Privacy Policy

Last Updated: August 14, 2026

At Zero Day, we take privacy and security seriously. This Privacy Policy explains how we collect, use, store, protect, and disclose information when you visit our website, use our security services, or use security tools such as our website security scanner.

By accessing or using the Zero Day website and services, you acknowledge that you have read and understood this Privacy Policy.

1. About Zero Day

Zero Day provides cybersecurity services and security tools designed to help businesses identify security risks in their websites, applications, APIs, cloud infrastructure, and other digital assets.

For the purposes of this Privacy Policy, "Zero Day," "we," "us," or "our" refers to the Zero Day business and its applicable legal entity operating the website and services.

"You" or "User" refers to any person or organization accessing our website or using our services.

2. Information We Collect

Depending on how you interact with Zero Day, we may collect different categories of information.

2.1 Information You Provide

When you contact us, request a security assessment, submit an inquiry, or otherwise communicate with us, we may collect:

  • Name
  • Email address
  • Phone number
  • Company or organization name
  • Job title or role
  • Information contained in your messages or requests
  • Information required to provide our services
  • Billing or transaction information where applicable

You may choose not to provide certain information. However, some services or features may not be available without the information required to provide them.

2.2 Information Collected Automatically

When you visit our website, our systems may automatically collect technical information such as:

  • IP address
  • Browser type and version
  • Operating system
  • Device information
  • Language and general configuration information
  • Pages visited
  • Date and time of access
  • Referring website
  • Approximate location derived from technical information
  • Website usage and interaction information
  • Server and security logs

We use this information primarily to operate, secure, maintain, and improve our website and services.

3. Information Collected Through the Security Scanner

Zero Day provides security scanning functionality that allows users to submit a website, domain, URL, or other supported target for security analysis.

When you use the scanner, we may process information associated with the scan, including:

  • The URL, domain, hostname, or target submitted for scanning
  • Date and time of the scan
  • Scan configuration or options selected by the user
  • Scan status and technical logs
  • Security findings generated by the scanner
  • HTTP response and publicly accessible technical information obtained from the target
  • Vulnerability or security-risk information identified during the scan
  • Technical metadata necessary to operate, troubleshoot, secure, and improve the scanner

The information collected during a scan depends on the target and the functionality enabled at the time of scanning.

Important: Authorization to Scan

You are responsible for ensuring that you have permission to scan any website, application, domain, API, server, or other digital asset submitted to the Zero Day scanner.

You must not use Zero Day to scan systems that you do not own or have explicit authorization to test.

Zero Day does not authorize you to access, test, probe, disrupt, exploit, or attempt to gain unauthorized access to third-party systems merely because the scanner is available.

We may restrict, suspend, or terminate access to the scanner where we reasonably believe it is being used for unauthorized, abusive, unlawful, or harmful activity.

4. How We Use Information

We may use information we collect for purposes including:

  • Providing and operating Zero Day services
  • Processing security scans
  • Generating security findings and reports
  • Responding to questions and support requests
  • Communicating with users and customers
  • Maintaining and improving our scanner and website
  • Detecting abuse, fraud, attacks, and unauthorized activity
  • Monitoring system performance and reliability
  • Troubleshooting technical problems
  • Protecting the security and integrity of our infrastructure
  • Maintaining records necessary for business and legal purposes
  • Processing payments where applicable
  • Complying with applicable laws and legal obligations
  • Developing and improving our products and services

We will not use scan information for purposes materially unrelated to providing, securing, maintaining, or improving the relevant service without an appropriate legal basis or notice where required by applicable law.

5. Security Scan Data

Security scan results may contain sensitive technical information about the target submitted by the user.

Depending on the scanner's functionality, results may contain information such as:

  • Detected security weaknesses
  • HTTP headers
  • Technology information
  • Configuration issues
  • Exposed services or endpoints
  • Security-related metadata
  • URLs or paths
  • Evidence associated with identified findings
  • Risk classifications or recommendations

We treat security scan information as confidential and use reasonable technical and organizational safeguards to protect it.

However, users should avoid submitting credentials, passwords, API keys, authentication tokens, personal information, confidential business information, or other sensitive data unless the relevant Zero Day service specifically requires it.

6. How We Share Information

We do not sell your personal information.

We may share information with trusted third parties only when reasonably necessary to operate our business and provide our services.

These parties may include:

Service Providers

We may use third-party infrastructure, hosting, analytics, communication, database, payment, security, or other technology providers. Such providers may process information on our behalf and are expected to handle information in accordance with applicable contractual and security requirements.

Legal Requirements

We may disclose information where reasonably necessary to:

  • Comply with applicable law
  • Respond to valid legal processes
  • Comply with lawful requests from government authorities
  • Protect our rights, property, or security
  • Investigate fraud, abuse, or security incidents
  • Protect users or the public from serious harm

Business Transfers

If Zero Day is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be transferred as part of that transaction, subject to applicable law.

7. Security of Your Information

We use reasonable technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, misuse, or destruction.

Depending on the service and technical architecture, these measures may include:

  • Access controls
  • Authentication and authorization mechanisms
  • Encryption where appropriate
  • Secure server infrastructure
  • Logging and monitoring
  • Security testing
  • Network and application security controls
  • Least-privilege access
  • Regular review of security practices

Despite these measures, no internet-based system can be guaranteed to be completely secure.

You acknowledge that transmitting information over the internet involves inherent risks, and Zero Day cannot guarantee absolute security of information transmitted to or from our services.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • Provide requested services
  • Maintain scan history where applicable
  • Maintain business and security records
  • Resolve disputes
  • Prevent abuse and fraud
  • Comply with legal obligations
  • Enforce agreements
  • Maintain security logs

The retention period for security scan information may vary depending on the type of scan, service configuration, operational requirements, contractual requirements, and applicable law.

Where information is no longer required, we may delete, anonymize, or securely dispose of it, subject to applicable legal and legitimate business requirements.

9. Cookies and Analytics

Zero Day may use cookies and similar technologies to:

  • Operate the website
  • Remember preferences
  • Understand website usage
  • Monitor performance
  • Improve user experience
  • Detect security and abuse-related activity
  • Understand general traffic patterns

We may also use third-party analytics or similar services.

You can control or disable cookies through your browser settings. Disabling certain cookies may affect the availability or functionality of some website features.

10. Third-Party Websites

Our website may contain links to third-party websites, services, documentation, social media platforms, or other resources.

Zero Day is not responsible for the privacy practices, security, content, or policies of third-party websites.

We encourage you to review the privacy policy of any third-party website before providing personal information.

11. Your Privacy Rights

Depending on your location and applicable law, you may have rights regarding your personal information, including the right to:

  • Request access to information we hold about you
  • Request correction of inaccurate information
  • Request deletion of information where legally permitted
  • Request information about how your data is processed
  • Withdraw consent where processing is based on consent
  • Opt out of certain promotional communications
  • Raise a privacy-related complaint or concern

Some requests may be subject to legal, security, contractual, or operational limitations.

To protect users and prevent unauthorized disclosure, we may need to verify your identity before processing certain requests.

12. Children's Privacy

Zero Day's services are intended primarily for businesses, professionals, developers, security researchers, and other users capable of using cybersecurity services responsibly.

We do not knowingly collect personal information from children where such collection is prohibited by applicable law.

If you believe that a child has provided personal information to us without appropriate authorization, please contact us so that we can review and take appropriate action.

13. Security Scanner Limitations

The Zero Day scanner is designed to assist users in identifying potential security weaknesses.

However, a scan does not guarantee that a website, application, API, server, or other digital asset is secure.

Automated security scanners may not detect every vulnerability, configuration issue, business-logic flaw, authentication issue, authorization issue, or other security weakness.

A clean or low-risk scan result should therefore not be interpreted as a guarantee that the target is free from vulnerabilities.

For higher-risk or business-critical systems, we recommend appropriate manual security testing or a professional penetration test in addition to automated scanning.

14. Responsible Use of the Scanner

Users agree to use the Zero Day scanner only for legitimate and authorized security testing.

You must not use the scanner to:

  • Test systems without authorization
  • Disrupt or damage systems
  • Attempt unauthorized access
  • Steal or exfiltrate information
  • Circumvent security controls for malicious purposes
  • Conduct denial-of-service attacks
  • Violate applicable laws
  • Scan targets where you do not have the necessary authorization

You are solely responsible for ensuring that your use of the scanner is lawful and authorized.

15. Security Findings and Reports

Security findings, risk scores, recommendations, and reports generated by Zero Day are provided to assist users in understanding potential security risks.

They should not be interpreted as:

  • A guarantee of security
  • A formal security certification
  • Legal advice
  • Regulatory approval
  • A guarantee of compliance with a particular security framework
  • A guarantee that no vulnerabilities exist

Findings generated by automated systems may contain false positives or false negatives and should be reviewed and validated where appropriate.

16. International Data Processing

Depending on our infrastructure, service providers, and the location of our users, information may be processed or stored in countries other than the country in which you reside.

Where required by applicable law, we will take appropriate measures concerning international transfers and processing of personal information.

17. Data Breaches and Security Incidents

If Zero Day becomes aware of a security incident involving personal information under our control, we will assess the incident and take reasonable steps to contain, investigate, remediate, and respond to it in accordance with applicable law and our security procedures.

Where legally required, affected users or relevant authorities may be notified.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our services
  • Changes to our security scanner
  • Changes to our data-processing practices
  • Changes in applicable laws or regulations
  • Improvements to our privacy practices

When we make changes, we will update the "Last Updated" date at the beginning of this page.

We encourage users to periodically review this page.

19. Contact Us

If you have questions about this Privacy Policy, want to exercise applicable privacy rights, or have concerns about how Zero Day handles information, please contact us:

Zero Day

Website: https://zerodaysecurities.com/

Contact: [email protected]

Location: Pune, Maharashtra, India

For privacy requests, please include enough information for us to understand and verify your request.