SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
The small print
Privacy policy
Last updated 7 October 2026 2 min read
The short version
Palisade collects what it needs to run the service, answer you and send an invoice, and nothing more. We never sell personal data. Findings about your systems belong to you and are used only to show them to you and help you close them. You can ask to see, correct or delete your data at any time by writing to hello@palisade.security.
What we collect
- Account details: your name, work email, company, role and the settings you choose.
- Connection data: the metadata we read from the sources you connect (identity provider, device management, cloud accounts, code hosts) in order to find exposures. We read configuration and metadata, not the contents of your files or messages.
- Findings: the list of exposures, their severity, who they were assigned to and when they were closed.
- Billing details: your billing name and address and what you paid. Card numbers are handled by the payment provider and never reach us.
- Website data: pages visited and the browser used, through privacy-friendly analytics.
How we use it
- To run the service: connect to your sources, run the sweep, rank findings and route them to the right owner.
- To talk to you: answer a demo request, send alerts you have switched on and tell you about changes that matter.
- To run the business: invoices, bookkeeping and the records the law asks us to keep.
- To improve the product: aggregate, de-identified statistics such as how long a kind of finding stays open. Never your raw findings.
Your findings stay yours
We do not share your findings, your asset inventory or your risk score with anyone outside your account, and we do not use them to train models that serve other customers.
Who processes data for us
A short list of subprocessors hosts and supports the service: cloud hosting, email delivery, payments and support tooling. Each works on our written instructions under a data processing agreement. The current list is on the Trust page.
Where it is stored
You choose a data region when the workspace is created. Data stays in that region unless you ask us to move it. Backups are encrypted and kept in the same region.
How long we keep it
Findings and connection metadata are kept for as long as your workspace is active and are deleted within 30 days of closing it. Invoices are kept for as long as tax law asks. Demo requests and emails are deleted after two years.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete what we are not required to keep, and object to any use you did not expect. Write to hello@palisade.security and we will answer within 30 days. You can also complain to your local data protection authority.
Changes
If this policy changes in a way that matters, we will say so on this page and by email before the change takes effect.
Contact
Palisade Security Ltd is the controller of the data described here. Questions go to hello@palisade.security.
A plain starting template, not legal advice. Have your own counsel review it before you publish.
A question about this page?
Write to us and a person answers, usually within two working days.
Palisade Security Ltd · hello@palisade.security
The small print
Privacy policy
Last updated 7 October 2026 2 min read
The short version
Palisade collects what it needs to run the service, answer you and send an invoice, and nothing more. We never sell personal data. Findings about your systems belong to you and are used only to show them to you and help you close them. You can ask to see, correct or delete your data at any time by writing to hello@palisade.security.
What we collect
- Account details: your name, work email, company, role and the settings you choose.
- Connection data: the metadata we read from the sources you connect (identity provider, device management, cloud accounts, code hosts) in order to find exposures. We read configuration and metadata, not the contents of your files or messages.
- Findings: the list of exposures, their severity, who they were assigned to and when they were closed.
- Billing details: your billing name and address and what you paid. Card numbers are handled by the payment provider and never reach us.
- Website data: pages visited and the browser used, through privacy-friendly analytics.
How we use it
- To run the service: connect to your sources, run the sweep, rank findings and route them to the right owner.
- To talk to you: answer a demo request, send alerts you have switched on and tell you about changes that matter.
- To run the business: invoices, bookkeeping and the records the law asks us to keep.
- To improve the product: aggregate, de-identified statistics such as how long a kind of finding stays open. Never your raw findings.
Your findings stay yours
We do not share your findings, your asset inventory or your risk score with anyone outside your account, and we do not use them to train models that serve other customers.
Who processes data for us
A short list of subprocessors hosts and supports the service: cloud hosting, email delivery, payments and support tooling. Each works on our written instructions under a data processing agreement. The current list is on the Trust page.
Where it is stored
You choose a data region when the workspace is created. Data stays in that region unless you ask us to move it. Backups are encrypted and kept in the same region.
How long we keep it
Findings and connection metadata are kept for as long as your workspace is active and are deleted within 30 days of closing it. Invoices are kept for as long as tax law asks. Demo requests and emails are deleted after two years.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete what we are not required to keep, and object to any use you did not expect. Write to hello@palisade.security and we will answer within 30 days. You can also complain to your local data protection authority.
Changes
If this policy changes in a way that matters, we will say so on this page and by email before the change takes effect.
Contact
Palisade Security Ltd is the controller of the data described here. Questions go to hello@palisade.security.
A plain starting template, not legal advice. Have your own counsel review it before you publish.
A question about this page?
Write to us and a person answers, usually within two working days.
Palisade Security Ltd · hello@palisade.security
The small print
Privacy policy
Last updated 7 October 2026 2 min read
The short version
Palisade collects what it needs to run the service, answer you and send an invoice, and nothing more. We never sell personal data. Findings about your systems belong to you and are used only to show them to you and help you close them. You can ask to see, correct or delete your data at any time by writing to hello@palisade.security.
What we collect
- Account details: your name, work email, company, role and the settings you choose.
- Connection data: the metadata we read from the sources you connect (identity provider, device management, cloud accounts, code hosts) in order to find exposures. We read configuration and metadata, not the contents of your files or messages.
- Findings: the list of exposures, their severity, who they were assigned to and when they were closed.
- Billing details: your billing name and address and what you paid. Card numbers are handled by the payment provider and never reach us.
- Website data: pages visited and the browser used, through privacy-friendly analytics.
How we use it
- To run the service: connect to your sources, run the sweep, rank findings and route them to the right owner.
- To talk to you: answer a demo request, send alerts you have switched on and tell you about changes that matter.
- To run the business: invoices, bookkeeping and the records the law asks us to keep.
- To improve the product: aggregate, de-identified statistics such as how long a kind of finding stays open. Never your raw findings.
Your findings stay yours
We do not share your findings, your asset inventory or your risk score with anyone outside your account, and we do not use them to train models that serve other customers.
Who processes data for us
A short list of subprocessors hosts and supports the service: cloud hosting, email delivery, payments and support tooling. Each works on our written instructions under a data processing agreement. The current list is on the Trust page.
Where it is stored
You choose a data region when the workspace is created. Data stays in that region unless you ask us to move it. Backups are encrypted and kept in the same region.
How long we keep it
Findings and connection metadata are kept for as long as your workspace is active and are deleted within 30 days of closing it. Invoices are kept for as long as tax law asks. Demo requests and emails are deleted after two years.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete what we are not required to keep, and object to any use you did not expect. Write to hello@palisade.security and we will answer within 30 days. You can also complain to your local data protection authority.
Changes
If this policy changes in a way that matters, we will say so on this page and by email before the change takes effect.
Contact
Palisade Security Ltd is the controller of the data described here. Questions go to hello@palisade.security.
A plain starting template, not legal advice. Have your own counsel review it before you publish.
A question about this page?
Write to us and a person answers, usually within two working days.
Palisade Security Ltd · hello@palisade.security