The formal Privacy Policy is with counsel. Everything below is an accurate description of what the product does today, and we will send the signed policy and a DPA on request — [email protected] .
Account data — name, work email, organisation, and authentication records.
Scan data — the hostnames, IP ranges and applications you ask us to test, and everything our scanners observe about them: open services, software versions, HTTP responses, findings, and the evidence captured to prove a finding.
Credentials you supply — if you give Umbra a login so it can test an authenticated surface, that credential is stored encrypted and used only for scans you run against the scope you authorised.
Usage data — which features you use and when, to operate and bill the service.
In the EU by default, on every plan including Free. The platform and database run in Helsinki, Finland (Hetzner). Scan artifacts — recon bundles, transcripts and reports — are stored in Stockholm, Sweden (AWS eu-north-1).
AI analysis is performed by Anthropic and DeepSeek when you trigger an audit or a verification. Those providers receive scan output for the run in question. Neither trains models on it.
Only the subprocessors on our subprocessor list , each for a single named purpose. We do not sell customer data, do not share it for advertising, and do not train models on it.
You can request a copy of your data, correction, or deletion of your organisation and everything in it. Email [email protected] and we will act within 30 days.
Our security posture, coordinated-disclosure policy and security inbox are on the security page.
Last reviewed: 4 September 2026.