Who we are and how to reach us
Sanctum SecOps LLC ("Sanctum SecOps", "we", "us") is a cybersecurity firm and software provider organised in New York, United States. For the purposes of the EU and UK General Data Protection Regulation we are the controller of the personal information described in this policy, except where we process customer data on a customer's behalf, in which case we act as a processor under that customer's agreement with us.
- Postal: Sanctum SecOps LLC, 128 Dry Run Rd, Pine City, NY 14871, United States
- Email: [email protected]
- Telephone: +1 (607) 378-8287
- Privacy requests: send them to the email address above with "Privacy request" in the subject line. A person reads that inbox; there is no automated intake.
We have not appointed an EU or UK representative under Article 27 GDPR, and we are not required to appoint a statutory data protection officer. Requests go to the address above and are handled by the company directly.
What this policy covers
This policy applies to every website, subdomain, customer portal, storefront, service desk and email programme operated by Sanctum SecOps, including the following domains and any host beneath them.
- sanctumsecops.com — commercial site, customer portal, investor room and operator consoles
- cygnetssl.com — certificate storefront and order path
- sanctumsecops.org — free and per-transaction tools
- sanctumsecops.io — standards, PKI policy, CRL and OCSP endpoints
- sanctumsecops.us — federal and procurement surface
- sanctumsecops.net — internal infrastructure surface
- sanctumsecops.tech — service status and incident history
- sso-labs.com and sso-labs.net — research, laboratory and prototype surfaces
It does not cover a third party whose site or product you reach from ours. Where a service we use hosts a surface under our own hostname — for example our service desk and knowledge base — that service processes data under our instruction and is listed in the processors section below.
What we collect
We collect only what a specific interaction requires. We do not buy personal information, we do not build advertising profiles, and we do not track you across sites we do not operate.
| Category | What it includes | Where it comes from | Why we have it |
|---|---|---|---|
| Contact and business details | Name, employer, job title, work email address, telephone number, postal address | You, when you email us, request a quote, submit a form, sign an agreement or open a service desk ticket | To answer you, quote work, perform a contract and keep business records |
| Account and portal data | Account identifier, authentication events, roles and entitlements, API key identifiers and their metadata | Created when an account is provisioned, and generated as you use the portal or an operator console | To operate the account, authorise access and investigate misuse |
| Certificate order data | Requested domain names, organisation name and address, the certificate signing request, and the name, email address and telephone number of the person who approves validation | You, when you place or validate a certificate order | To place the order, and because the issuing certificate authority requires it to validate and issue |
| Email programme data | Email address, delivery outcome, bounces and complaints, whether a message was opened, and which links were clicked, together with the IP address and user agent recorded when that happens | Generated when we send you email and you interact with it | To send the messages you asked for, keep our sending reputation healthy and stop mailing people who do not want it |
| Support content | Whatever you write in a ticket or attach to it, including any logs or configuration you choose to send | You | To resolve the issue you raised |
| Technical logs | IP address, timestamp, requested URL, HTTP status, referrer and user agent, plus edge security decisions such as a rate limit or a challenge | Generated automatically when your browser or client reaches our edge or our servers | To keep the service available, to detect and investigate abuse, and to comply with legal obligations |
| Evidence records | Records of certificate issuance, rotation, revocation and related approvals, which may include the identifier of the person who approved an action | Generated by our own systems when a state change happens | To provide the verifiable provenance that is the point of the product |
We do not ask for and do not want special category data, government identifiers, payment card numbers entered on our sites, or health information. Do not send them in a ticket or an email. If you do, we will delete them once the issue is closed unless we are required to keep them.
Email, and the platform that sends it
We use Customer.io, operated by Peaberry Software, Inc., to send and manage email. Customer.io processes your email address, the content of the messages we send you, and the resulting engagement data — deliveries, bounces, complaints, opens and link clicks, along with the IP address and user agent captured when a message is opened or a link is followed. Customer.io acts as our processor under a data processing agreement and processes this data in the data region configured for our account. It does not use it for its own purposes.
We separate two kinds of message and treat them differently.
- Transactional and service messages — order confirmations, certificate issuance and expiry notices, security and incident notifications, invoices, and replies to something you asked. These are necessary to perform our contract with you or to protect the service. You cannot unsubscribe from an expiry warning for a certificate you own, because a silent expiry is an outage.
- Marketing messages — product news, standards updates and event invitations. We send these on the basis of your consent, or where permitted for an existing business contact under applicable law. Every one carries a working one-click unsubscribe link and our postal address.
Unsubscribing takes effect immediately and applies to all marketing email. You can also unsubscribe by replying to any message or by emailing [email protected]. We keep a record that you unsubscribed — the email address and the date — because that is the only reliable way to make sure we do not mail you again; that suppression record is retained even if we delete everything else.
Open and click measurement can be defeated by your mail client, and we do not treat it as reliable. If you would rather not be measured at all, disable remote image loading in your client and tell us you want to be excluded from engagement tracking, and we will suppress it for your address.
We comply with the CAN-SPAM Act, and where applicable Canada's Anti-Spam Legislation and the GDPR and PECR rules on electronic marketing. We do not rent, sell or trade our mailing list, and we do not send on behalf of third parties.
Why we process it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Answering an enquiry, quoting work, and performing an engagement or a certificate order | Performance of a contract, or steps taken at your request before entering one — Article 6(1)(b) |
| Operating accounts, authenticating access and maintaining audit and evidence records | Performance of a contract, and our legitimate interest in a secure and accountable service — Article 6(1)(b) and 6(1)(f) |
| Keeping the service available and investigating abuse, fraud or attack | Legitimate interest in the security of our systems and our customers — Article 6(1)(f) |
| Sending transactional and security notifications | Performance of a contract, and legal obligation where a notification is required — Article 6(1)(b) and 6(1)(c) |
| Sending marketing email | Consent, or legitimate interest for an existing business contact where the law allows it — Article 6(1)(a) or 6(1)(f) |
| Meeting accounting, tax, export-control and contractual record-keeping duties | Legal obligation, and legitimate interest in defending legal claims — Article 6(1)(c) and 6(1)(f) |
We do not make decisions about you by automated means that produce legal effects or otherwise significantly affect you, and we do not profile you for advertising.
Who we share it with
We do not sell personal information and we do not disclose it for anyone else's marketing. We share it with the service providers below, each under a written agreement that limits them to processing it on our instruction, and with the recipients described in the two paragraphs that follow the table.
| Provider | What it does for us | What it processes |
|---|---|---|
| Customer.io (Peaberry Software, Inc.) | Sends and manages our email programme | Email address, message content, delivery and engagement data, IP address and user agent |
| Cloudflare, Inc. | DNS, edge network, DDoS and bot protection, zero-trust access to gated hosts, and the tunnel that fronts our origin | IP address, request metadata, security decisions, and identity assertions for gated hosts |
| BoldDesk (Syncfusion, Inc.) | Service desk and knowledge base under our own hostnames | Your name, email address, and everything in your tickets |
| Microsoft Corporation | Business email, calendaring, documents and directory for our own staff | Correspondence with us and internal business records |
| Neon, Inc. | Managed PostgreSQL behind the portal and the evidence ledger | Account records, order records and evidence entries |
| The SSL Store (Rapid Web Services, LLC) and the issuing certificate authorities it fronts, including DigiCert, Sectigo, GeoTrust, Thawte and RapidSSL | Places, validates and fulfils orders for publicly trusted certificates | Order details, organisation details, requested domain names, and the validation contact's name, email address and telephone number |
| GitHub, Inc. | Source control and release artifacts for the software we publish | Only what you choose to put in a public issue or pull request |
This list changes as our stack changes. The version in force is the one published here on the effective date at the top of this document.
We also disclose information where the law requires it — to comply with a valid legal process, to enforce our agreements, or to protect the rights, safety or property of Sanctum SecOps, our customers or the public. Where we are permitted to tell you about a demand for your data, we will.
If the business or a business line is sold, merged or reorganised, information may transfer to the acquirer as part of that transaction, subject to this policy or a policy at least as protective.
Certificate Transparency: what becomes permanently public
This section matters more than any other for anyone ordering a certificate, and it is the one that a general-purpose privacy policy would omit.
Publicly trusted TLS certificates are published to Certificate Transparency logs. Those logs are append-only, operated by independent third parties, mirrored worldwide, and permanent. Every domain name in a certificate — including any subdomain you request — becomes public information the moment the certificate is issued, and it stays public forever. Certificates validated at the organisation or extended-validation level also publish your organisation's name and address.
We cannot remove an entry from a Certificate Transparency log, and neither can the certificate authority. Revoking a certificate does not remove its log entry. If a hostname would reveal something you do not want public, do not put it in a publicly trusted certificate: use a wildcard, or use a private CA. We will help you pick the right shape before the order is placed.
Separately, our sanctum-chain evidence ledger is append-only by design, because a provenance record you can quietly rewrite is worthless. Where we hold personal information in it — typically the identifier of the person who approved an action — a correction is recorded as a new entry that supersedes the earlier one rather than by deleting history. We minimise what enters the ledger for exactly this reason.
How long we keep it
| What | How long |
|---|---|
| Enquiries that do not become engagements | Up to 24 months from the last contact, then deleted |
| Customer account and contract records | For the life of the account and 7 years afterwards, for tax, accounting and limitation-period reasons |
| Certificate order records | For the life of the certificate and 7 years afterwards, because a certificate's issuance record has to outlive the certificate |
| Service desk tickets | 36 months from closure |
| Email engagement data | 25 months from the event |
| Unsubscribe and suppression records | Indefinitely, so we do not mail you again |
| Technical and security logs | 90 days in the ordinary course, longer for a specific record preserved for an investigation or a legal hold |
| Evidence ledger entries | Retained for the lifetime of the ledger, corrected forward rather than deleted |
Your rights
Depending on where you live, you have some or all of the following rights. We apply them to everyone who asks, rather than checking your jurisdiction first.
- Access — get a copy of the personal information we hold about you.
- Correction — have inaccurate information fixed.
- Deletion — have information erased, subject to the records we are required or permitted to keep, and subject to the append-only and Certificate Transparency limits described above.
- Portability — receive information you gave us in a portable, machine-readable format.
- Restriction and objection — ask us to pause a use, or object to processing based on our legitimate interests.
- Withdraw consent — at any time, including by unsubscribing. Withdrawal does not affect processing that already happened.
- Opt out of sale, sharing or targeted advertising — we do none of these, so there is nothing to opt out of.
- Non-discrimination — exercising a right will not get you worse service or a worse price.
To exercise any of these, email [email protected]. We will acknowledge within 10 business days and respond substantively within 30 days, or within 45 days for a California request, extending once where the law allows and telling you if we do. We will ask you to verify your identity, using information we already hold — we will not demand new identity documents. An authorised agent may act for you with written authority.
If you are in the EU or the UK you may complain to your supervisory authority; in the UK that is the Information Commissioner's Office. If you are in California you may contact the California Privacy Protection Agency or the Attorney General. We would rather you came to us first, and we will not treat a complaint as a reason to end our relationship.
International transfers
We are based in the United States and our infrastructure and providers are principally located there, so information you send us is processed in the United States. Where we receive personal information from the EU, the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where relevant, together with the technical measures described below. A copy of the clauses relevant to your data is available on request.
How we protect it
We are a cryptography firm, so the standard we hold ourselves to is the one we sell.
- Transport is TLS 1.3 with FIPS-approved cipher suites. Public surfaces are fronted by Cloudflare; origins are not directly reachable from the internet.
- Cryptographic operations use FIPS 140-3 validated modules and FIPS-approved algorithms — AES-256-GCM, the SHA-2 family, HMAC-SHA-2, ECDSA P-256 and P-384, RSA-3072 and above — with the FIPS 203, 204 and 205 post-quantum algorithms where a post-quantum path is in use.
- Gated surfaces sit behind zero-trust access control with per-host policy; signing and administrative keys are held in hardware.
- Access to production data is least-privilege and logged, and administrative actions against the PKI generate evidence records.
- Backups are encrypted, and restore is tested rather than assumed.
No control set is perfect. If a breach affects your personal information we will notify you and any regulator we are required to notify, without undue delay and within the deadlines the law sets, and we will tell you what happened rather than issuing a statement that says nothing.
To report a vulnerability or a suspected exposure, email [email protected] with "Security" in the subject line. We do not pursue researchers who act in good faith, stay within the scope of our acceptable use policy, and give us a reasonable chance to fix the issue before disclosing it.
Children
Our services are sold to businesses and government bodies and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
When we change this policy we update the effective and last-updated dates at the top. For a change that materially reduces your rights or materially expands how we use your information, we will give notice by email to affected customers and subscribers before it takes effect. Superseded versions are available on request.
This version's digest is recorded in the Sanctum evidence ledger as a policy event, so a reader can confirm which text was in force on a given date. It is computed over every reader-visible string in this document, trimmed and newline-joined in document order, encoded UTF-8 — recompute it yourself if you want to check.