Privacy
What we collect, and what we refuse to.
A security platform that is vague about its own data handling has no business asking to inspect yours. This says what is collected, why, where it goes and how long it stays.
2A2M SIA · Latvia · last updated 2 September 2026
1Who is responsible
Cidra is operated by 2A2M SIA, a company registered in Latvia. For the account and website data described below we are the controller. For the inventories, artefacts and findings you put into a workspace we are a processor acting on your instructions — those are covered by the data processing agreement.
Privacy questions go to privacy@cidra.dev.
2What we collect
Account data
Your name, work email address, company name and a password hash. If you sign up through the trial we also hold the Stripe customer and subscription identifiers. We never see or store your card number; that stays with Stripe.
Data you upload
Software inventories, bills of materials, binaries and API contracts. These are yours. We process them to produce findings and for no other purpose — we do not use them to train models, we do not aggregate them into industry benchmarks, and we do not sell or share them.
Uploaded binaries and API contracts are analysed in memory and discarded when the request finishes. What is retained is the resulting findings and the artefact hash, never the bytes.
Operational records
Sign-in attempts with the source address, for brute-force protection; an audit log of actions taken in a workspace; and server logs. The audit log is hash-chained and deliberately append-only, which means entries in it cannot be edited or selectively removed — including by us.
Website analytics
Google Analytics runs on the public marketing pages only, and only after you accept it. It is never loaded inside the application, because application URLs contain workspace names and we are not willing to send those to a third party.
3Why we are allowed to hold it
Account and uploaded data: performance of our contract with you. Sign-in records, rate limiting and the audit log: our legitimate interest in keeping the service secure, and yours in the same. Analytics: your consent, which you may withdraw at any time by clearing this site’s stored data in your browser. Billing records: a legal obligation to retain them.
4Who else touches it
We keep this list short on purpose, and it is complete.
- MongoDB Atlas — hosts the database.
- DigitalOcean — hosts the application server, in Frankfurt.
- Stripe — payments and card data, which never reach us.
- Brevo — sends verification email.
- Google Analytics — marketing pages only, after consent.
To answer whether a component is vulnerable we query public advisory sources including OSV, the CISA KEV catalogue and FIRST EPSS. Those queries carry package names and versions. They do not carry your company name, your workspace name, or anything that identifies you as the asker.
5Where it is held
The application server is in Frankfurt, Germany. Stripe and Google may process data outside the EEA under the European Commission’s standard contractual clauses. Where a transfer outside the EEA happens, it happens on that basis.
6How long we keep it
- Sign-in attempts — one hour, then deleted automatically.
- Sessions — seven days maximum, twelve hours idle, and immediately on sign-out.
- Abandoned signups — twenty-four hours, then deleted automatically.
- Workspace data — for as long as the account exists. Deleted within 30 days of account closure, on request.
- Billing records — as long as tax law requires, currently five years.
7Your rights
You may ask for a copy of your data, correction of it, deletion of it, or restriction of how we use it, and you may object to processing based on legitimate interest. Write to privacy@cidra.dev and we will answer within 30 days.
One honest limitation: the audit log is append-only by design, because a security record that can be quietly edited is worth nothing. If you ask for erasure we will delete your account and workspace data, and we will tell you plainly which audit entries must remain and why, rather than promising a deletion we cannot perform.
If we handle a request badly you can complain to your national data protection authority. In Latvia that is the Data State Inspectorate.
8Breach notification
If a breach affects your personal data and is likely to result in a risk to you, we will notify the supervisory authority within 72 hours of becoming aware of it, and we will tell you directly and without delay where the risk is high. We publish a disclosure policy describing how to report a vulnerability to us, and we will not threaten a researcher who does.
9Changes
Material changes will be announced by email to account holders before they take effect. The date at the top of this page always reflects the current version.