Privacy Policy
This page explains how the utility is intended to handle session reports, public CVE intelligence, cache data, analytics considerations and future account-based features.
This policy reflects the current operational scope of RiskRank: a session-first public utility with no user accounts or stored reports. It should be reviewed by qualified legal counsel before adding ads, analytics, accounts or paid features.
Session-first reports
Generated reports are session-only and are not stored as user report history. Download or print before closing the session.
Public CVE cache only
The cache is intended for public vulnerability intelligence such as NVD, EPSS and CISA KEV data.
No sensitive inputs required
Users should not enter secrets, private keys, passwords or confidential incident details into public forms.
Detailed privacy policy
Last updated: 2026-06-26
1. Scope of this policy
This Privacy Policy explains how RiskRank handles data. The tool is a public security utility that helps users enrich CVE information, add business context and generate a session-only risk report. No account registration is required.
2. Session-only reports
Reports generated by this utility are session-only and are not stored as user-specific records in the application database. Users should download or print a report before generating a new one, refreshing the page or closing the browser session.
3. CVE lookup cache
The application caches public CVE intelligence to improve performance and reduce repeated external lookups. Cached data may include CVE identifiers, descriptions, CVSS metrics, vectors, references, affected product hints, FIRST EPSS data, CISA KEV status and source timestamps. This cache is for public vulnerability intelligence, not private user reports.
4. No user accounts
RiskRank does not require user accounts, user profiles or saved report history. If account-based features such as saved scenarios, report history or organization workspaces are introduced in a future version, this privacy policy, retention rules and access-control model will be updated before launch.
5. Data users should not enter
Users should not enter secrets, passwords, private keys, confidential incident details, customer names, internal hostnames, private IP addressing schemes, sensitive architecture details or regulated personal data. The input fields are designed for CVE identifiers and general business context, not sensitive operational data.
6. External source requests
When a user performs a CVE lookup, the application queries external vulnerability intelligence sources such as NVD, FIRST EPSS and CISA KEV. These requests retrieve public vulnerability data. Source availability, response time and accuracy depend on the upstream providers.
7. Server logs and abuse protection
The hosting platform collects technical logs such as request time, route, response status, IP-related metadata, user-agent and error traces. These logs are used for troubleshooting, abuse prevention, rate limiting, security monitoring and service reliability. Log retention is governed by the hosting provider's standard policy.
8. Advertising, analytics and cookies
RiskRank does not currently use tracking cookies, advertising networks or user-level analytics. If analytics or advertising are introduced in the future, the deployment will include the required consent controls and privacy notices for the target market. Sensitive report content will not be sent to third-party providers.
9. Data retention
Reports are session-only and are not retained after the browser session ends. Public CVE cache entries may be retained temporarily for performance, keyed on public CVE identifiers only. If saved reports or account data are introduced, retention periods and deletion controls will be published before that feature launches.
10. Security measures
The application uses HTTPS in production, manages secrets through the hosting provider's environment variable system, applies rate limiting and avoids sensitive client-side secrets. Errors are handled carefully to avoid leaking internal state. Security is treated as a practice, not an assumption.
11. Your data rights
Because RiskRank does not store personal data or user reports, there is no user data profile to access, correct or delete. If you believe personal data related to your use of this service is held (for example, in server logs), you may contact igorberner89@gmail.com to request clarification or removal.
12. Changes to this policy
This policy will be updated whenever the application introduces user accounts, saved reports, payment features, advertising, analytics, third-party integrations or new data retention behavior. The last updated date at the top of this policy reflects the date of the most recent revision.
13. Contact
For privacy questions, data handling concerns or requests related to this policy, contact: igorberner89@gmail.com.
Plain-language summary
RiskRank caches public CVE intelligence, not private reports. Reports are generated for the active browser session and should be downloaded by the user before closing. No account, login or personal information is required. If saved reports, accounts or premium services are added in future versions, this policy will be updated before those features launch.