Legal
Privacy policy
What Musterproof collects, why, where it sits and how to get rid of it. Short because we collect little, and we collect little on purpose.
Last updated 6 October 2026
Who is responsible
Tigran Avakov, a self-employed individual, Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan, is the controller for the data described here. For questions, requests or complaints, write to support@musterproof.com. We answer data requests ourselves; there is no ticket queue between you and the person who runs the service.
Where you upload material about your own customers or staff, you are the controller and we act as your processor, on your instructions, under these terms.
What we collect
To give you an account: the email address you sign in with, and the name of your organisation. There is no password to lose, because there is no password. We email you a single-use link instead.
To do the work: the products you register, the dates and scope classifications you enter, the software bills of materials you upload, and the entries the workflow writes to your journal. A bill of materials lists software components and versions; it does not contain personal data by design, and we have built nothing that would put personal data into one.
To share a release pack: the label you give each buyer link (free text, often a company name), which stays in our database and is shown only to people in your organisation. For the person who opens a link we keep a count of page views and downloads, and the time of the first and the last one. We do not keep their IP address or browser. That person does not sign in, the page sets no cookie and it loads no script. The explanations you write when you record a decision about a finding are part of the pack, so anyone who holds a link to a pack that includes them can read them.
To keep it running: error messages from our own code, and a record of which of our emails we sent you so we do not send the same alert twice. Cloudflare, which runs the service, saves the address of the page that was being requested together with each error message, but not the visitor's IP address or browser. When someone opens a buyer link, a sign-in link or a payment link we write no such message, so those links do not appear in these messages. The automatic per-request log that Cloudflare Workers can keep for our code is switched off. These messages are deleted automatically after a few days.
We do not run analytics, advertising or third-party trackers. Two pages load a script from another company, and nowhere else does our content security policy allow one. The payment page loads the Paddle checkout script, so your card details go straight to the processor and never touch us. The sign-in page loads Cloudflare Turnstile, a bot check that runs in your browser when the page opens. Your browser sends Cloudflare its IP address, user agent and other browser signals. When you submit the form, our server sends Cloudflare the check's token and your IP address to confirm it. The email address you type does not go to Cloudflare through this check.
Why we are allowed to
Running your account and doing what you asked is performance of our contract with you. Keeping the service secure, preventing abuse and pursuing unpaid invoices is our legitimate interest. Keeping billing records is a legal obligation. We do not rely on consent for any of this, which is why there is no cookie banner: the only cookie we set is the one that keeps you signed in.
Where it lives, and how it is protected
The database sits in Cloudflare's Western Europe region, and object storage sits in the Cloudflare EU jurisdiction, which is a residency guarantee rather than a placement hint. Uploads are encrypted before they reach storage, with a separate key for each object wrapped by a master key we can rotate without touching your data.
A dependency map of your product is an attack plan against you, and it is treated as one: every query is scoped to your organisation, nobody browses a bucket by hand, and the master key lives outside the account holding the data.
Who else sees it
These are all of them. If the list ever grows, this page changes before the change ships.
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, object storage, email delivery | EU (database in Western Europe, object storage in the EU jurisdiction) |
| Cloudflare, Inc. (Turnstile) | Bot check on the sign-in page | Cloudflare's global network, not limited to the EU |
| Paddle.com Market Ltd | Payment processing, invoicing, tax; merchant of record | UK and EU |
Cloudflare delivers every page of the service through its global network. In doing so it processes each visitor's IP address and the address requested, and it keeps network-level analytics for the domain for a limited time, about a month. We do not use that data to find out who opened a link.
Vulnerability data is pulled on a schedule from OSV.dev, the CISA catalogue of known exploited vulnerabilities and FIRST EPSS. Nothing of yours goes to them: we query by package coordinates, meaning names and versions that are public facts about public packages, and we cache their answers so your pages never wait on someone else's API.
We do not sell data, and we will not hand it to anyone else without a legal obligation. If we ever receive a binding request for your data, we will tell you unless we are forbidden to.
How long we keep it
| Account and product records | While the account is open, then 30 days after you ask us to delete it. |
|---|---|
| SBOM uploads and findings | While the account is open. Deleted with the account, including the object storage prefix that holds them. |
| Release packs and buyer links | While the account is open. A pack is never edited after it is built. A link works until it expires (30 days unless you choose another term, 365 at most) or you revoke it, even after a subscription ends. When you ask us to delete the account, its links stop working at once and its packs are deleted with everything else 30 days later. |
| Compliance journal | While the account is open. It is the evidence you may need years later, so we never trim it on our own. You export it, then we delete it with everything else. |
| Sign-in links | Single use, and they expire whether used or not. |
| Billing records | Kept as long as tax law requires, which is longer than the account lives. Held by the merchant of record, not by us. |
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to what we are doing with it, or ask for it in a portable form. Email support@musterproof.com and we will do it within 30 days, usually the same week. You do not have to explain why, and asking will never affect your account.
Your journal is exportable at any time without asking us, and it verifies without us too — that is the point of the hash chain. If you are in the EU or the UK and think we have got something wrong, you may complain to your national data protection authority, though we would rather you told us first.
Changes
When this policy changes, the date at the top changes with it. If a change affects what we do with data we already hold, we email you before it takes effect.