Legal Document

Privacy Policy

Fortuna_Security LLC  |  Effective Date: January 1, 2026  |  Last Revised: May 2026

What This Means in Plain Language

Contents

01

What Data We Collect & Why

Fortuna_Security processes personal, technical, and operational data through two channels: information you voluntarily provide, and metadata our systems automatically record to ensure platform security and service delivery.

A. Information You Provide Directly

Data TypeExamplesPurpose
Identity DataFirst name, last nameAccount creation, course enrollment, assessment scoping
Contact DataEmail address, phone numberService delivery, notifications, support
Authentication DataPassword hash (bcrypt), JWT tokensSecure portal access and session management
Organization DataCompany name, role, service interestClient engagement scoping and service customization
Technical Scope DataIP ranges, domain lists, asset inventoriesAuthorized penetration testing and security assessment delivery
Payment DataTransaction confirmationsHandled exclusively by external compliant payment processors. We do not store card numbers.
Application DataResume, cover letter, portfolio URLCareers — candidate evaluation only
Course Progress DataEnrolled courses, lab completions, scoresAcademy — student progress tracking and instruction

B. Automatically Collected Technical Metadata

To enforce rate-limiting, verify authorization boundaries, and protect the platform from unauthorized access, our backend automatically records:

02

Legal Basis for Processing

Where applicable under GDPR or equivalent data protection frameworks, we process your data on the following legal bases:

03

How We Use Your Data

We use the data we collect for the following specific purposes and no others:

What We Do Not Do

We do not sell, rent, or trade your personal data to any third party. We do not use your data for advertising profiling or behavioral targeting. We do not aggregate client vulnerability data across engagements or share findings between client environments.
04

Session Tokens, JWTs & Browser Storage

Fortuna_Security does not use third-party advertising cookies or cross-site tracking mechanisms. Authentication on this platform is managed through JSON Web Tokens (JWTs) — cryptographically signed, stateless tokens stored in your browser's sessionStorage.

These tokens expire after 24 hours and are not persistent across browser sessions. They contain your user ID, role, and token expiry timestamp — nothing else. They are signed with a server-side secret and cannot be forged or tampered with.

Clearing your browser storage or closing your browser session will log you out. This is by design. We do not use persistent cookies that track you across other websites.

What This Means for You

No advertising network can identify you through tokens issued by this platform. Your session is local to your browser tab. We cannot see what other sites you visit.
05

Data Sharing & Third-Party Processors

We share data only with trusted third-party service providers who are contractually bound to process data only on our behalf and in accordance with this policy. Current categories of processors include:

We do not sell, rent, license, or otherwise transfer your personal data to data brokers, advertising networks, analytics companies, or any other third party for commercial purposes.

06

Law Enforcement & Legal Disclosure

We may also disclose data in response to a valid court order, subpoena, or other lawful legal process. Where permitted by law, we will attempt to notify you of such a request before complying. We will challenge any legal demand we believe to be overbroad or unlawful.

07

Technical Safeguards

Fortuna_Security applies the following technical and administrative controls to protect your data:

You acknowledge that no internet-facing application can be guaranteed completely secure against sophisticated or coordinated exploitation. We apply industry-standard controls and disclose our security posture transparently — but we do not make absolute guarantees of imperviousness.

08

Client Vulnerability Data Isolation

Technical findings, assessment outputs, network vulnerability details, and configuration weaknesses generated during security engagements are treated as strictly confidential client data. Fortuna_Security enforces the following isolation controls:

09

Data Retention & Deletion

We retain data only for as long as necessary to fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

Data CategoryRetention Period
Account profile data (name, email, role)Duration of account + 90 days post-deletion request
Course enrollment and progress recordsDuration of enrollment + 1 year for academic records
Security assessment deliverablesDuration of engagement + 2 years (legal obligation window)
Security audit logs (hashed IPs, request metadata)90 days rolling, then automatically purged
Honeypot and intrusion telemetry1 year (law enforcement referral window)
Booking and payment confirmation records7 years (standard financial record obligation)
Career applications6 months post-decision, unless candidate consents to longer retention

To request deletion of your account and associated data, contact privacy@fortunasecurity.com. We will acknowledge your request within 5 business days and complete deletion within 30 calendar days, subject to any legal retention obligations that prevent immediate deletion.

10

Your Privacy Rights (CCPA / GDPR)

Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights for all users regardless of location.

Right to Access

Request a copy of all personal data we hold about you, including what it is, why we have it, and how it is used.

Right to Rectification

Request correction of inaccurate or incomplete personal data in your account profile.

Right to Deletion

Request erasure of your personal data, subject to legal retention obligations that may prevent immediate deletion.

Right to Restriction

Request that we limit processing of your data in certain circumstances, such as while a dispute is being resolved.

Right to Data Portability

Request your personal data in a structured, machine-readable format for transfer to another service.

Right to Opt Out (CCPA)

California residents have the right to opt out of the sale of personal information. We do not sell data, so this right is not applicable — but we honor the principle.

Right to Object

Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect prior lawful processing.

How to Exercise Your Rights

Submit a written request to privacy@fortunasecurity.com with your name, account email, and the specific right you wish to exercise. We will respond within 30 calendar days. We may require identity verification before processing requests that involve access to or deletion of account data.
11

Children's Privacy (COPPA)

Fortuna_Security services are intended exclusively for individuals 18 years of age or older. We do not knowingly collect, solicit, or process personal information from anyone under 18. Our Terms of Service require users to confirm they meet this age requirement at account creation.

If we become aware that we have inadvertently collected personal information from a person under 18, we will delete that information from our systems within 72 hours of discovery. If you believe a minor has created an account on our platform, contact us immediately at privacy@fortunasecurity.com.

12

Data Breach Notification

In the event of a security incident that results in unauthorized access to, disclosure of, or destruction of personal data, Fortuna_Security will:

Notification will include: the nature of the breach, categories of data affected, likely consequences, and steps we have taken or will take to mitigate harm.

13

Cross-Border Data Transfers

Our platform is operated from the United States. If you are accessing our services from outside the United States, your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For users in the European Economic Area (EEA) or United Kingdom, data transfers are conducted under appropriate safeguards including Standard Contractual Clauses (SCCs) or equivalent mechanisms recognized under applicable data protection law. By using our services, you acknowledge and consent to this transfer.

14

Policy Updates & Contact

We reserve the right to update this Privacy Policy to reflect changes in our services, legal obligations, or data handling practices. When material changes are made, we will update the "Last Revised" date at the top of this document and notify registered users by email at least 14 days before the revised policy takes effect.

Continued use of the platform after the effective date of a revised policy constitutes acceptance of the updated terms. If you do not agree to a revised policy, you must discontinue use and may request account deletion.

Privacy Contact Channels

Privacy Requests privacy@fortunasecurity.com
Legal Inquiries legal@fortunasecurity.com
Security Issues security@fortunasecurity.com
Data Deletion privacy@fortunasecurity.com — response within 5 business days
Response Time 30 calendar days for all privacy rights requests