Privacy Policy & Data Protection
1. Safe-By-Default Attestation Gate
MIAN DAST operates from Abu Dhabi, United Arab Emirates (UAE) exclusively under the safe-by-default architecture pioneered by Dave Mian. We do not scan, probe, or test any domain or application without cryptographically verified authorization evidence and a named individual attesting ownership. We never perform unauthorized security research or scan third-party hosts.
2. Information We Collect & Store
- Account Information: Organization name, email address, PBKDF2 hashed administrative credentials.
- Target Scope: Base URLs, in-scope host boundaries, API schemas (Swagger/OpenAPI), and attestation evidence tickets.
- Diagnostic Telemetry: Vulnerability findings, HTTP response headers, check IDs, latency benchmarks, and timestamp metadata.
- Payment Metadata: Handled securely via Stripe. We do not store full credit card numbers or CVVs.
3. Absolute Confidentiality of Security Findings
Your vulnerability scan data, finding summaries, and threat assessments are classified as Strictly Confidential. We do not sell, license, share, or disclose customer vulnerability findings to any third parties, advertisers, or threat intelligence brokers under any circumstances.
4. GDPR, UK DPA, & CCPA Rights
Under GDPR and California Consumer Privacy Act, you have the right to:
- Request complete export of your organization's telemetry and scan findings.
- Request permanent cryptographic erasure (Right to be Forgotten) of targets, scans, and accounts.
- Revoke authorization tokens and purge stored API keys instantly.
5. Contact Data Protection Officer
For any data protection inquiries, audit requests, or to exercise your GDPR rights, contact Dave Mian and our security operations team at security@askmian.com.