Privacy Policy
Last updated: 28 September 2026
In short
Pentrawl is built to respect your privacy. We collect the minimum needed to run a scan and show you the report, we never sell or share your data, and scan results are automatically deleted after 30 days. No account is required to use Pentrawl.
What we collect
When you run a scan, we process and store the following:
- The domain you enter, along with the technical scan results — DNS records, email configuration, certificate details, HTTP headers and publicly reachable paths. This is information the domain already exposes to any visitor on the public internet.
- Your IP address, used only to apply rate limiting and prevent abuse of the service. It is not linked to your identity and is not used for tracking.
- A session cookie, used solely to protect our forms against cross-site request forgery (CSRF). It contains no personal information and is not used for advertising or analytics.
What we do not collect
We do not require or store names, email addresses or accounts. We do not scan or store anything behind a login on the target site. We do not use advertising trackers, and we do not build profiles of our visitors.
Why we process this data
We process the data above for one purpose only: to perform the security scan you requested and present the resulting report to you. Rate-limiting data exists purely to keep the service available and prevent misuse. Our legal basis under the GDPR is our legitimate interest in providing and protecting the service you asked for.
How long we keep it
Scan results are automatically and permanently deleted 30 days after the scan. Rate-limiting records are short-lived and expire automatically. We keep nothing longer than necessary.
Who we share it with
No one. We do not sell, rent, trade or share your data with third parties. Your scan results are yours. The only way a report leaves our systems is if you choose to share its link or download it yourself.
Your rights
Under the GDPR you have the right to access, correct or delete the personal data we hold about you, and to object to its processing. Because we store so little and delete it automatically, most requests resolve themselves within 30 days — but if you would like a scan result removed sooner, you can request it and we will delete it.
Changes to this policy
If we update this policy, we will change the date at the top of this page. Continued use of Pentrawl after a change means you accept the updated policy.
Pentrawl scans only domains you own or have permission to test. For how we run scans and what each check means, see our Security page.