Effective date: August 30, 2026
Website: https://www.threatunknown.com/
This Privacy Policy explains how Threat Unknown ("Threat Unknown," "we," "us," or "our") collects, uses, discloses, and safeguards personal information when you visit our website or contact us about cybersecurity services. It also describes your privacy rights and how you can exercise them.
Scope. This policy covers personal information we collect through our public website, contact forms, email, and phone inquiries from prospective or existing clients. If we process data on behalf of a client as part of a services engagement, that processing is governed by our services agreement and (if applicable) a Data Processing Addendum (DPA) rather than this website policy.
If you have questions or wish to exercise a privacy right, contact us at the email above.
We collect the following categories of personal information when you provide it or when it is collected automatically from your device:
We do not intentionally collect sensitive personal information through our website.
We use personal information for the following purposes:
We use personal information only for purposes a reasonable person would consider appropriate in the circumstances. If we intend to use it for a materially different purpose, we will explain and seek consent where required by law.
When required, we obtain your consent to collect, use, and disclose personal information. Consent may be express (e.g., you submit a form) or implied (e.g., you contact us about services). We rely on recognized privacy principles such as identifying purposes, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and accountability.
If you subscribe to marketing communications, you may opt out at any time using the unsubscribe link in the message or by emailing us. We comply with Canada's Anti‑Spam Legislation (CASL) where it applies.
Asking first, on this website. Analytics is not essential to running this site, so we ask before we switch it on. PostHog does not load at all until you accept in the cookie banner. If you decline, no analytics cookies are set and no session is recorded. You can change your answer later by clearing this site's data in your browser, and you can adjust your browser settings to refuse or delete cookies at any time.
In the client portal, we do not show a banner. The portal is a signed‑in product, and the analytics described below run as part of it. What that covers is limited and set out here: which features are used and where people get stuck, attached only to an opaque user identifier and an organization identifier, never your email or name, and, as noted below, no session recording at all. If you would prefer we did not collect this for your account, email [email protected] and we will arrange it.
Product analytics in our portal. Our client portal uses PostHog to understand which features are used and where people get stuck. It records page views and interactions with the interface. When you are signed in, the only account details we attach are an opaque user identifier and your organization identifier. We do not send your email address or your name.
Session recording. PostHog records browsing sessions on this marketing website only, not in our client portal. A recording is a replay of your visit: the pages you opened, where you clicked, how you scrolled, the order you did things in, and how long each step took. It is not just a count of page views. Anything you type into a form field is masked. Recordings also capture your browser's console output, which can contain technical messages produced by the page.
A recording made on this website includes the text displayed on the page, which here is public marketing content. It does not include what you type into form fields, which is masked. Recordings are associated with the same opaque user identifier and organization identifier described above, so they are not anonymous.
We made a deliberate choice not to extend this to the client portal. The portal shows one customer's security findings and details of their environment, and we would rather not hold a replay of that at all, so none is captured, rather than captured and obscured.
We share personal information only as needed, including with:
Service providers we currently use: Amazon Web Services (hosting and storage), Anthropic (the AI models our agents run on), WorkOS (sign‑in and identity), PostHog (product analytics), Stripe (payments and billing), Cloudflare (network, DNS, and site delivery), and Pipedrive (CRM). We update this list as our providers change.
We do not sell personal information.
We are based in Canada and may store or process information in Canada, the United States, or other locations where our service providers operate. Data held in our platform is stored on Amazon Web Services in the us-east-1 region (Northern Virginia, United States). We implement appropriate safeguards for cross‑border transfers where required by law.
We use reasonable physical, organizational, and technical safeguards designed to protect personal information against loss, theft, and unauthorized access, disclosure, copying, use, or modification. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
We retain personal information only as long as necessary to fulfill the purposes outlined in this policy and to comply with legal, tax, or accounting requirements. When information is no longer needed, we will delete or de‑identify it.
Your rights depend on where you live. We will make reasonable efforts to honor requests consistent with applicable law.
You may request access to your personal information, correction of inaccuracies, and information about our handling of your data. To submit a request, email [email protected].
Your rights vary by state. If you are a California resident, you may have rights to know/access, correct, delete, opt out of certain processing (e.g., sale or sharing for cross‑context behavioral advertising), and limit use of sensitive personal information (if applicable), subject to legal conditions. We do not sell personal information. To submit a request, email [email protected] and indicate you are a California resident.
We will verify your identity before responding and may refuse requests where an exemption applies or where verification is not possible.
Our website and services are intended for business audiences and are not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child provided us personal information, contact us so we can delete it.
Our site may link to third‑party websites or services we do not control. This policy does not apply to those third parties.
We may update this Privacy Policy from time to time. The Effective date above indicates when it was last revised. If we make material changes, we will take reasonable steps to provide notice as required by law.
If you have questions or complaints about this policy or our privacy practices, contact us at [email protected]. You may also have the right to contact the Office of the Privacy Commissioner of Canada or your local privacy regulator.