Back to home

Privacy Policy

Effective date: November 15, 2026

EvidnZ is operated by 6 Paths Cyber Security LLC. EvidnZ helps penetration testers convert uploaded evidence, tester context, annotations, redactions, and report metadata into structured findings and report deliverables. This policy describes what data we process and how it is handled.

Data we collect

  • Account information — email, hashed password, plan, role, and account status.
  • Uploaded evidence and report content — screenshots, tester context, annotations, redactions, finding details, methodology settings, and report metadata that you provide.
  • Billing data — subscription status and billing period information returned from Stripe. Card numbers and CVCs are entered directly with Stripe and are not stored by EvidnZ.
  • Authentication and email events — sign-in attempts, password reset requests, and transactional email delivery status.
  • Abuse and security signals — salted hashes of IP addresses and user-agent strings used transiently for account lockout, rate limiting, and abuse detection.
  • Usage and log data — application logs, error reports, and AI-generation counters used to enforce plan limits.

How we use uploaded content

Uploaded content is used to support your own reporting workflow. Screenshots, tester context, annotations, and report fields are used to generate findings, executive summaries, methodology text, conclusions, and report exports on your behalf.

AI processing

EvidnZ sends selected uploaded content to third-party large language model providers to generate or improve report content on your behalf. EvidnZ does not use your uploaded customer content to train a public AI model.

Payments

Subscription payments are processed by Stripe. EvidnZ receives subscription status and billing period information via Stripe webhooks. EvidnZ does not store full payment-card details or CVCs.

Sensitive information

Penetration testing evidence may contain sensitive information such as credentials, tokens, hostnames, IP addresses, or client data. You should avoid uploading data that is not required for report generation and should redact sensitive content before exporting deliverables.

Shared responsibility

EvidnZ provides redaction workflows, sensitive-data warnings, and redacted-image export safeguards. You remain responsible for confirming you are authorized to upload client evidence, reviewing all uploaded content, redacting sensitive information, and verifying exported reports before delivery.

Data retention

Uploaded evidence and report content are stored for your account until you delete them or delete the associated report. Account information and billing history are retained for the duration of your account and for a reasonable period afterward to comply with legal, tax, and abuse-prevention obligations.

Account isolation

Authentication and account-level isolation are used so users can access only their own reports, findings, evidence, annotations, and redactions.

Subprocessors

EvidnZ relies on infrastructure and service providers in the following categories: cloud hosting and edge compute, managed database and storage, transactional email delivery, payment processing (Stripe), and large language model APIs. Subprocessors are used only to operate the service.

Your rights

You may access, edit, and delete your account content from within the application. You may request account deletion or a privacy inquiry by contacting privacy@evidnz.app. Depending on your location, you may have additional rights under applicable data protection laws.

Security

EvidnZ uses private storage for evidence, tenant-scoped access controls, short-lived signed URLs for evidence previews, and abuse-prevention controls. No online service is completely secure; EvidnZ does not guarantee that transmissions or stored data are immune to compromise.

Contact

Privacy inquiries: privacy@evidnz.app
Security issues: security@evidnz.app
Operator: 6 Paths Cyber Security LLC.