Skip to main content
Varaxon Technologies
  • Sign in
  • Create account
  • Pre-flight
  • Feedback
Menu
  • Sign in
  • Create account
  • Pre-flight
  • Feedback

Varaxon Technologies LLC — Privacy Policy

Document set version: v1.0, effective September 11, 2026
Last updated: September 11, 2026
Company: Varaxon Technologies LLC
Contact: support@varaxontech.com
Service domains: varaxontech.com and scan.varaxontech.com

This Privacy Policy explains how Varaxon Technologies LLC ("Varaxon," "we," "us," or "our") processes personal information when you visit our marketing site, use Varaxon Scan Hub, create an account, contact support, or use related services.

At launch, Varaxon Scan Hub is intended for U.S. customers. We do not knowingly market the service as available in the EU, United Kingdom, Switzerland, Iceland, Liechtenstein, Norway, or Canada. If our customer geography changes, we will update this policy and the applicable terms before expanding the service.

Information we collect

Information you provide

Depending on how you use the service, we may collect:

  • email address;
  • a password hash generated with scrypt and a unique salt (we do not store your plaintext password);
  • account creation and email-verification dates;
  • subscription status, plan tier, renewal date, current-period report count, period start, and report-credit balance;
  • Stripe customer identifier and processed Stripe event identifiers;
  • API-key identifiers, names, created/revoked dates, and one-way API-key hashes (we do not store the API-key secret);
  • hashed session identifiers and hashed email-verification or password-reset token values; and
  • support messages and other information you voluntarily send us.

Payment information

We do not collect or store payment-card numbers, CVC/security codes, or full payment-instrument details. Payment entry and processing occur on Stripe's hosted checkout infrastructure. We receive limited billing information from Stripe, such as a Stripe customer identifier, subscription state, payment status, and related event identifiers. Stripe's privacy information is available at Stripe's Privacy Center.

Scan and report data

The synchronous report service processes uploaded Nessus and Greenbone exports in request-scoped memory. It does not intentionally retain the uploaded scan or generated report after the request completes. The report may contain security and system information supplied by the customer, so customers must upload only data they are authorized to process.

The Terms of Service restrict the categories of data that may be uploaded. Unless a separate written agreement is in place, the service does not accept protected health information, payment-card data, classified or controlled government information, export-controlled technical data, or personal data subject to European Union, United Kingdom, or Swiss transfer restrictions.

The anonymous pre-flight assessment also accepts an upload without an account. That upload is processed in request-scoped memory for the pre-flight response and is not intentionally retained after the request completes. We do not create an account from a pre-flight upload.

Operational information

We use strictly necessary session and CSRF cookies to operate authenticated browser sessions and protect state-changing requests. We may use request information momentarily for rate limiting and security controls. Application logs are limited to operational data such as job identifiers, timings, aggregate counts, HTTP status codes, and error types. We do not intentionally log IP addresses, hostnames, filenames, CVEs, plugin output, scan contents, or report findings.

We do not use analytics SDKs, advertising pixels, third-party tracking scripts, cross-site behavioral tracking, or third-party web fonts. Assets used by the application are served from our own domain.

How we use information

We use information to:

  • create and authenticate accounts;
  • deliver reports and other requested services;
  • administer subscriptions, credits, and billing;
  • send verification, password-reset, security, subscription renewal reminder, price-change, and other administrative messages;
  • respond to support requests;
  • prevent abuse, enforce authorization and rate limits, and secure the service;
  • comply with legal obligations and resolve disputes; and
  • maintain and improve the service based on aggregate operational information.

We do not use customer-uploaded scan data to train an AI model, assign security scores outside the deterministic service pipeline, or create advertising profiles.

Who receives information

We share information only with service providers that need it to operate the service or when required by law:

  • Stripe receives billing-related account information and sends subscription and payment-status events to our server so we can maintain billing state. Stripe hosts the payment-card entry and processing flow.
  • Resend receives email addresses and the contents of transactional messages so they can be delivered. These include account verification, password reset, feedback you send us, subscription renewal reminders, price-change notices, and other administrative messages. We do not send scan contents, hostnames, findings, or report data by email.
  • OVHcloud provides the U.S.-region hosting and infrastructure on which the application and its account records run.

We do not share personal information with advertising networks or business partners for promotions. We may disclose information in a merger, acquisition, financing, or sale of assets, or when disclosure is required to comply with law or protect the service.

Cookies and tracking notice

The service uses only strictly necessary session and CSRF cookies. These cookies are required for authentication and request security; they are not used for advertising, analytics, or cross-site tracking. You can disable cookies in your browser, but authenticated features will not work correctly. This section is the cookie notice for the current application unless we later publish a separate cookie page.

Do Not Track

Because we do not use cross-site behavioral tracking, advertising profiles, or analytics tracking, we do not take a separate action in response to browser Do Not Track signals. Our no-tracking practices apply whether or not a Do Not Track signal is present.

Retention

We retain account, subscription, credit, API-key metadata, security, support, and billing records for as long as reasonably necessary to provide the service, protect it, meet legal and accounting obligations, resolve disputes, and enforce our agreements. Processed Stripe event identifiers are retained for up to 30 days on a fixed cleanup schedule.

Uploaded scans and synchronously generated reports are not intentionally retained after the request completes. If a future asynchronous feature temporarily stores an upload or report, we will document its retention period and controls before enabling it for an account.

When there is no ongoing business or legal need for account information, we will delete or anonymize it where reasonably possible. Some records may remain in restricted legal, accounting, or security records for the period required by law or legitimate security needs.

Security

We use measures appropriate to the service and the information we process, including scrypt password hashing with unique salts, hashed API-key and session secrets, CSRF protections, secure session-cookie settings, authentication and email-route rate limits, secure XML parsing that rejects external entities and DTDs, upload limits and concurrency controls, and logging rules that prohibit scan-derived payload data. No method of transmission or storage is completely secure.

Account and privacy requests

There is currently no self-service account-edit or account-deletion control. To request access, correction, deletion, account closure, or information about processing, email support@varaxontech.com. We may verify the request before acting and may retain information required for security, fraud prevention, legal compliance, or dispute resolution.

U.S. privacy rights

Depending on your state of residence, you may have rights to know, access, correct, delete, obtain a copy of, or limit certain processing of personal information. We do not sell personal information or share it for targeted advertising. Requests and appeals may be sent to support@varaxontech.com. We have not sold or shared personal information for targeted advertising, and we have not disclosed customer information to advertising networks.

For California privacy-category purposes, the service may process the following limited categories: (a) identifiers, such as an email address; (b) commercial information, such as subscription status, plan, credits, and report usage; and (c) limited internet or network information used momentarily for rate limiting and security controls. We do not use browsing history, cross-site activity, advertising interactions, or behavioral profiles. Stripe, not Varaxon, handles payment-card details. Varaxon does not sell personal information or share it for cross-context behavioral advertising.

Children

The service is not directed to children under 18, and we do not knowingly collect information from children under 18.

Updates and contact

We may update this policy by posting a revised version with a new effective date. If a security incident legally requires notice to affected individuals or regulators, we will provide notice in the manner and time required by applicable law. For questions, privacy requests, or complaints, contact:

Varaxon Technologies LLC
5372 Washington St
Camp Lejeune, NC 28547
United States
support@varaxontech.com

  • Privacy
  • Terms
  • Refunds
  • Contact
  • Data processing

Varaxon Technologies