Dreadnode

Privacy Policy

Last updated: March 23, 2026

1. Who We Are

Dreadnode, Inc. ("Dreadnode," "we," "our," or "us") is a Delaware corporation that provides the Dreadnode Platform (Strikes), an AI cyber security and red-teaming platform. We are the data controller for the personal data we collect through our platform and services.

If you have questions about how we handle your data, or wish to exercise any of your rights, you can reach us at:

  • Data Protection Officer: Nick Landers/CTO, privacy@dreadnode.io
  • General inquiries: support@dreadnode.io
  • Mailing address: Dreadnode, Inc., 2425 Technology Boulevard, Suite 2175, Bozeman, MT 59718

2. What Data We Collect

We collect the following categories of personal data in connection with the Dreadnode Platform:

CategoryExamplesRequired?
Identification dataName, username, user account identifiersYes — required for account creation
Contact dataEmail addressYes — required for account creation and communications
Authentication dataLogin credentials, session tokens, access logsYes — collected automatically for security
Technical and usage dataIP address, browser type and version, pages visited, timestamps, session data, platform interaction dataYes — collected automatically
Profile and preference dataCommunication preferences, role informationOptional
Communication contentSupport tickets, messages sent through the platformOnly when you contact us

We do not intentionally collect sensitive personal data (such as racial or ethnic origin, health data, or biometric data). If you upload sensitive data to the platform, you are responsible for ensuring you have a lawful basis to do so.

3. How and Why We Use Your Data

We process your personal data for the following purposes. For each purpose, we identify the lawful basis under the General Data Protection Regulation (GDPR) and the retention period:

PurposeWhat We DoLawful BasisRetention
Account managementCreating and managing your platform account, authentication, and authorizationContractUntil you request deletion
Product analyticsUnderstanding how users interact with the platform to improve the product experienceLegitimate interests24 months rolling
Customer supportResolving technical issues and service requests you submitContract3 years post-resolution
Marketing communicationsProduct announcements, newsletters, and promotional email campaignsLegitimate interests (with opt-out)30 days post-unsubscribe
Sales & CRMManaging prospect outreach and customer communicationsLegitimate interests3 years after last activity
Security monitoringThreat detection, access monitoring, compliance evidence collection, incident responseLegitimate interests12 months

Where we rely on legitimate interests, our interest is in operating, improving, and securing the Dreadnode Platform. You have the right to object to processing based on legitimate interests — see "Your Rights" below.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

4. Who We Share Your Data With

We share personal data with the following third-party service providers ("subprocessors") who process data on our behalf under written agreements imposing data protection obligations at least as protective as those described in this policy:

ProviderWhat They Do For UsLocationSafeguard
Amazon Web Services (AWS)Cloud infrastructure, compute, storage, security monitoringUSADPF / SCCs
ClickHouseDatabase services for platform dataUSASCCs
CloudflareWeb security, CDN, threat detectionUSADPF / SCCs
Google WorkspaceAuthentication, document management, customer supportUSA / IrelandDPF / SCCs
HubSpotCRM, sales, marketing communicationsUSADPF / SCCs
LoopsEmail marketing automationUSASCCs
PostHogProduct analytics and user behavior telemetryUSASCCs
SlackInternal communications, customer support channelsUSA / IrelandDPF / SCCs

We do not sell your personal data to third parties. We do not share your personal data for cross-context behavioral advertising.

We may also disclose personal data when required by law, regulation, court order, or other legal process, or when necessary to protect our rights, your safety, or the safety of others.

5. International Data Transfers

Your personal data may be transferred to and processed in the United States and Ireland. When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on the following safeguards:

  • EU-U.S. Data Privacy Framework (DPF) self-certification, where applicable
  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Addendum (IDTA)

The specific transfer mechanism for each subprocessor is shown in the table in Section 4 above.

6. How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfill the purposes described in Section 3. Specific retention periods are listed in the table in Section 3. When a retention period expires or you request deletion, we will securely delete or anonymize your data within 30 days, unless a longer retention period is required by applicable law (for example, employment records are retained for 7 years as required by law).

7. Your Rights

If you are in the EEA, UK, or Switzerland (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate or incomplete data
  • Erasure — Request deletion of your personal data ("right to be forgotten")
  • Restriction — Request that we limit how we process your data
  • Portability — Request your data in a structured, machine-readable format
  • Object — Object to processing based on legitimate interests, including for direct marketing
  • Withdraw consent — Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at privacy@dreadnode.io. We will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

If you are in California (CCPA/CPRA)

Under the California Consumer Privacy Act, California residents have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete personal information we hold about you
  • Opt out of the sale or sharing of personal information — we do not sell or share your personal information for cross-context behavioral advertising
  • Non-discrimination for exercising your privacy rights

To submit a request, contact us at privacy@dreadnode.io. We will verify your identity before processing your request.

8. Cookies and Tracking Technologies

We use the following technologies to collect technical and usage data automatically when you use the Dreadnode Platform:

  • PostHog — Product analytics to understand platform usage patterns and improve the user experience. Data is retained for 24 months on a rolling basis.
  • Cloudflare — Web application firewall and CDN for security and performance. Cloudflare processes technical data (IP address, request metadata) for threat detection.

We do not use third-party advertising cookies. We do not engage in cross-site tracking.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit and at rest, access controls, regular security testing, and incident response procedures. We maintain compliance with the ISO 27701 privacy framework and conduct periodic reviews of our security practices.

While we take reasonable measures to protect your data, no system is completely secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant supervisory authorities as required by applicable law.

10. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, applicable law, or the ISO 27701 framework. When we make material changes, we will notify you by email to the address associated with your account before the changes take effect. The "Last updated" date at the top of this page indicates when this policy was most recently revised.

11. Contact Us

If you have questions about this policy, wish to exercise your data protection rights, or have a concern about how we handle your data:

  • Privacy and data protection inquiries: privacy@dreadnode.io
  • General support: support@dreadnode.io
  • Data Protection Officer: Nick Landers/CTO, privacy@dreadnode.io
  • Mailing address: Dreadnode, Inc., 2425 Technology Boulevard, Suite 2175, Bozeman, MT 59718

If you are in the EEA, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.