SecWaypoint.com
List Firm
Legal & Data Protection

Privacy Policy

Last Updated: October 2026 • Effective Date: January 1, 2025

1. Overview and Scope

SecWaypoint (“we,” “our,” or “us”) operates an open directory and research index of cybersecurity service providers, consultancies, MSSPs, and defense solution firms accessible via https://secwaypoint.com.

We are committed to transparent, fair, and responsible data processing. This Privacy Policy details the types of information we collect, how it is maintained, the purposes for which it is used, and your rights regarding the data published on or submitted to SecWaypoint.

2. Categories of Information We Process

A. Public Business & Commercial Information

The primary purpose of SecWaypoint is to curate publicly available business records to facilitate B2B vendor discovery. This includes:

  • Corporate business name, website URL, and branding assets.
  • Public corporate email addresses (e.g., info@, sales@, hr@, careers@).
  • Published telephone numbers and headquarters/branch office locations.
  • Public business social profiles (LinkedIn, X / Twitter, YouTube, Instagram).
  • Publicly disclosed service domains, specializations, and software products.

B. Submitter & Contributor Information

When you submit a new company, suggest an edit, or submit a claim request via our portal, we collect the submitter's email address and submission notes to verify authority, prevent spam, and acknowledge the change.

C. Telemetry and Usage Analytics

To improve platform performance, search speed, and discoverability, we collect aggregated, non-personally identifiable telemetry such as page views, category filter clicks, and outbound link referrals. We do not sell this data or track users across external third-party websites.

3. How We Use Information

We process collected data exclusively for the following legitimate purposes:

  • Publishing accurate, organized profiles of cybersecurity organizations.
  • Auditing and approving user submissions and profile claim requests.
  • Preventing automated abuse, spam submissions, and malicious scraping.
  • Fulfilling legal obligations and responding to verified takedown or correction requests.

4. Storage, Security, and Retention

Our infrastructure is hosted on ISO 27001 and SOC 2 Type II certified cloud providers (including Supabase for PostgreSQL database storage and Vercel for application hosting). All database connections and web traffic are protected by TLS 1.3 cryptographic encryption.

Directory records are retained for as long as a cybersecurity organization operates active commercial services. Submitter logs are maintained for administrative audit trails and discarded when no longer required.

5. Cookies and Client-Side Storage

SecWaypoint does not use advertising tracking cookies. We utilize browser localStorage strictly for user interface preferences, such as remembering your chosen light or dark theme (secwaypoint_theme), and functional session cookies for authenticated administrators.

6. Your Rights and Listing Corrections

Depending on your jurisdiction (including rights under the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and India's Digital Personal Data Protection Act (DPDP)), you maintain the right to:

  • Request confirmation of any personal information associated with your submissions.
  • Request the rectification of outdated, incorrect, or superseded company records.
  • Request the delisting or removal of specific personal contact details or business records.

To submit a data inquiry or removal request, contact our privacy desk directly at secwaypoint@gmail.com. We process verified requests within five (5) business days.

7. Contact Information

For any questions, concerns, or requests relating to this Privacy Policy, please reach out to:

SecWaypoint Editorial & Privacy Desk