← Back to homepage

Privacy Policy

Last updated: 2026

Outward Security ("we," "us") provides a monthly report on information about your business that is already publicly visible on the internet. This page explains what we collect and how we use it.

What we collect

  • The business domain and contact email you give us at signup.
  • Billing information, handled entirely by Stripe — we never see or store your card details ourselves.
  • Publicly available technical information about the domain you submit: DNS records (SPF/DMARC/DKIM), SSL/TLS certificate details, and HTTP response headers.

What we never do

  • We never ask for or store login credentials, passwords, or any information that requires authentication to access.
  • We never run penetration tests, exploit attempts, or any active/intrusive scanning — only publicly published information is used.
  • We do not sell your information to third parties.

How we use it

Your domain and email are used to generate and deliver your monthly report, and to send you account-related notices (like a failed payment). Reports are sent from our email system and, if a report needs manual review before sending, a member of our team may look at the draft before it goes out.

Data retention

We retain your contact email, domain, and past report data for as long as your subscription is active, plus a reasonable period afterward for records purposes. You can request deletion of your data at any time by contacting us.

Third parties

We use Stripe for payment processing (see Stripe's own privacy policy) and our own email provider to deliver reports. Neither is given more information than needed to perform their function.

Contact

Questions about this policy or your data? Reply to any report email, or contact us directly.