Privacy Policy

πŸ“… Effective date: 1 January 2025 πŸ”„ Last updated: 1 January 2025 🌍 Applies to: auditxa.com
πŸ”’ The short version β€” plain English first Your firewall, VPN, router, Active Directory, and Microsoft 365 configuration/export files never leave your browser and are never sent to our servers. We only collect your email address to manage your account and send you login codes. We do not sell your data. We do not show you ads. This policy explains in full what we collect, why, and what your rights are.

Contents

  1. Who we are
  2. What data we collect and why
  3. Your configuration files β€” a special note
  4. Legal basis for processing (GDPR)
  5. How we use your data
  6. Who we share data with
  7. How long we keep your data
  8. How we protect your data
  9. Cookies and tracking
  10. Your rights
  11. Children's privacy
  12. International data transfers
  13. California residents (CCPA)
  14. Changes to this policy
  15. Contact us

1. Who we are

AuditXA ("we," "us," or "our") operates the website at auditxa.com and provides a browser-based network security auditing tool for firewall, VPN, router, Active Directory and Microsoft 365 configuration analysis. AuditXA is operated by Monogon Solutions LLC.

For the purposes of data protection law, including the EU General Data Protection Regulation (GDPR) and the UK GDPR, we act as the data controller of the personal data described in this policy. We collect a limited set of data to operate your account β€” your email address, login activity, and billing status β€” and we do not collect special categories of data (health, biometric, racial/ethnic, political, religious, or similar). Saving an audit report to your account is entirely optional and only happens if you actively choose it; configuration and export files themselves (firewall, VPN, router, Active Directory, or Microsoft 365) are never uploaded to or stored on our servers.

AuditXA is a newly launched service. We have not yet appointed a formal EU Article 27 representative; we will do so before we have an established base of EU/UK subscribers, consistent with our obligations as our service grows. In the meantime, email is the fastest and most reliable way to reach us on any privacy matter, including exercising your data protection rights, and we aim to respond to all such requests within the timeframes set out in Section 10 below.

Contact for privacy matters:
Email: admin@auditxa.com

2. What data we collect and why

Data Why we collect it How long kept
Email address To create and manage your account; to send one-time login codes (MFA); to notify you of subscription changes Until you delete your account + 30 days
One-time login codes (OTP) Stored as a one-way cryptographic hash (not the code itself) to verify your identity at login. Never stored in plain text. Automatically deleted after use or after 1 hour, whichever is sooner
Subscription status and plan To determine whether you have an active subscription and which features to enable Until you delete your account + 7 years (tax/legal requirement)
Payment provider customer ID To link your subscription to your account and process billing events Duration of subscription + 7 years
Login timestamps and IP address Security logging β€” to detect suspicious access patterns and protect your account 90 days, then automatically deleted
Audit activity log Records which audit tool you used and your audit score (not the config content) for your audit history feature Until you clear your history or delete your account
Rate limit records To prevent abuse of the login system (max 5 OTP requests per 15 minutes per IP) 24 hours, then automatically deleted
We do not collect: your firewall configuration file content, device hostnames, IP addresses from your configs, passwords or secrets from your configs, browser fingerprints, or advertising identifiers. We do not use analytics platforms like Google Analytics.

3. Your configuration and export files β€” a special note

This is the most important part of this policy for our users.

Your firewall, VPN, router, Active Directory, and Microsoft 365 configuration/export files are processed entirely within your web browser. They are never uploaded to, transmitted to, or stored on our servers.

When you paste or upload a configuration file:

You can verify this yourself by opening your browser's developer tools (F12 β†’ Network tab) and observing that no configuration content is transmitted when you run an audit.

This design is intentional. Network configuration files often contain sensitive information such as pre-shared keys, management IP ranges, and authentication settings. We believe this data should never leave your environment, so we architected the tool so that it technically cannot.

The one exception β€” reports you choose to save: if you click "Save to Cloud" or "Email me a copy," we store the resulting report (your score, findings summary, and the generic remediation guidance shown on screen) so you can retrieve it later. This is opt-in per report β€” nothing is saved unless you explicitly select it. Reports never contain your raw configuration file content, only the analysis output. You can delete any saved report at any time from your Audit History.

5. How we use your data

We use the data we collect strictly to:

We do not: sell your data, share it for advertising purposes, use it for profiling or automated decision-making, or process it for any purpose beyond what is described in this policy.

6. Who we share data with

We share your data with the following third-party service providers only to the extent necessary to operate the service:

Provider Purpose Data shared Location
Cloudflare
cloudflare.com
Web hosting, edge functions, database (D1) and file storage (R2) β€” stores account, subscription, and report data Email, subscription status, OTP hashes, login logs, saved report content, IP addresses in server logs Globally distributed edge network; primary data storage in the USA
Resend
resend.com
Transactional email β€” sends your one-time login codes Your email address and the one-time code USA
Stripe
stripe.com
Payment processing and subscription management Email address, subscription data. Payment details are processed exclusively by Stripe β€” we never see or store your card details. USA

All third-party providers are contractually required to handle your data securely and only for the purposes we specify. We do not share your data with any other parties except where required by law.

Legal disclosure

We may disclose your data if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7. How long we keep your data

We keep your data only for as long as necessary for the purposes described in this policy:

When data reaches its retention limit, it is permanently deleted from our database. Backups containing the data are also purged within 30 days of the live deletion.

8. How we protect your data

We implement industry-standard technical and organisational measures to protect your personal data:

No method of transmission or storage is 100% secure. If you become aware of any security vulnerability in our service, please report it responsibly to admin@auditxa.com.

9. Cookies and tracking

We use no advertising cookies, no analytics cookies, and no third-party tracking of any kind.

What we do use

localStorage (not a cookie, but similar) β€” we store your login session token in your browser's localStorage so you stay signed in across visits. It persists until it expires (8 hours) or you sign out, and is never sent to third parties. This is strictly necessary for the service to function.

What we do not use

Our hosting provider (Cloudflare) and font provider (Google Fonts) may set standard infrastructure cookies as part of CDN delivery. These are outside our control but do not track you for advertising purposes.

Because we use no tracking or analytics cookies beyond session management, we do not display a cookie consent banner. If we ever add optional tracking (which we will always announce), we will implement a full consent mechanism before doing so.

10. Your rights

Depending on your location, you have the following rights regarding your personal data. To exercise any of these rights, email us at admin@auditxa.com. We will respond within 30 days (EEA/UK: within 1 calendar month as required by GDPR).

πŸ“‹ Right of access

You can request a copy of all personal data we hold about you.

✏️ Right to rectification

You can ask us to correct inaccurate or incomplete data we hold about you.

πŸ—‘οΈ Right to erasure

You can ask us to delete your personal data ("right to be forgotten"), subject to our legal retention obligations.

⏸️ Right to restriction

You can ask us to restrict processing of your data in certain circumstances (e.g. while a dispute is resolved).

πŸ“¦ Right to portability

You can request your data in a structured, machine-readable format (JSON or CSV).

🚫 Right to object

You can object to processing based on legitimate interests. We will stop unless we have compelling grounds.

πŸ€– Automated decisions

We do not make any automated decisions that significantly affect you. No profiling is performed.

πŸ›οΈ Right to complain

You have the right to lodge a complaint with your national data protection authority (e.g. ICO in the UK, your local EU supervisory authority).

How to delete your account

Email admin@auditxa.com with the subject line "Delete my account" from your registered email address. We will delete your account data within 30 days and confirm when done. Billing records required by law (7 years) will be retained but isolated from the main account database.

11. Children's privacy

AuditXA is a professional tool intended exclusively for adults (18 years or older) working in IT, network security, or related fields. We do not knowingly collect personal data from anyone under the age of 18.

If you believe a person under 18 has provided us with personal data, please contact us at admin@auditxa.com and we will delete that data promptly.

12. International data transfers

Our service providers are primarily based in the United States. If you are located in the European Economic Area (EEA) or the United Kingdom, your personal data may be transferred to and processed in the USA.

We ensure such transfers comply with applicable data protection law through the following safeguards:

13. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you specific rights regarding your personal information.

Categories of personal information collected

We collect: Identifiers (email address, IP address). We do not collect: financial information (handled exclusively by Stripe), biometric data, geolocation, internet activity beyond login logs, or sensitive personal information.

Your California rights

To exercise your California rights, email admin@auditxa.com. We will respond within 45 days.

"Do Not Sell or Share My Personal Information"

We do not sell or share your personal information for advertising purposes. No opt-out is necessary, but we honor this right regardless.

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

When we make material changes (changes that significantly affect your rights or how we process your data), we will:

We encourage you to review this policy periodically. Your continued use of AuditXA after the effective date of any changes constitutes acceptance of the updated policy.

Previous versions of this policy are available on request by emailing admin@auditxa.com.

15. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy & Data Protection Contact

πŸ“§ Email: admin@auditxa.com πŸ” Security issues: admin@auditxa.com