Privacy Policy
Last updated: August 6, 2026
1. Overview
This Privacy Policy explains what information Sense Six Cyber collects through the client portal (the “Service”), how it’s used, and the choices available to you. It applies to client contacts with portal accounts and to vendors who complete a security questionnaire through a link sent by a client.
2. Information we collect
- Account information — name, email address, and role, used to create and secure your portal login
- Authentication data — hashed password, and a second-factor secret if you enroll in 2FA
- Compliance and risk content — checklist progress, risk register entries, policy documents, and comments your organization submits through the Service
- Vendor information— vendor company details, contact emails, and questionnaire responses/documents submitted by your organization’s vendors
- Usage and audit data — an audit log of key actions taken in the portal (e.g. status changes, document uploads, questionnaire sends), and standard technical data such as IP address, used for authentication security and rate limiting
3. How we use information
We use the information above to:
- Provide, maintain, and secure the Service, including authenticating logins and applying rate limits to protect against abuse
- Deliver the GRC consulting engagement the Service supports (compliance tracking, risk management, vendor risk review)
- Send transactional email, such as questionnaire invitations, password resets, and account notifications
- Maintain an audit trail of actions taken in client accounts, for accountability and troubleshooting
- Investigate and respond to security incidents
We don’t sell your information, and we don’t use it to serve advertising.
4. Third-party service providers
The Service relies on the following sub-processors to operate. Each processes data only as needed to provide its function to us:
- Supabase — database, authentication, and file storage
- Resend — transactional email delivery (questionnaire invitations, notifications, password resets)
- Vercel — application hosting
- VirusTotal — malware scanning of uploaded files. [Confirm this section still matches production before publishing: the current integration uses VirusTotal’s free tier, which shares scanned file hashes/content with the wider VirusTotal community. If a paid, private-scanning tier hasn’t been adopted yet, this policy shouldn’t claim uploaded files are kept confidential during scanning.]
5. Data security
Data is stored in Supabase with row-level security policies that restrict each client’s data to that client’s own users and Sense Six Cyber administrators. Files are held in access-controlled storage buckets and scanned for malware on upload. Portal accounts support two-factor authentication, and repeated sign-in attempts are rate-limited. No method of transmission or storage is completely secure, and we can’t guarantee absolute security.
6. Data retention
We retain account and compliance data for as long as the engagement with your organization is active, and for a reasonable period afterward to meet legal, accounting, or contractual obligations. Contact us if you’d like data deleted sooner; some records may need to be retained where required by law or by the terms of the underlying engagement.
7. Your rights
Depending on your location, you may have rights to access, correct, or request deletion of your personal information, or to object to certain processing. To exercise these rights, contact us at sensesixcyber@gmail.com. We’ll respond within a reasonable time and may need to verify your identity first.
8. Cookies
The Service uses only the essential cookies needed to keep you signed in and maintain your session. We don’t use advertising or third-party tracking cookies.
9. Children’s privacy
The Service is intended for business use by adult professionals and isn’t directed at children. We don’t knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active client accounts. The “last updated” date at the top of this page reflects the most recent revision.
11. Contact
Questions about this Privacy Policy can be directed to sensesixcyber@gmail.com.
This document is a working draft prepared for the Service and hasn’t been reviewed by a lawyer. Have it reviewed by qualified legal counsel, and confirm the VirusTotal note in Section 4, before relying on it as binding.