Legal
Privacy policy
What Musterproof collects, why, where it sits and how to get rid of it. Short because we collect little, and we collect little on purpose.
Last updated 25 August 2026
Who is responsible
Tigran Avakov, Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan, is the controller for the data described here. For questions, requests or complaints, write to support@musterproof.com. We answer data requests ourselves; there is no ticket queue between you and the person who runs the service.
Where you upload material about your own customers or staff, you are the controller and we act as your processor, on your instructions, under these terms.
What we collect
To give you an account: the email address you sign in with, and the name of your organisation. There is no password to lose, because there is no password. We email you a single-use link instead.
To do the work: the products you register, the dates and scope classifications you enter, the software bills of materials you upload, and the entries the workflow writes to your journal. A bill of materials lists software components and versions; it does not contain personal data by design, and we have built nothing that would put personal data into one.
To keep it running: ordinary server logs, and a record of which of our emails we sent you so we do not send the same alert twice.
We do not run analytics, advertising or third-party trackers, and the product loads no third-party scripts. The single exception is the payment page, which loads the Paddle checkout script so your card details go straight to the processor and never touch us. That page is the only one where the content security policy allows an outside script at all.
Why we are allowed to
Running your account and doing what you asked is performance of our contract with you. Keeping the service secure, preventing abuse and pursuing unpaid invoices is our legitimate interest. Keeping billing records is a legal obligation. We do not rely on consent for any of this, which is why there is no cookie banner: the only cookie we set is the one that keeps you signed in.
Where it lives, and how it is protected
The database sits in Cloudflare's Western Europe region, and object storage sits in the Cloudflare EU jurisdiction, which is a residency guarantee rather than a placement hint. Uploads are encrypted before they reach storage, with a separate key for each object wrapped by a master key we can rotate without touching your data.
A dependency map of your product is an attack plan against you, and it is treated as one: every query is scoped to your organisation, nobody browses a bucket by hand, and the master key lives outside the account holding the data.
Who else sees it
These are all of them. If the list ever grows, this page changes before the change ships.
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, object storage, email delivery | EU (database in Western Europe, object storage in the EU jurisdiction) |
| Paddle.com Market Ltd | Payment processing, invoicing, tax; merchant of record | UK and EU |
Vulnerability data is pulled on a schedule from OSV.dev, the CISA catalogue of known exploited vulnerabilities and FIRST EPSS. Nothing of yours goes to them: we query by package coordinates, meaning names and versions that are public facts about public packages, and we cache their answers so your pages never wait on someone else's API.
We do not sell data, and we will not hand it to anyone else without a legal obligation. If we ever receive a binding request for your data, we will tell you unless we are forbidden to.
How long we keep it
| Account and product records | While the account is open, then 30 days after you ask us to delete it. |
|---|---|
| SBOM uploads and findings | While the account is open. Deleted with the account, including the object storage prefix that holds them. |
| Compliance journal | While the account is open. It is the evidence you may need years later, so we never trim it on our own. You export it, then we delete it with everything else. |
| Sign-in links | Single use, and they expire whether used or not. |
| Billing records | Kept as long as tax law requires, which is longer than the account lives. Held by the merchant of record, not by us. |
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to what we are doing with it, or ask for it in a portable form. Email support@musterproof.com and we will do it within 30 days, usually the same week. You do not have to explain why, and asking will never affect your account.
Your journal is exportable at any time without asking us, and it verifies without us too — that is the point of the hash chain. If you are in the EU or the UK and think we have got something wrong, you may complain to your national data protection authority, though we would rather you told us first.
Changes
When this policy changes, the date at the top changes with it. If a change affects what we do with data we already hold, we email you before it takes effect.