Vorpcel Vorpcel

Products

Applications

Web Application Firewall Inspect requests and enforce application security policies Content Delivery Network Accelerate content delivery with global edge caching

Abuse & fraud

Behavior Defense Identify enumeration, probing and abusive request patterns Account Defense Detect suspicious sign-ins and account takeover signals

Attack surface

Attack Surface Management Discover exposed assets and monitor security posture

Response security

Outbound Control Monitor script integrity and browser data destinations

Cloud

Cloud Defense (CNAPP) Prioritize cloud risk across resources and identities

The platform

Application protection, exposure monitoring and cloud risk management in one platform. Build coverage around your environment.

Request a trial

Solutions

Protect applications

Application & API security Reduce exposure to exploits and malicious requests Bot & DDoS mitigation Control automated traffic and application-layer floods API & business-logic abuse Investigate abuse across API requests and sessions

Protect users & data

Client-side & data protection Script integrity, CSP and outbound control Account takeover & credential abuse Investigate credential attacks and suspicious sign-ins

Manage risk & compliance

Attack surface management Continuous discovery and posture Cloud security posture Connect cloud exposure, permissions and data risk Compliance & PCI DSS Evidence for payment-page and audit requirements

Deliver & accelerate

Content delivery & performance Global caching and delivery at the edge

Not sure where to start?

Share your security priorities. Our team will help define the products and coverage that fit your environment.

Talk to sales
Blog About Contact
Request a trial
Home Web Application Firewall Outbound Control Attack Surface Management Account Defense Behavior Defense Content Delivery Network Cloud Defense (CNAPP) Blog About us Contact
Request a trial
Legal

Privacy Notice

How Vorpcel collects, uses, shares, and protects personal data, and the rights you have over your information.

On this page

  1. Scope & controller
  2. Information we collect
  3. How we collect it
  4. How we use information
  5. Legal bases
  6. Payments
  7. Cookies & tracking
  8. Sharing & disclosure
  9. International transfers
  10. Data retention
  11. Security
  12. Your rights
  13. Children's privacy
  14. Third-party links
  15. Changes
  16. Contact

This Privacy Notice explains how Vorpcel ("Vorpcel", "we", "us", "our") handles personal data in connection with our website, dashboard, Web Application Firewall, Web Application Scanner, and related services (the "Service"). We are committed to processing personal data lawfully, transparently, and only as necessary to operate and improve the Service. By using the Service, you acknowledge the practices described here.

1. Scope & controller

This Notice applies to personal data we process as a controller about visitors, prospects, account holders, and authorized users. It does not change any separate data-processing terms that may apply where Vorpcel processes data on your behalf as a processor (for example, security telemetry generated by traffic to your Protected Assets). For payment data, our third-party payment provider acts as an independent controller, as described below.

2. Information we collect

  • Account information: name, email address, company name, password (stored hashed), and preferences you provide when registering or contacting us.
  • Billing information: subscription and transaction status, plan, and billing country. Full payment-card details are collected and processed by our payment provider, not stored by us.
  • Configuration data: the domains, origins, applications, and policies you configure for the WAF or submit to the Scanner.
  • Security & operational telemetry: request metadata, detection events, scan findings, IP addresses, user agents, and logs generated while delivering protection and scanning.
  • Usage & device data: pages visited, features used, approximate location derived from IP, browser and device type, and similar diagnostic data.
  • Communications: messages you send us through forms, email, or support.

3. How we collect it

We collect data: (a) directly from you, when you register, configure the Service, subscribe, or contact us; (b) automatically, through cookies and server logs as you use the website and Service; and (c) from third parties, such as our payment provider (transaction and subscription status) and infrastructure providers that help us operate.

4. How we use information

  • to provide, operate, and maintain the Service, including delivering WAF protection and Scanner assessments;
  • to authenticate users and secure accounts;
  • to process subscriptions, renewals, and related billing;
  • to communicate with you about your account, security events, service changes, and support;
  • to improve detection quality, develop features, and ensure performance and reliability;
  • to detect, prevent, and respond to fraud, abuse, and security incidents; and
  • to comply with legal obligations and enforce our terms.

We do not sell personal data, and we do not use the content of your security telemetry for advertising.

5. Legal bases

Where data-protection law such as the GDPR applies, we rely on: performance of a contract (to provide the Service you request); legitimate interests (to secure, improve, and operate the Service, balanced against your rights); legal obligation (to meet accounting, tax, and compliance duties); and consent (for certain cookies or communications, where required). You may withdraw consent at any time without affecting prior processing.

6. Payments

All purchases are processed by our third-party payment provider, which acts as an independent controller for payment data. When you subscribe, the information needed to complete and manage your order. Such as name, email, billing address, payment details, and tax information. Is collected and processed directly by that provider under its own privacy policy. We receive the transaction and subscription information we need to provision and manage your plan, but we do not receive or store your full payment-card data.

7. Cookies & tracking

We use strictly necessary cookies for authentication, session management, and security (such as CSRF protection), and limited analytics to understand how the website and dashboard are used so we can improve them. Checkout pages may set cookies controlled by our payment provider. You can control non-essential cookies through your browser settings; disabling necessary cookies may impair core functionality.

8. Sharing & disclosure

We share personal data only:

  • with service providers and subprocessors that help us operate the Service (for example, payment processing, cloud infrastructure, email delivery, and analytics), under appropriate confidentiality and data-protection obligations;
  • when required by law, legal process, or to respond to lawful requests from authorities;
  • to protect the rights, safety, and security of Vorpcel, our customers, and others, including to prevent fraud or abuse; and
  • in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this Notice.

9. International transfers

Vorpcel and its providers may process personal data in countries other than your own. Where we transfer data internationally, we rely on appropriate safeguards recognized under applicable law (such as standard contractual clauses) to protect your information.

10. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet our legal, accounting, and security obligations, after which it is deleted or anonymized. Security and operational logs are retained for a limited period appropriate to their purpose. You may request deletion as described under "Your rights".

11. Security

We apply technical and organizational measures designed to protect personal data, including encryption in transit, access controls, hashed credentials, network protection, and monitoring. No method of transmission or storage is completely secure; while we work to protect your data, we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will act in accordance with applicable law.

12. Your rights

Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; receive a portable copy of your data; and lodge a complaint with a supervisory authority. Residents of certain regions (for example, the EEA/UK under GDPR, or California under the CCPA/CPRA) have specific statutory rights, including the right not to be discriminated against for exercising them. To exercise any right, contact us at the address below; we may need to verify your identity before responding.

13. Children's privacy

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, please contact us so we can delete it.

14. Third-party links

Our website may link to third-party sites and services that we do not control. This Notice does not apply to those sites, and we encourage you to review their privacy policies.

15. Changes to this notice

We may update this Notice to reflect changes in our practices or for legal reasons. Material changes will be communicated through the Service or by email. Your continued use after changes take effect indicates acknowledgment of the updated Notice.

16. Contact

For privacy questions or to exercise your rights, contact us at support@vorpcel.com. For matters relating to payment data, please also refer to the privacy policy of our payment provider, available on its website.

Questions about this policy?

Our team is happy to help clarify anything.

Talk to the team
Vorpcel Vorpcel

Security for applications, identities and cloud environments.

© 2026 Vorpcel. All rights reserved.

Platform

Web Application Firewall Outbound Control Attack Surface Management Account Defense Behavior Defense Content Delivery Network Cloud Defense (CNAPP)

Get started

Request a trial

Company

About us Careers Blog Contact

Legal

Terms of Service Privacy Notice Refund Policy