Security Analyst Toolkit Privacy Policy
Effective date: August 18, 2026
1. Scope
This Privacy Policy explains how DPLex Technologies LLC (“DPLex,” “we,” “us,” or “our”) handles information in the Security Analyst Toolkit mobile and web application (the “App”). It describes information stored locally, information that may be transmitted when specific features are used, and choices available to users.
2. Information Stored Locally
The App is designed so that case and investigation records remain local to the user’s device or browser by default. Depending on how the App is used, local records may include:
- case number, title, date, alert type, alert source, description, status, severity, tags, and ticket references;
- usernames, user names, device names, hostnames, manually entered location information, authentication method, and MFA status;
- IP addresses, ports, protocols, domains, URLs, hashes, CVEs, filenames, file paths, process names, command lines, and other indicators of compromise;
- investigation notes, findings, recommendations, containment, remediation, recovery/verification details, root cause, lessons learned, closure summary, and disposition;
- timeline entries, related indicators, enrichment results, remediation tasks, timestamps, and other analyst-entered case information;
- local recovery copies, historical snapshots, and pre-restore safety snapshots used by Case Vault protection features;
- local preferences such as favorite commands, recently copied commands, and release-note state.
On native platforms, this information is stored within the App’s local storage context. On the web version, it is stored in browser-local application storage. The current App does not automatically synchronize case records to a cloud case database.
3. Live Intelligence Lookups
When a user intentionally performs a live intelligence lookup, the indicator being researched is sent to the DPLex API service. The complete case record is not sent as part of these lookup requests.
Depending on the lookup selected, the DPLex API service may forward the submitted indicator to services such as IPinfo, ARIN and other RDAP authorities, PhishTank, CIRCL Hashlookup, the NIST National Vulnerability Database (NVD), FIRST EPSS, and CISA Known Exploited Vulnerabilities (KEV) data services.
Those services may process the indicator and normal network metadata according to their own privacy practices. Provider credentials, where required, are kept on the server and are not embedded in the App.
4. Operational Network Data
The App may contact DPLex services for runtime status, gateway health, identity/session status, and support/build diagnostics. These requests do not include complete case records or analyst notes.
The API infrastructure may process ordinary connection metadata such as IP address, HTTP method, request path, response status, request identifier, and user-agent or similar protocol information. Client IP addresses may be used for rate limiting. Authorization headers and cookies are not intentionally included in custom request logs.
Some compatibility routes may include an indicator in a URL path. In those circumstances, the indicator may appear in operational server logs associated with that request path.
5. Development Session Functionality
Current builds may include a development-session mechanism used for testing and runtime diagnostics. This is not a traditional end-user account system: there is no email/password registration flow, no user-profile database, and no cloud case ownership or synchronization. Development access tokens are held in client memory, and associated development session state is temporary.
6. Portable Backup, Export, and Restore
Users may create a portable Case Vault backup. Portable backups contain the current case records in plain-text JSON. Depending on the cases stored, the backup may contain personal, organizational, security, investigative, or incident information entered by the user.
Portable backups are not automatically uploaded by the App. When a user chooses to create or share a backup file, the App uses the operating system’s file/share interface and the user selects the destination. A chosen destination may be a local folder, cloud drive, email client, messaging application, or other third-party service. Once a user sends or stores a backup with another service, that service’s privacy and security practices apply.
Portable backup files are currently not encrypted or password-protected by the App. Users should treat them as sensitive and store or transmit them appropriately.
When restoring from a file, the user explicitly selects the backup. The App reads and validates the file locally and does not automatically upload the selected backup.
7. Clipboard Use
The App can copy content such as security commands, investigation summaries, portable backup JSON, or diagnostics to the operating system clipboard after an explicit user action. Clipboard synchronization provided by an operating system, device ecosystem, or account is outside the App’s control.
8. Device Permissions and Sensitive Capabilities
Current App behavior does not intentionally collect or use device GPS location, contacts, camera or microphone data, advertising identifiers, hardware device identifiers, Bluetooth data, or biometric data. Location fields appearing in case forms are manually entered text. File access is limited to explicit backup creation, sharing, and user-selected backup restore operations.
9. Analytics, Advertising, and Crash Reporting
The current App does not include behavioral analytics, advertising SDKs, marketing attribution SDKs, or third-party crash-reporting services. The App may display local error information when a problem occurs, but it does not currently transmit crash reports to an external analytics or crash-reporting provider.
10. How We Use Information
- provide case-management, investigation, reference, enrichment, and reporting functionality;
- perform user-requested live intelligence lookups;
- maintain App, API, runtime, and support diagnostics;
- protect service availability through security controls and rate limiting;
- provide backup, restore, recovery, and continuity functions requested by the user.
11. Data Sharing
DPLex does not use the App to sell case records or analyst-entered case data. Information may be disclosed to an external intelligence provider when the user intentionally performs the corresponding lookup, as described above. Information may also be disclosed when required by law, legal process, or to protect the rights, safety, integrity, or security of DPLex, users, or others.
12. Data Security
DPLex uses reasonable technical and organizational safeguards appropriate to the App’s design. Case Vault data is application-local but is not represented as encrypted storage within the current App implementation. Portable backup files are plain-text JSON and should be protected by the user.
No method of electronic storage, local-device storage, or network transmission is completely secure. Users are responsible for applying appropriate device security, access controls, backup handling, and organizational policies when entering sensitive incident or client information.
13. Data Retention and Deletion
Local case data remains on the device or in the browser until the user deletes cases, clears App/browser data, restores a different vault, or removes the application/storage context. Local recovery and history features may retain recent snapshots inside the same installation for recovery purposes.
Portable backup files remain wherever the user chooses to save or share them until the user or the receiving service deletes them.
The current App does not maintain a cloud case database or conventional end-user account containing case records. Operational server logs and temporary session/rate-limit information may be retained for reasonable operational, security, troubleshooting, and legal purposes.
14. Children’s Privacy
Security Analyst Toolkit is designed for cybersecurity and IT professionals and is not directed to children. DPLex does not knowingly design the App to collect personal information from children.
15. Changes to This Privacy Policy
We may update this Privacy Policy as the App, its features, or legal requirements change. The effective date at the top of this page will be updated when revisions are made. Material changes to data-handling practices should also be reflected in applicable App disclosures and store-listing declarations.
16. Contact
For privacy questions or requests concerning Security Analyst Toolkit, contact:
DPLex Technologies LLC
Email: dplextechnologiesllc@gmail.com
Website: dplextechnologies.com