically collect technical and usage information such as IP address, device identifiers, browser type, operating system, language and regional settings, pages viewed, actions taken, date and time stamps, referring URLs, and limited email engagement data.
We use this information to operate and secure the Services, improve functionality, detect abuse or fraud, and understand usage trends.
C. Information from third parties
We may receive Personal Information from business partners, resellers, merchants of record, marketing providers, publicly available sources, recruiting platforms, and service providers acting on our behalf where permitted by law.
Assessment and Scan Data
Insight Recon's core function is assessing the security posture of Active Directory environments. This section explains how assessment data is collected, processed, stored, and retained.
A. What the scanner collects
The Insight Recon scanner runs locally within an environment, on a machine controlled by the customer or authorized operator, using credentials supplied by the customer. It reads and enumerates Active Directory configuration metadata, which may include object attributes for users, groups, and computers; access-control and permission relationships; group memberships; Group Policy configuration; certificate services configuration; trust relationships; and similar directory configuration state.
B. What the scanner does not collect
The scanner is designed to perform read-only assessment activity. As currently offered, it does not collect, extract, or transmit raw credential material such as plaintext passwords, password hashes, Kerberos keys or tickets, or the contents of the NTDS.dit database, and it does not perform credential extraction or exploitation of the assessed Active Directory environment.
C. How scan data reaches our platform
The scan runs locally and generates Active Directory metadata. That metadata is uploaded to the Insight Recon platform, automatically or manually depending on configuration, where it is processed to generate reports, findings, and risk information.
D. Hosting, encryption, and access
The Insight Recon platform is currently hosted on Microsoft Azure. Scan metadata is encrypted in transit and at rest. Scan data is accessible to authorized users within the applicable customer account. A limited number of authorized Breach Point personnel may access customer data when reasonably necessary to operate, support, secure, troubleshoot, or maintain the Services.
E. Retention and deletion
On the Free plan, we retain the most recent scan in the active account. Paid plans may retain scan history to support posture tracking over time. Customers may delete scan data from within their account, which removes it from active account views promptly.
Following deletion, or following expiration or termination of an account or subscription, scan data is removed from active systems within thirty (30) days, except to the extent a longer retention period is required by applicable law or reasonably necessary to establish, exercise, or defend legal claims.
Residual copies of scan data contained in routine backup or archival systems may be retained until overwritten or deleted in accordance with our standard backup-retention practices. Those copies remain access-restricted and are not restored or otherwise processed except as reasonably necessary for disaster recovery, security, legal compliance, or the establishment, exercise, or defense of legal claims.
F. Aggregated and de-identified data
We may generate aggregated and de-identified statistics and insights from scan data across our customer base, such as the average number of findings per assessment, prevalence of particular security conditions, or changes in security posture over time.
We use this information to operate, secure, analyze, research, and improve the Services and to produce industry research, aggregate statistics, trend reports, educational materials, and marketing materials.
Aggregated and de-identified information will not identify you, your organization, an individual user, or a specific assessed environment and will not reasonably be capable of being used to do so. We do not sell or disclose individual customer scan results or identifiable environment data for advertising or marketing purposes.
Customers using Insight Recon to assess environments owned or operated by third parties are responsible for obtaining the rights and authorizations necessary for Breach Point to process scan data as described in this Privacy Policy and the applicable End User License Agreement.
How We Use Personal Information
We use Personal Information for legitimate business purposes, including to:
- Provide, operate, and maintain the Services
- Create and manage accounts
- Process transactions and billing
- Deliver reports, findings, and support services
- Respond to inquiries and requests
- Communicate service-related updates
- Improve and develop products and features
- Conduct analytics and research
- Market and promote our Services using contact information you provide and aggregated, de-identified insights
- Administer events, surveys, and promotions
- Protect against fraud, misuse, or security threats
- Comply with legal, regulatory, and contractual obligations
- Enforce our terms, policies, and agreements
Disclosure of Personal Information
A. Corporate affiliates
Within Breach Point and its affiliates where reasonably necessary for legitimate business and operational purposes.
B. Service providers
With trusted vendors and subprocessors that provide cloud infrastructure, payment processing, analytics, communications, customer support, auditing, legal, accounting, and other services on our behalf.
C. Business transactions
In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction.
D. Legal and compliance obligations
Where required to comply with applicable law, regulation, legal process, or government request.
E. With your direction
When you instruct us to disclose information or intentionally make information available to another party.
Analytics, Cookies, and Similar Technologies
We may use cookies, pixels, web beacons, and similar technologies to understand usage patterns, improve user experience, measure marketing effectiveness, and secure and operate the Services.
Most browsers allow you to manage cookie preferences. Disabling cookies may affect certain features. We may use third-party analytics services subject to their own privacy terms.
Third-Party Services and Links
Our Services may include links to third-party websites or integrations. This Privacy Policy does not govern those third parties, and we are not responsible for their privacy practices or content.
Do Not Track Signals
At this time, we do not respond to browser "Do Not Track" signals because there is no consistent industry standard governing those signals.
Security Safeguards
We implement commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Information and scan data from unauthorized access, loss, misuse, or disclosure.
Scan metadata is encrypted in transit and at rest, and the Insight Recon platform is hosted on Microsoft Azure. Access to customer data by Breach Point personnel is limited to personnel with a legitimate need to operate, support, secure, or maintain the Services.
If we become aware of a security incident involving unauthorized access to or acquisition of customer scan data in our possession or control, we will provide notifications as required by applicable law and applicable contractual commitments, including Section 7.6 of the End User License Agreement and any applicable Data Processing Addendum.
No information system is completely secure, and we cannot guarantee absolute security.
Data Retention
We retain Personal Information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Scan and assessment data is retained according to the applicable plan. The Free plan retains the most recent active scan, while paid plans may retain scan history to support posture tracking over time.
Customers may delete scan data from within their account. Deleted scan data, and scan data associated with an expired or terminated account or subscription, is removed from active systems within thirty (30) days, except to the extent a longer retention period is required by applicable law or reasonably necessary to establish, exercise, or defend legal claims.
Residual copies contained in routine backup or archival systems may be retained until overwritten or deleted in accordance with our standard backup-retention practices. Those copies remain access-restricted and are not restored or otherwise processed except as reasonably necessary for disaster recovery, security, legal compliance, or the establishment, exercise, or defense of legal claims.
Children's Privacy
The Services are intended for business and professional use by adults age 18 or older. They are not directed to children, and we do not knowingly collect Personal Information from children.
If you believe a child has provided us with Personal Information, contact [email protected] and we will take steps to delete it.
Your Rights and Choices
A. Updating or correcting information
You may request updates or corrections to Personal Information by contacting [email protected].
B. Accessing or deleting scan data
Authorized users can view, export, or delete applicable scan data through the Insight Recon account interface. You may also contact us for assistance.
C. Marketing communications
You may unsubscribe from marketing emails using the unsubscribe link in those communications. Transactional, account, security, billing, or service-related communications may still be sent.
California Privacy Rights
California residents may have rights under applicable law, including rights to:
- Know what Personal Information we collect and disclose
- Request correction or deletion of Personal Information, subject to exceptions
- Receive information about our privacy practices
- Not be discriminated against for exercising applicable privacy rights
We do not sell Personal Information. Requests may be submitted to [email protected].
European Economic Area and UK Rights
Where applicable, individuals in the EEA or United Kingdom may have rights to access, correct, delete, restrict, or object to processing of Personal Information and may have rights to data portability.
To exercise applicable rights, contact [email protected].
Our Services may process information in the United States or other countries. Where required by applicable law, we use appropriate safeguards for international transfers.
Where we act as a processor of personal data contained in scan data on a customer's behalf, that processing is governed by the applicable Data Processing Addendum and Section 7.4 of the End User License Agreement.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or Services. When we make changes, we will update the "Last Updated" date above. Where required by applicable law, we will provide additional notice of material changes.