How Penthropic Security collects, uses, and protects personal data, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Last updated: 4 September 2026
We collect only what we need to run our services and answer your enquiries, we never sell your data, we encrypt it and isolate it per tenant, and you can ask us to access or delete it at any time. The formal detail, who controls your data, our lawful bases, processors, retention, and your rights, follows below.
Penthropic Security is a trading name of Penthropic Ltd, a company registered in England & Wales. For the personal data described in this policy, Penthropic Ltd is the data controller. We are a boutique cyber-security consultancy based in London, United Kingdom.
If you have any question about this policy or how we handle your data, contact us at privacy@penthropic.ai.
We only collect personal data we genuinely need to operate our business and serve our clients. Depending on how you interact with us, this may include:
We do not seek to collect special-category personal data through our website, and we ask that you do not submit it through our contact forms.
Under UK GDPR we rely on the following lawful bases:
| Activity | Lawful basis |
|---|---|
| Responding to enquiries and discovery calls | Legitimate interests (responding to a request you initiated) and steps to enter a contract. |
| Delivering engagements and operating portal/platform accounts | Performance of a contract with you or your organisation. |
| Securing our website, logs, and platform | Legitimate interests (keeping our services and clients safe) and legal obligation. |
| Understanding how visitors find and use our website (first-party analytics) | Legitimate interests (measuring and improving our website), using privacy-friendly, cookie-free analytics. |
| Sending service or relationship updates | Legitimate interests, or consent where required. |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to this processing at any time, see section 9.
Our public website uses a small number of strictly necessary cookies and browser storage to function, for example, to remember whether you have dismissed a banner, and to register a service worker that caches static assets so the site loads quickly and reliably. These are essential to the operation of the site.
The client portal and platform use authentication and session storage that are necessary to keep you signed in securely. We do not use advertising cookies, and we do not sell or share your personal data with advertising networks.
To understand how our public website is used, which pages are popular, how visitors arrive, and roughly where in the world our audience is, we operate our own first-party, privacy-friendly analytics. When you load a page, our own server records a single page-view event containing:
This analytics is deliberately lightweight and respectful of your privacy:
Our lawful basis is legitimate interests, measuring and improving our website and understanding our audience, balanced against your rights. You can object to this processing at any time (see section 9), and analytics records are automatically deleted on the schedule set out in section 7.
We use a small set of trusted suppliers to run the service. Each acts as a data processor on our behalf under a written data processing agreement, and processes personal data only on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, and infrastructure for our website, portal, and platform. | London (eu-west-2) |
| Anthropic | AI-assisted features (for example, the website assistant and platform investigation tooling). Inputs are processed to generate responses and are not used to train foundation models. | United States |
| Stripe | Payment and billing processing where you pay for a service. | UK / EU / US |
The platform verifies things rather than taking them on trust, and verification means asking someone else. When you run a supplier check, an attack-surface scan, an email triage or a threat-intelligence lookup, we send the identifier being checked to a public or commercial data source. That identifier is usually a domain name, a company name, an IP address, a URL or a file hash. Sometimes it is an email address. It can relate to your organisation, to one of your suppliers, or to a person.
We publish the full list because it is the question this product exists to make buyers ask, and it would be indefensible to answer it incompletely on our own site.
| Source | What we send it | Why |
|---|---|---|
| Cloudflare DNS over HTTPS | The domain or subdomain being checked. Also a supplier IP address, reversed into a DNS name, on the fallback network lookup described in the Team Cymru row below. | Public DNS lookups for SPF, DMARC, DNSSEC and MTA-STS records, and to test candidate subdomains. The query never reaches the domain being checked. |
| crt.sh (Certificate Transparency search) | The domain being checked. | Certificate history, used to find subdomains and to read certificate expiry. |
| Internet Archive (Wayback CDX) | The domain being checked. | Historic URLs, used to find subdomains that are no longer linked but still resolve. |
| SecurityTrails | The domain being checked. | Passive DNS subdomain discovery. Called only when a SecurityTrails API key is configured. |
| VirusTotal | A domain, or a file hash during a forensic investigation. | Domain and file reputation across many antivirus engines. |
| AlienVault OTX | The domain being checked. | Whether published threat-intelligence reports reference that domain. |
| Google Safe Browsing | The URL being checked. | Whether the site is on Google's unsafe-browsing lists. |
| Have I Been Pwned | A domain, or an email address where you ask us to check one. | Whether credentials for that domain or address appear in a known breach corpus. |
| URLhaus (abuse.ch) | The domain being checked. | Whether the host appears in malware-distribution URL intelligence. |
| ThreatFox (abuse.ch) | Nothing identifying. | We download the recent indicator feed in bulk and match it against your data inside our own infrastructure. |
| NVD (US National Vulnerability Database) | A supplier's company name, as a search keyword. | Recently published vulnerabilities that name that supplier. |
| OSV (Open Source Vulnerabilities) | Package names and versions from your software inventory. | Known vulnerabilities affecting those packages. |
| FIRST (EPSS) | Nothing identifying. | The exploit-prediction feed is downloaded whole and joined to your data inside our own infrastructure. |
| AbuseIPDB | IP addresses, typically taken from the headers of an email you asked us to triage. | Reputation of the sending infrastructure. |
| urlscan.io | URLs found in an email you asked us to triage. | Whether the URL has been scanned before and what was seen. |
| GreyNoise | IP addresses under forensic investigation. | Whether an IP is untargeted internet background noise or something aimed at you. |
| OpenSanctions | A supplier's company or person name. | Sanctions and politically-exposed-person screening during supplier intake. |
| Companies House | The company name or number you entered. | Registration details used to pre-populate a supplier record. Called only when a Companies House API key is configured. |
| Clearbit | A supplier's domain. | Company enrichment during supplier intake. Called only when a Clearbit API key is configured. |
| RIPE NCC (stat.ripe.net) | An IP address belonging to a supplier you asked us to map. | Which network operator and autonomous system that address sits in, so the concentration map can show where several of your suppliers share infrastructure. This is the first source asked. |
| Team Cymru (asn.cymru.com) | The same supplier IP address, reversed into a DNS name. | The same network question, asked only when RIPE NCC gives no answer. The query travels as a DNS lookup through the Cloudflare DNS over HTTPS resolver listed above, so Cloudflare sees it as well. If neither source answers, we record no network for that address rather than guess at one. |
| GDELT | A supplier's company name, as a news search term. | Whether that supplier has been named in a breach or incident story. |
| Google News | A supplier's company name, as a news search term. | The same breach and incident watch. This source can be turned off for your tenant. |
| Shodan | An IP address under forensic investigation. | What services that address exposes. Called only when a Shodan API key is configured. |
| MalwareBazaar (abuse.ch) | A file hash during a forensic investigation. | Whether that file is a known malware sample. We send the hash, never the file. |
| Namecheap | Candidate lookalike domain names derived from your own domain. | Registering the domain a phishing simulation sends from. Called only when Namecheap credentials are configured, and only for a simulation you commissioned. |
| ransomware.live | Nothing identifying. | We download the recent leak-site victim list in bulk and match it against your supplier names inside our own infrastructure. |
| CISA (Known Exploited Vulnerabilities) | Nothing identifying. | The KEV catalogue is downloaded whole and joined to your data inside our own infrastructure. |
| BleepingComputer and Dark Reading | Nothing identifying. | Public RSS feeds fetched whole, then filtered against your supplier names inside our own infrastructure. |
| ipapi.co | The IP address of a visitor to our public website. | The approximate country and city described in section 5. This is the only row here that is about you as a website visitor rather than about something you asked us to check. See the note below the table. |
Every lookup above except the last is passive: nothing in it contacts the organisation being checked. Several are gated on an API key, and where the key is not configured the call is not made at all.
The exception is ipapi.co. Our website analytics (section 5) resolves a visitor IP address to an approximate country and city, and it does that by sending the address to ipapi.co, which is outside the UK. A resolved address is cached for thirty days so a returning visitor is not looked up again. Section 9 sets out how to object to this processing and how to ask us to erase the records held against your address.
Where we are not certain whether a particular query carries data that could identify a person, we have listed it above rather than leaving it out. If you need to know which of these apply to your tenant, ask us at privacy@penthropic.ai and we will tell you.
Where you connect one of your own systems to the platform, we read from it and write to it using the credentials and scopes you grant, and we do so at your direction. Today that covers Microsoft 365, Microsoft Defender, Google Workspace, GitHub, Cloudflare, Slack, Microsoft Teams, CrowdStrike, Okta, Jira, PagerDuty, Tenable, Sumo Logic and AWS accounts you nominate. The connections offered to your tenant are listed in the integrations panel in your console. These are your suppliers rather than ours. You control the connection and you can revoke it from your own console at any time, and from ours.
Voice and messaging features (text to speech, speech to text, SMS delivery for simulated phishing) are built against third-party providers and each is gated on a credential. The providers wired today are ElevenLabs and Deepgram for speech, OpenAI as an alternative speech-to-text and model provider, and Twilio for SMS. Where you enable one, the content of that message or recording reaches that provider. We will confirm in writing which provider applies before any such feature is switched on for your tenant.
We keep this list current and review our processors' security and data-protection posture. We do not sell personal data, and we share it with these providers only to the extent needed to deliver our services to you.
When data is no longer needed for the purpose it was collected, we securely delete or anonymise it.
Our primary hosting region is the United Kingdom (AWS London, eu-west-2). Some processors, such as Anthropic and parts of Stripe, may process data outside the UK. Most of the external sources listed in section 6.1 are also operated outside the UK, and a lookup sent to one of them leaves the UK. Where personal data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
Under UK GDPR you have the right to:
To exercise any of these rights, email privacy@penthropic.ai. We will respond within one month. There is normally no charge.
We apply encryption in transit and at rest, least-privilege access, multi-factor authentication for our team, and tenant isolation within our platform. You can read more on our security statement.
For any data-protection request or question, contact us at privacy@penthropic.ai or write to Penthropic Ltd, London, United Kingdom.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the chance to address your concerns first.