Privacy Policy
Last updated: September 15, 2026
What we collect and why
This policy describes how CTEMEGA (“we”, “us”) handles data for customers using the Service at ctemega.com. It covers account data, the security data our platform generates while operating on your behalf, technical/operational logs, AI processing, and billing.
1. Who operates the Service
CTEMEGA is a B2B cybersecurity SaaS platform. For questions about the entity operating the Service, applicable jurisdiction, or anything not covered here, contact us directly at customer.service@ctemega.com — we don't publish a separate corporate registry page, so that inbox is the authoritative place to ask.
2. Account data
We collect your email, name, and organization details to create and operate your account, including sending account-related email (verification, password reset, security notifications) through our transactional email provider.
3. Security data: assets, targets, findings, and reports
Targets you register, and the assets, findings, attack graph data, and reports CTEMEGA generates from scanning and analyzing them, are stored and scoped to your organization. Every organization's data is tenant-isolated — findings, reports, scan results, and Attack Graph data are only ever returned to requests authenticated for that organization. This tenant-isolation property is something we've directly tested, not just assumed.
4. Technical and operational data
We log security-relevant events — sign-ins, failed authentication attempts, API usage, and administrative actions — to operate the Service reliably, investigate abuse, and maintain an audit trail for actions taken within your organization (for example, Mission approvals and Governed Exploit Validation runs). These logs are used for security and operational purposes; we don't sell or repurpose them for advertising.
5. AI processing
When OMEGA Intelligence or an AI Agent analyzes a finding, relevant finding and asset data is sent to the AI provider configured for your organization to generate that analysis. Depending on your plan and configuration, that provider may be a third-party model provider (for example OpenAI, Anthropic, or Google) reached over the network, or a self-hosted model that never leaves our infrastructure — which one applies depends on your organization's AI provider configuration. Every AI request is tenant-scoped and logged for auditability (provider, model, and outcome); it is never mixed with another organization's data. We don't control, and can't make representations about, how a third-party AI provider itself retains or uses data once it receives a request — see that provider's own policy if this matters for your use case.
6. Billing data
Paid plans are billed through Dodo Payments, our payment processor. We do not store your full payment card details — Dodo Payments handles payment collection and storage directly.
7. Data retention and deletion
You can request deletion of your account and associated data, or export of your data, by contacting us at the email below. We retain data for as long as your account is active and as needed to operate the Service, resolve disputes, and meet legal obligations — we don't currently publish a fixed retention schedule per data type, so if you need a specific answer for your organization, ask us directly.
8. Your privacy rights
Depending on where you're located, applicable data protection law (such as the GDPR in the EU/EEA, the UK GDPR, the CCPA in California, or similar frameworks elsewhere) may give you rights over your personal data — for example, to access, correct, export, or delete it, or to object to certain processing. We haven't obtained a specific compliance certification for any of these frameworks; where they apply to you, we intend to honor the rights they establish. To exercise any of these rights or ask which apply to you, contact us at the email below.
9. Third-party service providers
We rely on the following categories of third-party providers to operate the Service:
- AI model providers (managed or bring-your-own-key, depending on your plan) — see Section 5.
- Dodo Payments — payment processing for paid plans.
- A transactional email provider, configured via standard SMTP — for account and security emails.
Each is used only to the extent necessary to provide the corresponding part of the Service.
10. Contact
Questions about this policy, your data, or a request under Section 7 or 8: customer.service@ctemega.com
