1.About this policy
EightScope is operated by Heuristic Group Pty Ltd, ABN 37 700 907 080. This policy applies to personal information handled through the EightScope website, dashboard, scanning platform, monitoring system, reports, billing functions, support channels and related services.
It applies to account holders, organisation members, website visitors, support contacts and individuals whose publicly available information may appear in an authorised scan result.
This policy should be read together with the Terms of Service and Scan Methodology.
A customer organisation may also have its own privacy obligations relating to information it submits to EightScope or obtains through a scan.
Where an organisation provides access to employees, contractors or clients, that organisation controls who it authorises to access its workspace and reports.
2.What personal information means
Personal information generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
A domain name, IP address or technical finding is not always personal information. It may become personal information where it can reasonably be connected to a sole trader, account holder, employee, domain registrant or another identifiable person.
EightScope does not normally require sensitive information such as health information, government identifiers, political opinions, religious beliefs or biometric information.
3.Information we collect
Account and identity information
Examples
email address; organisation name; user and organisation identifiers; organisation role; account creation date; email-verification status
Why it is needed
create and manage accounts; identify authorised organisation members; provide service access; communicate account and security information
Authentication and security information
Examples
password hash; MFA method; encrypted authentication secrets where applicable; login and verification activity; password-reset activity; IP address; security and rate-limit events
Why it is needed
authenticate users; prevent abuse; protect accounts; investigate suspicious activity
Organisation and preference information
Examples
organisation plan; alert address; monitoring schedule; digest preferences; webhook URL and type; beta-program settings; organisation permissions
Why it is needed
configure the service; send alerts; schedule monitoring; enforce plan entitlements
Domain and scan information
Examples
verified domain names; domain verification records; registrar renewal date where supplied; scan settings; discovered assets; scan results; findings; scores; reports; evidence; remediation status; scan history
Why it is needed
perform authorised scans; provide asset visibility; identify changes; create reports; assist remediation
Billing and subscription information
Examples
selected plan; billing interval; scan-credit use; Stripe customer identifier; Stripe subscription identifier; renewal and pending plan information
Why it is needed
process and reconcile subscriptions; apply entitlements; manage billing changes; prevent billing abuse
Support, beta and feedback information
Examples
messages to support; issue descriptions; screenshots; uploaded media; reproduction steps; page URLs; false-positive reports; customer notes; technical evidence; account snapshots
Why it is needed
investigate problems; respond to support requests; review disputed findings; improve reliability; administer beta rewards where applicable
Technical and usage information
Examples
IP address; scan IDs; timestamps; quota use; request outcomes; email-delivery events; webhook-delivery events; system errors; security logs
Why it is needed
operate and secure the platform; troubleshoot problems; enforce limits; detect abuse; maintain audit records
EightScope does not store account passwords in readable plain text.
4.Information collected through scans
EightScope performs authorised external assessments from the public internet.
Depending on the selected scan type and options, a scan may collect or derive information such as:
- hostnames and subdomains
- public IP addresses
- DNS and email-security records
- certificate information
- HTTP and HTTPS responses
- security headers and cookie attributes
- publicly reachable ports and services
- public service banners
- web technologies and version indicators
- public files, paths and directory listings
- public login panels and API documentation
- public JavaScript libraries
- secret-like text patterns
- public email addresses
- Certificate Transparency information
- domain-reputation indicators
- security findings, scores and recommendations
This information usually concerns systems rather than people. However, public pages, WHOIS-related information, email addresses, usernames, file contents or sole-trader domains may contain personal information.
EightScope does not collect this information for advertising, profiling individuals or contacting people identified during a scan.
Customers must have authority to scan the relevant domain and must use scan information lawfully.
A scan is a point-in-time external observation. Information can be incomplete, inaccurate or become outdated. See the Scan Methodology for more detail.
5.How information is collected
Directly from you
We collect information when you create an account, verify a domain, configure monitoring, select a plan, add notes, submit evidence, contact support, report an issue or configure an integration.
Automatically through use of the service
We collect technical and usage information when you sign in, make requests, run scans, download reports, use credits or interact with security and billing features.
From the public internet
Authorised scans collect externally observable information from the target’s public systems, DNS, certificates, web responses and public security-data sources.
From service providers
Payment and communication providers may return subscription identifiers, delivery information, billing status and other records required to operate the service.
From your organisation
An organisation owner or administrator may add an alert address, create access for users, assign findings, add notes or configure integrations containing information about other people.
6.How information is used
EightScope uses personal information where reasonably necessary to:
- create and administer accounts and organisations
- verify email addresses and domains
- authenticate users and provide MFA
- perform authorised external scans
- create findings, scores, reports and comparisons
- schedule monitoring
- send account, scan, security and billing messages
- deliver customer-configured webhook notifications
- manage plans, subscriptions and credits
- provide support
- investigate false positives and product issues
- prevent fraud, misuse and unauthorised scanning
- secure, test and maintain the service
- diagnose failures and improve reliability
- maintain records of account and billing activity
- comply with applicable law and valid legal requests
- establish, exercise or defend legal claims
- produce aggregated or de-identified operational insights
We do not use scan results to build advertising profiles about individuals.
We do not sell or rent personal information.
We may use aggregated or de-identified information where it no longer reasonably identifies an individual or customer organisation.
7.Browser storage and website technology
EightScope uses browser storage to maintain signed-in account state, remember the active account and support normal dashboard operation.
EightScope does not use third-party advertising or session-replay software.
When configured in production, EightScope may load Google Analytics 4 (and optionally Google Tag Manager) on public marketing pages to measure traffic, acquisition channels, page performance and primary marketing CTA / conversion events (for example sign-up, sample report and pricing clicks). Google may process technical information such as IP address (with IP anonymisation enabled where supported), browser type, pages viewed, approximate location and those event names with a coarse location label on the page. Analytics identifiers are not used for advertising personalisation by EightScope.
Hosting, security and network providers may still process standard technical information required to serve and protect the website, such as IP addresses, request times and error information.
If EightScope introduces additional non-essential advertising or session-replay technology, this policy and any required consent controls must be updated before that technology is enabled.
8.Emails and notifications
EightScope may send service-related messages including:
- email-verification codes
- MFA codes
- password-reset links
- security notices
- domain-verification or ownership warnings
- scan and monitoring alerts
- security digests
- billing and subscription messages
- support responses
Email delivery providers receive the recipient address, sender information, subject line, message body and any attachment required to deliver the message.
EightScope does not currently use account email addresses for third-party advertising.
Marketing email should not be sent unless a separate consent and unsubscribe process is implemented.
Customer-configured webhooks
Customers may provide a webhook destination such as Slack, Microsoft Teams or another compatible service.
When enabled, EightScope may send the configured destination information such as:
- domain name
- scan identifier
- score and grade
- new findings
- regressions
- change summaries
The customer is responsible for choosing and securing the destination and ensuring that sending this information to it is authorised.
9.Payments and billing
EightScope uses a third-party payment provider to process paid subscriptions. The current production payment provider is Stripe.
The payment provider may collect payment-card and billing information directly from the customer. EightScope’s application stores billing references and subscription status required to provide the selected plan.
EightScope does not store complete payment-card numbers or card-security codes in its application database where those details are entered directly into the payment provider’s checkout.
Information provided to the payment provider can include:
- account email
- organisation identifier
- selected plan
- billing interval
- promotion-code use
- subscription metadata
Payment providers retain information under their own privacy policies and legal obligations.
11.Overseas processing
Some providers used by EightScope are headquartered in, operate from or use systems located outside Australia.
Personal information and scan artefacts may therefore be processed outside Australia by:
- Vercel (frontend / edge; may include regions outside Australia)
- Railway (API and Postgres; live region US West / California, USA - no Australia region currently)
- Stripe (payments; commonly including the United States)
- Resend or another configured email provider
- Optional scan intelligence providers (for example Safe Browsing, VirusTotal, SecurityTrails) when those modules are configured
The exact location depends on each provider's infrastructure for the live deployment.
Where required by applicable Australian privacy law, EightScope will take reasonable steps concerning overseas recipients and the handling of personal information.
12.Security
EightScope takes reasonable technical and organisational steps intended to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Examples may include:
- access controls
- organisation-level data separation
- password hashing
- MFA options
- encryption where appropriate
- rate limiting
- domain-verification controls
- scan safety protections
- restricted administrative access
- security and audit logging
- service monitoring
- backup and recovery processes
No online service, transmission method or storage system can be guaranteed to be completely secure.
Customers are responsible for:
- protecting their login credentials
- using strong unique passwords
- enabling MFA where available
- controlling organisation membership
- securing alert and webhook destinations
- avoiding the upload of secrets
- notifying EightScope promptly of suspected unauthorised access
Do not email passwords, private keys, access tokens or security credentials to support.
13.Retention
EightScope retains information for as long as reasonably required to provide the service, maintain security and billing records, resolve disputes, meet legal obligations and support legitimate operational needs. Published schedules for the main data categories are set out below.
Account and organisation records
Retained while the account or organisation remains active. Removed from the primary database when the organisation owner completes account deletion (subject to the limited deletion audit record below).
Domain and scan records
Retained while needed to provide scan history, comparisons, findings and reports. Deleted from the primary database when you delete the domain or delete the account. Protected backups may retain residual copies for up to 30 days until ordinary backup rotation completes.
Billing records
Billing references and payment-provider records may be retained for up to 7 years for financial, reconciliation, fraud-prevention and legal purposes. Stripe also retains its own records under Stripe's policies.
Support and product-quality records
Support messages, beta reports, uploaded media and false-positive reports may be retained for up to 24 months where needed to investigate the issue, prevent abuse or preserve the history of a decision, unless an earlier deletion request is completed.
Security and audit records
IP addresses, quota events, delivery events and security logs may be retained for up to 12 months. Account-deletion audit records may be retained for up to 24 months for security, fraud-prevention, billing reconciliation and legal recordkeeping.
Backups
Deleted information may remain temporarily in protected backups for up to 30 days until those backups are rotated or securely removed through ordinary backup processes.
14.Account deletion
Eligible organisation owners may request or initiate account deletion after completing the required identity and password confirmation.
Where an organisation has multiple members, ownership or member access may need to be resolved before the organisation can be deleted.
The current deletion process is intended to remove the primary user, organisation, domain, scan, managed-finding and related operational records associated with the organisation.
This limited record may be retained for security, fraud-prevention, billing reconciliation, dispute handling and legal recordkeeping.
Third-party providers, including payment and email providers, may retain their own records under their privacy policies and legal obligations.
Deleting an EightScope account cancels any active paid Stripe subscription associated with the organisation so that it does not renew. Charges already processed for the current billing period are not automatically refunded except where Australian Consumer Law requires otherwise.
If billing cancellation cannot be confirmed, account deletion is blocked and you will be asked to cancel billing in Settings first or contact support.
Some support, beta or false-positive records may require separate review. False-positive reports associated with the organisation are removed with the organisation. Certain beta-program records and uploaded beta media may not be fully removed by the current automated deletion process and may need a support request.
To request deletion or review of retained information, contact support.
15.Access and correction
You may request access to personal information EightScope holds about you and request that inaccurate or incomplete information be corrected.
Some account, organisation, monitoring and billing information can be viewed or updated through the dashboard.
For other requests, contact support using the address below.
EightScope may need to verify identity and authority before providing information, particularly where a request concerns an organisation or security scan.
Where permitted by law, EightScope may refuse or limit access where disclosure would:
- reveal another person’s information
- create a security risk
- expose confidential security evidence
- interfere with an investigation
- be unlawful
- disclose information that the requester is not authorised to access
Where a request is refused, EightScope will explain the reason where legally permitted.
Public information appearing in scan results
If personal information about you appears in a scan because it is publicly exposed on an authorised target, you may contact EightScope to request review, correction or removal.
Provide enough information to identify the relevant domain, page, scan or finding, but do not send passwords or sensitive credentials.
EightScope may need to consult the customer organisation responsible for the authorised scan before changing customer-controlled records.
16.Privacy complaints
To make a privacy complaint, email EightScope with:
- your name or account email
- a description of the concern
- the information or activity involved
- the outcome you are seeking
- any relevant dates or references
Use “Privacy complaint” in the subject line.
EightScope will acknowledge and investigate the complaint and aims to respond within 30 days where reasonably practicable.
If more time is required, EightScope will explain the reason and provide an updated timeframe.
If you are not satisfied with the response and Australian privacy law applies, you may be able to complain to the Office of the Australian Information Commissioner.
17.Data breaches
A data breach can involve personal information being lost or accessed or disclosed without authorisation.
EightScope will investigate suspected privacy and security incidents and take reasonable steps to contain and address them.
Where the Notifiable Data Breaches scheme or another applicable law requires notification, EightScope will notify affected individuals and the relevant regulator.
Not every security incident is legally notifiable. Notification depends on the information involved, likely harm, remedial action and applicable law.
Customers should contact support immediately if they believe their account or organisation has been accessed without authorisation.
18.Children
EightScope is intended for business and professional use and is not directed to children under 18.
EightScope does not knowingly invite children to create accounts or submit personal information.
If you believe a child has provided personal information, contact support so that the information can be reviewed and, where appropriate, removed.
19.Automated scanning and scoring
EightScope uses automated software to discover assets, perform technical checks, classify findings and calculate security scores and grades.
These automated outputs concern domains, systems and externally observable security conditions.
Customers must independently validate important findings and must not use EightScope outputs as the sole basis for a decision that significantly affects an individual. See the Scan Methodology.
Scoring and scanning are not AI. Optional AI-assisted wording, when enabled, is described in Optional AI-assisted wording.
20.Optional AI-assisted wording
When optional AI-assisted report wording is enabled for an organisation and a generation runs, EightScope may send allowlisted, sanitised finding metadata and report facts to Amazon Bedrock in Sydney (ap-southeast-2) to produce plain-English wording.
Optional AI-assisted report wording never changes findings, evidence, severity, priority, score or grade. EightScope remains authoritative for those results.
Inputs are allowlisted and sanitised. EightScope does not send the complete scan result, raw evidence, hostnames, email addresses, IP addresses or WHOIS records to the model by design.
Generated output is validated. Output that introduces unsupported claims or structural changes is rejected and is not stored or displayed.
Accepted AI output is stored in a separate database record linked to the scan. Rejected model output is not persisted. Linked AI records are cascade-deleted when the scan or organisation is deleted from the primary database.
EightScope requires the Bedrock account retention mode to report none before generation; generation is blocked when that requirement cannot be verified. Successful retention checks may be cached briefly. This describes Bedrock request and response data under the configured zero-data-retention mode, not a claim that AWS stores nothing whatsoever elsewhere.
AI-assisted wording is optional and off by default. Opening a saved report or downloading a PDF reads stored ready output only and does not call the model again.
There is currently no customer self-service control in the dashboard to turn AI-assisted wording on or off. Operators control availability with a global feature flag and organisation allowlist.
Related pages: Trust Centre, Methodology, and the FAQ.
21.Changes to this policy
EightScope may update this policy when the service, providers, laws or information-handling practices change.
The updated policy will display a revised last-updated date.
Where a change is material, EightScope will provide additional notice through the website, dashboard or account email where reasonably practicable.
Changes do not retrospectively authorise a materially different use of personal information where consent or another legal basis is required.
22.Contact
Privacy enquiries
For privacy questions, access or correction requests, deletion requests or complaints, contact:
- Legal entity
- Heuristic Group Pty Ltd
ABN 37 700 907 080 - Privacy contact
- support@eightscope.au
Please do not send passwords, private keys, access tokens or other security credentials by email.