Short version: this site has no backend, no accounts, no cookies and no analytics. The longer version is below.
Last updated 8 August 2026
These pages are static files. There is no application behind them, no account to create and no login. The site sets no cookies, includes no analytics or tracking scripts, and loads no third-party resources — fonts and images are served from the same origin as the page, so viewing the site does not make a request to anyone else.
The form on the scoping page runs entirely in your browser. It composes a message and hands it to your own email client, or copies it to your clipboard. Nothing is transmitted to us and nothing is stored when you fill it in — if you close the tab without sending, we never knew you were there.
If you email us, we hold that email and anything in it for as long as it takes to answer you and to keep a record of the conversation. We do not add you to a mailing list and we do not sell or share it. Ask us to delete it and we will.
The site is served by a hosting provider that, like any web server, processes the technical details of your request — IP address, browser user agent, the page you asked for — in order to deliver the page and to protect the service. We do not use those logs to build a profile of you, and we do not combine them with anything else.
Cloudkeel-DD runs on your own infrastructure, and its data — findings, credentials, history — stays in your database. It has no Cloudkeel-operated endpoint to call and nothing in it reports back to us. Three outbound paths exist only if you configure them yourself: notification webhooks, GitHub, and GitLab, each going to a destination you choose. See the security model.
Write to audit@cloudkeel.io.