Privacy and data handling

Privacy Policy

This page explains how the utility is intended to handle session reports, public CVE intelligence, cache data, analytics considerations and future account-based features.

This policy reflects the current operational scope of RiskRank: a session-first public utility with no user accounts or stored reports. It should be reviewed by qualified legal counsel before adding ads, analytics, accounts or paid features.

Session-first reports

Generated reports are session-only and are not stored as user report history. Download or print before closing the session.

Public CVE cache only

The cache is intended for public vulnerability intelligence such as NVD, EPSS and CISA KEV data.

No sensitive inputs required

Users should not enter secrets, private keys, passwords or confidential incident details into public forms.

Detailed privacy policy

Last updated: 2026-06-26

1. Scope of this policy

This Privacy Policy explains how RiskRank handles data. The tool is a public security utility that helps users enrich CVE information, add business context and generate a session-only risk report. No account registration is required.

2. Session-only reports

Reports generated by this utility are session-only and are not stored as user-specific records in the application database. Users should download or print a report before generating a new one, refreshing the page or closing the browser session.

3. CVE lookup cache

The application caches public CVE intelligence to improve performance and reduce repeated external lookups. Cached data may include CVE identifiers, descriptions, CVSS metrics, vectors, references, affected product hints, FIRST EPSS data, CISA KEV status and source timestamps. This cache is for public vulnerability intelligence, not private user reports.

4. No user accounts

RiskRank does not require user accounts, user profiles or saved report history. If account-based features such as saved scenarios, report history or organization workspaces are introduced in a future version, this privacy policy, retention rules and access-control model will be updated before launch.

5. Data users should not enter

Users should not enter secrets, passwords, private keys, confidential incident details, customer names, internal hostnames, private IP addressing schemes, sensitive architecture details or regulated personal data. The input fields are designed for CVE identifiers and general business context, not sensitive operational data.

6. External source requests

When a user performs a CVE lookup, the application queries external vulnerability intelligence sources such as NVD, FIRST EPSS and CISA KEV. These requests retrieve public vulnerability data. Source availability, response time and accuracy depend on the upstream providers.

7. Server logs and abuse protection

The hosting platform collects technical logs such as request time, route, response status, IP-related metadata, user-agent and error traces. These logs are used for troubleshooting, abuse prevention, rate limiting, security monitoring and service reliability. Log retention is governed by the hosting provider's standard policy.

8. Advertising, analytics and cookies

RiskRank does not currently use tracking cookies, advertising networks or user-level analytics. If analytics or advertising are introduced in the future, the deployment will include the required consent controls and privacy notices for the target market. Sensitive report content will not be sent to third-party providers.

9. Data retention

Reports are session-only and are not retained after the browser session ends. Public CVE cache entries may be retained temporarily for performance, keyed on public CVE identifiers only. If saved reports or account data are introduced, retention periods and deletion controls will be published before that feature launches.

10. Security measures

The application uses HTTPS in production, manages secrets through the hosting provider's environment variable system, applies rate limiting and avoids sensitive client-side secrets. Errors are handled carefully to avoid leaking internal state. Security is treated as a practice, not an assumption.

11. Your data rights

Because RiskRank does not store personal data or user reports, there is no user data profile to access, correct or delete. If you believe personal data related to your use of this service is held (for example, in server logs), you may contact igorberner89@gmail.com to request clarification or removal.

12. Changes to this policy

This policy will be updated whenever the application introduces user accounts, saved reports, payment features, advertising, analytics, third-party integrations or new data retention behavior. The last updated date at the top of this policy reflects the date of the most recent revision.

13. Contact

For privacy questions, data handling concerns or requests related to this policy, contact: igorberner89@gmail.com.

Plain-language summary

RiskRank caches public CVE intelligence, not private reports. Reports are generated for the active browser session and should be downloaded by the user before closing. No account, login or personal information is required. If saved reports, accounts or premium services are added in future versions, this policy will be updated before those features launch.