Privacy Policy

Effective date: August 30, 2026
Website: https://www.threatunknown.com/

This Privacy Policy explains how Threat Unknown ("Threat Unknown," "we," "us," or "our") collects, uses, discloses, and safeguards personal information when you visit our website or contact us about cybersecurity services. It also describes your privacy rights and how you can exercise them.

Scope. This policy covers personal information we collect through our public website, contact forms, email, and phone inquiries from prospective or existing clients. If we process data on behalf of a client as part of a services engagement, that processing is governed by our services agreement and (if applicable) a Data Processing Addendum (DPA) rather than this website policy.


01Who we are and how to contact us

If you have questions or wish to exercise a privacy right, contact us at the email above.


02Information we collect

We collect the following categories of personal information when you provide it or when it is collected automatically from your device:

Information you provide directly

  • Contact details: name, email address, phone number, company, role/title.
  • Inquiry content: the message you submit, meeting preferences, service needs, and any other details you choose to share.
  • Contract and billing info (if you become a client): business contact information, billing contacts, purchase orders, and similar administrative records.

Information collected automatically

  • Technical and usage data: IP address, device and browser type, pages viewed, referring/exit pages, and timestamps.
  • Cookies and similar technologies: used for essential site functionality and, if enabled, analytics and performance. See Cookies below.
  • Session recordings (this website only): a replay of your visit, covering the pages you opened, where you clicked, how you scrolled, and the timing of each step, together with your browser's console output. We do not record sessions in the client portal. See Cookies and analytics below.

We do not intentionally collect sensitive personal information through our website.


03How we use personal information

We use personal information for the following purposes:

  • Provide and improve our website and services.
  • Respond to inquiries and provide proposals.
  • Operate our business. Including customer relationship management (CRM), record keeping, product and website analytics, and security monitoring.
  • Legal and compliance. To comply with applicable laws, enforce our terms, and protect our rights and the security of our services.

We use personal information only for purposes a reasonable person would consider appropriate in the circumstances. If we intend to use it for a materially different purpose, we will explain and seek consent where required by law.


When required, we obtain your consent to collect, use, and disclose personal information. Consent may be express (e.g., you submit a form) or implied (e.g., you contact us about services). We rely on recognized privacy principles such as identifying purposes, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and accountability.

If you subscribe to marketing communications, you may opt out at any time using the unsubscribe link in the message or by emailing us. We comply with Canada's Anti‑Spam Legislation (CASL) where it applies.


05Cookies and analytics

  • Essential cookies enable core site features and security.
  • Analytics cookies. We use PostHog on this website to understand site usage, meaning pages viewed, referring pages and interactions, so we can improve our content and performance.

Asking first, on this website. Analytics is not essential to running this site, so we ask before we switch it on. PostHog does not load at all until you accept in the cookie banner. If you decline, no analytics cookies are set and no session is recorded. You can change your answer later by clearing this site's data in your browser, and you can adjust your browser settings to refuse or delete cookies at any time.

In the client portal, we do not show a banner. The portal is a signed‑in product, and the analytics described below run as part of it. What that covers is limited and set out here: which features are used and where people get stuck, attached only to an opaque user identifier and an organization identifier, never your email or name, and, as noted below, no session recording at all. If you would prefer we did not collect this for your account, email [email protected] and we will arrange it.

Product analytics in our portal. Our client portal uses PostHog to understand which features are used and where people get stuck. It records page views and interactions with the interface. When you are signed in, the only account details we attach are an opaque user identifier and your organization identifier. We do not send your email address or your name.

Session recording. PostHog records browsing sessions on this marketing website only, not in our client portal. A recording is a replay of your visit: the pages you opened, where you clicked, how you scrolled, the order you did things in, and how long each step took. It is not just a count of page views. Anything you type into a form field is masked. Recordings also capture your browser's console output, which can contain technical messages produced by the page.

A recording made on this website includes the text displayed on the page, which here is public marketing content. It does not include what you type into form fields, which is masked. Recordings are associated with the same opaque user identifier and organization identifier described above, so they are not anonymous.

We made a deliberate choice not to extend this to the client portal. The portal shows one customer's security findings and details of their environment, and we would rather not hold a replay of that at all, so none is captured, rather than captured and obscured.


06Disclosures and service providers

We share personal information only as needed, including with:

  • Service providers (e.g., website hosting, CRM, email service, analytics, security, consultants) bound by confidentiality and appropriate safeguards.
  • Business transfers in connection with a merger, acquisition, or asset sale.
  • Legal disclosures when required by law, regulation, or legal process, or to protect our rights, users, or the public.

Service providers we currently use: Amazon Web Services (hosting and storage), Anthropic (the AI models our agents run on), WorkOS (sign‑in and identity), PostHog (product analytics), Stripe (payments and billing), Cloudflare (network, DNS, and site delivery), and Pipedrive (CRM). We update this list as our providers change.

We do not sell personal information.


07International transfers

We are based in Canada and may store or process information in Canada, the United States, or other locations where our service providers operate. Data held in our platform is stored on Amazon Web Services in the us-east-1 region (Northern Virginia, United States). We implement appropriate safeguards for cross‑border transfers where required by law.


08Security

We use reasonable physical, organizational, and technical safeguards designed to protect personal information against loss, theft, and unauthorized access, disclosure, copying, use, or modification. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.


09Retention

We retain personal information only as long as necessary to fulfill the purposes outlined in this policy and to comply with legal, tax, or accounting requirements. When information is no longer needed, we will delete or de‑identify it.


10Your privacy rights

Your rights depend on where you live. We will make reasonable efforts to honor requests consistent with applicable law.

Canada (PIPEDA)

You may request access to your personal information, correction of inaccuracies, and information about our handling of your data. To submit a request, email [email protected].

United States

Your rights vary by state. If you are a California resident, you may have rights to know/access, correct, delete, opt out of certain processing (e.g., sale or sharing for cross‑context behavioral advertising), and limit use of sensitive personal information (if applicable), subject to legal conditions. We do not sell personal information. To submit a request, email [email protected] and indicate you are a California resident.

We will verify your identity before responding and may refuse requests where an exemption applies or where verification is not possible.


11Children's privacy

Our website and services are intended for business audiences and are not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child provided us personal information, contact us so we can delete it.


Our site may link to third‑party websites or services we do not control. This policy does not apply to those third parties.


13Changes to this policy

We may update this Privacy Policy from time to time. The Effective date above indicates when it was last revised. If we make material changes, we will take reasonable steps to provide notice as required by law.


14How to contact us

If you have questions or complaints about this policy or our privacy practices, contact us at [email protected]. You may also have the right to contact the Office of the Privacy Commissioner of Canada or your local privacy regulator.


Quick summary

  • We collect contact details and inquiry content when you reach out about services.
  • We use information to respond to you, operate and secure our website, and run our business.
  • We share data with service providers under safeguards; we do not sell personal information. Our providers are listed under Disclosures and service providers.
  • Our client portal uses PostHog analytics, identified by an opaque user id and an organization id, not your email address.
  • PostHog records browsing sessions on this marketing website. We do not record sessions in the client portal.
  • Platform data is stored on Amazon Web Services in the us-east-1 region.
  • You can request access or correction (Canada) and may have additional rights in some U.S. states (e.g., California).
  • Contact [email protected] with any questions or requests.