Privacy Policy
Cal Security & Forensics LLC
Effective date: October 1, 2026 · Last updated: October 1, 2026
1. Introduction
Cal Security & Forensics LLC ("we", "us", "our") operates calsecforensics.com. This policy explains what personal information we collect, why, how we use it, and the rights you have over it.
We are the data controller for the information described here. Contact us at [email protected].
2. The short version
Most of what our tools do never reaches us.
Our forensic, cryptographic and analysis tools execute in your browser. When you paste a hash, a file, a packet capture or a log into one of them, that data is processed locally on your device and is not transmitted to our servers. We cannot see it, we do not store it, and it is not in our backups.
There are three exceptions, described in Section 4: the Blue Team threat-intelligence lookup, content you explicitly choose to save to your account, and information you send us directly.
3. Information we collect
3.1 Information you provide
| What | When | Why |
|---|---|---|
| Email address | Account creation | Authentication, transactional email |
| Name | Account creation | Account identification, certificate issuance |
| Password | Account creation | Authentication (stored hashed, never in plain text) |
| Payment details | Purchase | Processed by Stripe; we do not receive or store full card numbers |
| Billing address, where required | Purchase | Tax determination, fraud prevention |
| Message content | Contact form, support | Responding to you |
| Two-factor authentication secret | If you enable it | Verifying login codes (stored encrypted) |
3.2 Information generated by your use
| What | Why |
|---|---|
| Course and lesson progress | Delivering training, showing your progress |
| Laboratory attempts, answers submitted, pass/fail state | Grading, attempt limits |
| Certification attempts, scores, certificates issued | Awarding and verifying certification |
| Subscription and entitlement status | Determining what you can access |
| Which tools you opened and when | Product analytics, and your activity history |
Note the distinction in that last row: we record that you used a tool, not what you put into it.
3.3 Technical information
IP address, browser type, device type, referring page, and pages viewed. We use this for security, abuse prevention, rate limiting and aggregate analytics.
4. The three exceptions to local processing
4.1 Blue Team threat-intelligence lookup
This tool differs from every other tool on the site.
When you submit an indicator — an IP address, domain or file hash — it is sent to our server, which forwards it to AlienVault OTX, AbuseIPDB and Shodan using our API credentials, and returns their responses to you.
Those third parties receive the indicator you submitted and may log it under their own policies. We do not control their retention or use.
We retain the indicator only as long as needed to complete the lookup, and record the request for rate-limiting purposes without retaining the indicator value.
4.2 Content you save to your account
Tool session history is stored in your browser by default and is not transmitted to us. If you explicitly choose to save an item to your account, that item is transmitted and stored on our servers so it is available across your devices. You choose what to save, item by item.
4.3 Information you send us
Anything you put into a contact form, support message or email reaches us directly.
5. How we use information
We process personal information to:
- —Provide, maintain and improve the Services;
- —Authenticate you and secure your account;
- —Process payments and manage subscriptions;
- —Deliver training content according to your entitlement;
- —Administer the certification programme and issue certificates;
- —Operate the public certificate verification service;
- —Respond to your enquiries;
- —Detect, prevent and investigate fraud, abuse and security incidents;
- —Send transactional email about your account, purchases and certification;
- —Send marketing email, only where you have opted in;
- —Comply with legal obligations.
Legal bases (UK/EU users)
| Purpose | Basis |
|---|---|
| Providing the Services you requested | Performance of a contract |
| Payment processing | Performance of a contract |
| Security, fraud prevention, rate limiting | Legitimate interests |
| Product analytics | Legitimate interests |
| Marketing email | Consent |
| Non-essential cookies | Consent |
| Legal and tax record-keeping | Legal obligation |
6. Cookies and similar technologies
Essential cookies maintain your session and secure your account. These cannot be disabled without breaking the Services, and no consent is required for them.
Functional cookies remember preferences such as theme.
Third-party cookies are set by our live chat provider. We request your consent before setting these; you can decline and continue to use the Services.
You can manage cookies through your browser. Blocking essential cookies will prevent you signing in.
7. Third parties who process data on our behalf
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Name, email, payment details, billing address |
| GoDaddy | Hosting and infrastructure | All server-side data |
| Airo email gateway | Transactional email | Name, email |
| GoDaddy Inbox | Live chat support | Name, email, message content |
| AlienVault OTX, AbuseIPDB, Shodan | Threat-intelligence lookups | Only indicators you submit to that tool |
We require processors to protect your information and to process it only on our instructions.
We do not sell personal information, and we do not share it with third parties for their own marketing.
We may disclose information where required by law, to enforce our Terms, or to protect the rights, safety or property of any person.
If we are involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
8. Retention
| Data | Retention |
|---|---|
| Account information | While your account is active |
| Progress and laboratory records | While your account is active |
| Payment records | As required by tax and accounting law, typically 7 years |
| Certification records | Retained after account deletion — see below |
| Support correspondence | 5 years after resolution |
| Technical logs | 180 days |
| Saved tool content | Until you delete it, or account deletion |
Certification records are the exception to deletion. The public verification service exists so that employers and third parties can confirm a certificate is genuine. If we deleted the underlying record on account deletion, every certificate we have issued would become unverifiable and the credential would be worthless to the people who earned it.
We therefore retain the minimum necessary — certificate identifier, name as issued, credential, date, and validity status — after account deletion. You may request that your certificate be revoked and removed from verification, which we will honour, but you should understand that this invalidates the credential.
9. Your rights
Depending on where you live, you may have the right to:
- —Access the personal information we hold about you;
- —Correct inaccurate information;
- —Delete your information, subject to Section 8;
- —Port your information to another service in a machine-readable format;
- —Object to processing based on legitimate interests;
- —Restrict processing in certain circumstances;
- —Withdraw consent at any time, where processing is based on consent;
- —Not be discriminated against for exercising these rights.
Exercise these through your account settings, where export and deletion are available directly, or by contacting [email protected]. We will respond within 30 days.
UK and EU users may lodge a complaint with their supervisory authority. California residents have rights under the CCPA/CPRA; we do not sell or share personal information as those terms are defined.
10. International transfers
We are based in the United States and our servers are located in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may not offer the same level of protection as your jurisdiction.
Where we transfer personal information from the UK or EEA to the United States, we rely on Standard Contractual Clauses approved by the European Commission (and, for UK transfers, the UK International Data Transfer Agreement or Addendum) as the lawful transfer mechanism.
11. Security
We protect information using measures including encryption in transit, hashed password storage, encrypted storage of two-factor secrets, access controls, and separation of answer keys and examination content from client-accessible systems.
No system is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials confidential.
If a breach occurs affecting your personal information, we will notify you and any relevant supervisory authority as required by law.
12. Children
The Services are not directed to children under 18 and we do not knowingly collect information from anyone under 13. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.
13. Changes
We may update this policy. We will post the updated version with a new date and, for material changes, notify you by email or in the Services.
