Privacy
What we collect, and why
Short version: we measure how our research and product pages perform, we store what you give us when you ask for a report or an account, and we do not run advertising or sell anything to anyone.
Last updated 29 August 2026
01 · Cookies
What is set, and when
Necessary cookies are always on. They keep you signed in, carry your session between pages, and remember the choice you make about the cookies below. Nothing about them is optional — without them the site does not function — and none of them are used to profile you.
Analytics cookies are Google Analytics 4, loaded through Google Tag Manager. They tell us which research gets read, which pages people leave, and which campaign or link brought someone here. They are first-party and we do not use them to build advertising audiences.
We do not run Google Ads, and the advertising, ad-personalisation and ad-user-data signals are switched off unconditionally on every page for every visitor. There is no choice that turns them on, because there is nothing here for them to do.
02 · Your choice
Where we ask, and where we assume
In the EEA, the United Kingdom and Switzerland, analytics are off until you turn them on. You get a banner on your first visit, nothing analytics-related is stored before you answer it, and you can decline without any part of the site working differently.
Everywhere else, analytics are on by default and you can turn them off at any time using the control below. This is the standard opt-out model, and it is the reason this notice exists in the detail it does: if we are going to measure by default, the description of what that means has to be easy to find and easy to act on.
If your browser sends a Global Privacy Control signal, we treat it as a decision in the regions where it is legally recognised and in the opt-in regions above — no banner, analytics off, nothing further asked.
Whichever way you answer, the choice is stored in a first-party cookie for 180 days and then we ask again. Turning analytics off also deletes the Google Analytics cookies already on your browser, rather than only changing what happens next.
Change your choice at any time: .
03 · Data you give us
Reports, accounts and email
To read a gated threat-research report we ask for your name, work email, company and role, and optionally your phone number and the SIEM or EDR stack you run. We use it to send you the report, to understand which kinds of teams our research is reaching, and — if you tick the box that says so — to email you about future research. The box is not pre-ticked and the report is delivered either way.
The link that unlocks a report is a signed token tied to your email address. It is valid for six months, it carries no personal data inside it beyond the address it was issued to, and it is moved out of the URL into a cookie the moment you open it so it does not end up in your address bar, your browser history or a link you paste to a colleague.
If you create an account we store what you enter on the signup form and what you subsequently create in the product. That data belongs to your organisation and is not used to train anything or shared with anyone.
04 · Third parties
Who else sees any of this
Google, as the processor behind Google Analytics and Tag Manager, and only for visitors whose analytics consent is on. Our email provider, to deliver the report or account mail you asked for. Our hosting and infrastructure providers, which necessarily process traffic in order to serve the site.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not pass it to data brokers. Those are not aspirations; there is no mechanism on this site that would do any of them.
05 · Your rights
Asking us to show, correct or delete
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Where we rely on your consent — analytics, and research email — you can withdraw it at any time, and withdrawing it is as easy as giving it was.
Email privacy@detectionhub.ai and we will respond within 30 days. If you are in the EEA or the UK and you are not satisfied with how we have handled a request, you have the right to complain to your national data protection authority.
