Privacy Policy
Effective date: November 15, 2026
EvidnZ is operated by 6 Paths Cyber Security LLC. EvidnZ helps penetration testers convert uploaded evidence, tester context, annotations, redactions, and report metadata into structured findings and report deliverables. This policy describes what data we process and how it is handled.
Data we collect
- Account information — email, hashed password, plan, role, and account status.
- Uploaded evidence and report content — screenshots, tester context, annotations, redactions, finding details, methodology settings, and report metadata that you provide.
- Billing data — subscription status and billing period information returned from Stripe. Card numbers and CVCs are entered directly with Stripe and are not stored by EvidnZ.
- Authentication and email events — sign-in attempts, password reset requests, and transactional email delivery status.
- Abuse and security signals — salted hashes of IP addresses and user-agent strings used transiently for account lockout, rate limiting, and abuse detection.
- Usage and log data — application logs, error reports, and AI-generation counters used to enforce plan limits.
How we use uploaded content
Uploaded content is used to support your own reporting workflow. Screenshots, tester context, annotations, and report fields are used to generate findings, executive summaries, methodology text, conclusions, and report exports on your behalf.
AI processing
EvidnZ sends selected uploaded content to third-party large language model providers to generate or improve report content on your behalf. EvidnZ does not use your uploaded customer content to train a public AI model.
Payments
Subscription payments are processed by Stripe. EvidnZ receives subscription status and billing period information via Stripe webhooks. EvidnZ does not store full payment-card details or CVCs.
Sensitive information
Penetration testing evidence may contain sensitive information such as credentials, tokens, hostnames, IP addresses, or client data. You should avoid uploading data that is not required for report generation and should redact sensitive content before exporting deliverables.
Shared responsibility
EvidnZ provides redaction workflows, sensitive-data warnings, and redacted-image export safeguards. You remain responsible for confirming you are authorized to upload client evidence, reviewing all uploaded content, redacting sensitive information, and verifying exported reports before delivery.
Data retention
Uploaded evidence and report content are stored for your account until you delete them or delete the associated report. Account information and billing history are retained for the duration of your account and for a reasonable period afterward to comply with legal, tax, and abuse-prevention obligations.
Account isolation
Authentication and account-level isolation are used so users can access only their own reports, findings, evidence, annotations, and redactions.
Subprocessors
EvidnZ relies on infrastructure and service providers in the following categories: cloud hosting and edge compute, managed database and storage, transactional email delivery, payment processing (Stripe), and large language model APIs. Subprocessors are used only to operate the service.
Your rights
You may access, edit, and delete your account content from within the application. You may request account deletion or a privacy inquiry by contacting privacy@evidnz.app. Depending on your location, you may have additional rights under applicable data protection laws.
Security
EvidnZ uses private storage for evidence, tenant-scoped access controls, short-lived signed URLs for evidence previews, and abuse-prevention controls. No online service is completely secure; EvidnZ does not guarantee that transmissions or stored data are immune to compromise.
Contact
Privacy inquiries: privacy@evidnz.app
Security issues: security@evidnz.app
Operator: 6 Paths Cyber Security LLC.