Privacy Policy

Effective Date: April 6, 2026 · Last Updated: April 6, 2026

This Privacy Policy describes how Machplace LLC (“Machplace,” “we,” “us,” or “our”), operating under the Vigilium product brand, collects, uses, shares, and protects your personal information when you visit vigilium.ai (the “Website”), create an account, or use our security scanning and monitoring services (the “Service”).

By using the Website or Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Website or Service.

1. Information We Collect

1.1 Information You Provide Directly

  • Account Information: Name, email address, company name, phone number, and job title when you create an account or request a free security scan.
  • Scan Targets: Domain names, IP addresses, or URLs that you submit for scanning. You represent that you own or are authorized to scan these targets.
  • Payment Information: Billing address, payment card details, and related financial data. Payment processing is handled exclusively by Stripe, Inc. We do not store your full credit card number on our servers.
  • Communications: Information you provide when contacting support, submitting feedback, or responding to surveys.

1.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, scan history, report views, and interaction patterns within the Service.
  • Device and Browser Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.
  • Log Data: Server logs recording access times, referring URLs, and system activity for security and performance monitoring.

1.3 Information Generated Through the Service

  • Scan Results: Vulnerability data, security configurations, open port information, SSL/TLS status, and other technical findings generated by scanning your submitted targets.
  • Security Reports:AI-generated plain-English security health reports, A–F security grades, trend data, and remediation recommendations produced from scan results.
  • Compliance Evidence: Documentation generated for PCI DSS, HIPAA, or SOC 2 audit purposes based on scan findings.

2. How We Use Your Information

We use collected information for the following purposes:

  • Service Delivery: To perform security scans, generate reports, calculate security grades, and deliver the features included in your subscription plan.
  • Account Management: To create and manage your account, process payments, and communicate about your subscription.
  • Service Improvement: To analyze usage patterns, diagnose technical issues, and improve the accuracy and performance of our scanning engines and AI report generation.
  • Communication: To send service-related notifications (scan completions, critical vulnerability alerts, billing confirmations) and, with your consent, promotional communications about product updates and security best practices.
  • Security and Fraud Prevention: To protect against unauthorized access, detect abuse of the Service, and maintain the integrity of our infrastructure.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

3. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties.

We may share your information only in the following circumstances:

  • Payment Processing:Billing and payment data is shared with Stripe, Inc. to process subscription charges. Stripe's privacy policy governs their handling of your payment information.
  • Infrastructure Providers: We use third-party hosting providers to operate our servers. These providers process data on our behalf under contractual obligations to protect your information.
  • Legal Requirements: We may disclose information if required by law, subpoena, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity. We will notify you of any such change.
  • With Your Consent: We may share information with third parties when you explicitly direct us to do so.

Scan Results and Security Reports: Your vulnerability scan results, security grades, and AI-generated reports are confidential and will not be shared with any third party unless you explicitly choose to share them (e.g., by exporting a report for an auditor or sharing a report link).

4. Data Retention

  • Account Data: We retain your account information for as long as your account is active. If you close your account, we will delete your personal information within 30 days, except as required by law or legitimate business purposes (e.g., billing records retained for tax compliance).
  • Scan Results and Reports: Scan data and generated reports are retained for the duration of your active subscription to enable historical trend tracking. Upon account closure, scan data is deleted within 90 days.
  • Free Scan Data: If you use the free security grade feature without creating an account, we retain the submitted email address and domain for up to 12 months for follow-up communications (subject to your ability to opt out).
  • Server Logs: Automatically collected log data is retained for up to 12 months for security and diagnostic purposes.

5. Data Security

We implement reasonable technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS), access controls, and regular security assessments of our own infrastructure.

However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.

6. Cookies and Tracking Technologies

  • Essential Cookies: Required for Website functionality, session management, and security. These cannot be disabled.
  • Analytics Cookies: Used to understand how visitors interact with the Website, including page views, traffic sources, and navigation patterns. You may opt out of analytics cookies through our cookie consent banner.
  • Marketing Cookies: Used to deliver relevant content and measure the effectiveness of our communications. These are only placed with your explicit consent.

You can manage cookie preferences through the cookie consent banner displayed on your first visit, or by adjusting your browser settings. Disabling certain cookies may affect Website functionality.

7. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information:

7.1 All Users

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to legal retention requirements.
  • Opt-Out: Unsubscribe from promotional emails at any time using the unsubscribe link in any marketing email, or by contacting us.
  • Data Export: Request an export of your scan reports and account data in a commonly used format.

7.2 European Economic Area (EEA) and UK Residents (GDPR)

In addition to the rights above, you may:

  • Restrict processing of your personal information in certain circumstances.
  • Object to processing based on our legitimate interests.
  • Request data portability in a structured, machine-readable format.
  • Lodge a complaint with your local data protection authority.

Our legal bases for processing your data include: performance of a contract (Service delivery), legitimate interest (service improvement, security), consent (marketing communications), and legal obligation (regulatory compliance).

7.3 California Residents (CCPA/CPRA)

In addition to the rights above, California residents have the right to:

  • Know what categories of personal information we collect, use, and disclose.
  • Request deletion of personal information.
  • Opt out of the sale of personal information. We do not sell personal information.
  • Non-discrimination for exercising your privacy rights.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or within the timeframe required by applicable law).

8. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us at [email protected] and we will promptly delete it.

9. International Data Transfers

Your information is processed and stored on servers located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For EEA, UK, or Swiss residents, any data transfer outside of your region is conducted in compliance with applicable data protection laws, including the use of Standard Contractual Clauses where required.

10. Third-Party Links

The Website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external sites you visit.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy on the Website with a revised “Last Updated” date, and where appropriate, by email notification. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:

Machplace LLC (operating as Vigilium)

St. Petersburg, Florida, USA

Email: [email protected]

General inquiries: [email protected]