Privacy
Short version: this site sets no cookies, runs no analytics of its own, and asks you for nothing. There is no account to create, no form to fill in, and no tracking script. What follows is the detail, because a site about security research should be specific rather than reassuring.
Last updated 2 September 2026.
What this site collects directly
Nothing. There is no analytics script, no advertising, no social embed, no font loaded from a third party, and no cookie set by this site. Every page is a static file. If you disable JavaScript entirely, the site works exactly the same, because it ships none.
What our infrastructure provider processes
This site is served by Cloudflare, which operates the network and the hosting. Delivering a web page inherently means Cloudflare receives and briefly logs the technical details of each request — including the IP address it came from, the page requested, the time, and the browser's user-agent string. This is the ordinary operation of a web server, and it happens before anything of ours runs.
- Why: to serve the page, and to protect the site from attack and abuse.
- Legal basis: legitimate interests — operating and securing the service. Network and information security is expressly recognised as a legitimate interest under the GDPR (Recital 49), and this processing is likewise necessary for the site to function under South Africa's POPIA.
- What we see: we read only aggregate statistics from Cloudflare — counts of requests, pages, estimated unique visitors and security events per day. We do not download, store or analyse individual visitor records, and we do not build profiles of visitors.
- Retention: governed by Cloudflare's own retention periods, not by us. On our plan, security event detail is retained for roughly 24 hours.
Cloudflare's own privacy documentation is at cloudflare.com/privacypolicy.
What we do not do
- We do not sell, rent or share visitor data. There is nobody to share it with.
- We do not publish visitor or scanner IP addresses. Automated probing of this site comes overwhelmingly from compromised machines and shared address pools, so an address usually identifies someone who is themselves a victim rather than an attacker. Where we write about traffic patterns, we publish aggregates only.
- We do not use cookies, local storage, fingerprinting, or any cross-site tracking.
- We do not run a mailing list, and there is nothing here to subscribe to.
If you contact us
Email sent to [email protected] reaches a mailbox we read. Your message and address are kept only as long as needed to deal with what you wrote about — and, where it concerns a vulnerability report, for as long as the coordinated disclosure record needs to exist. We do not add correspondents to any list.
For reporting a security issue in something published here, see /.well-known/security.txt.
Your rights
Under the GDPR and POPIA you may ask what personal information we hold about you, ask for it to be corrected or deleted, and object to processing. In practice we hold nothing about visitors beyond what is described above — but if you have written to us, write again and we will act on it.
Changes
If this notice changes materially, the date above changes with it. Since the site is a permanent archive, an old page that referenced this notice will still find it at the same address.