This Privacy Policy describes how Esprit Labs Inc. (“Esprit Labs,” “we,” “us,” or “our”), the operator of the Trident product, collects, uses, and shares information when you visit our websites or use our services (the “Services”).
If you are an end user whose employer is a Trident customer, the information we process on your employer’s behalf is governed by the agreement between Esprit Labs and your employer. Please also refer to your employer’s privacy policy.
Information we collect
What you give us
Your name, work email, company, role, and login credentials when you set up or join an account; whatever you write to us in sales, support, or a security disclosure; and billing details on a paid plan. If we take card payments, a payment processor handles them — we don’t keep full card numbers.
What we collect automatically
Basic technical and usage data when you visit the site or use the platform: IP address, browser and device details, the pages and features you use, and error logs. This keeps the Services running and secure and shows us what to improve.
Customer Data you connect for testing
Depending on what you enable, this can include target and configuration details, source code and pull requests, request-and-response data captured during a test, credentials you supply for authenticated testing, and the findings we produce. On a paid plan we act as a processor of this material: we use it only to deliver the Services and only as your agreement directs. For free and trial use, we also retain the findings we produce and use them to operate and improve the Services, and to create aggregated, irreversibly de-identified vulnerability research that we may license for security research and industry reporting, and we act as a controller for that limited purpose — see section 5 of our Terms.
Because of how Trident is built, we handle these materials transiently — in memory or a short-lived, encrypted workspace scoped to a single test. Your source code stays private. We do not store your source code: it is never written to our databases, never retained after a test completes, and never used to train third-party general-purpose AI models. The same applies to your repository or GitHub contents, cloud contents, and credentials — we do not persistently store any of them.
Findings are different. We store the findings we produce so you can open, track, share, and retest them; they are held encrypted and scoped to your account. Retention and deletion of findings are governed by section 7, section 12, and — for free and trial use — section 5 of our Terms.
How we use information
- To provide, secure, and improve the Services.
- To create aggregated, irreversibly de-identified vulnerability research from free and trial use, which we may license for security research and industry reporting.
- To communicate about the Services, including account, billing, and security notices.
- To respond to requests, inquiries, and to provide customer support.
- To detect, prevent, and investigate security incidents, fraud, or abuse.
- To comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not use Customer Data to train third-party general-purpose AI models.
Retention and deletion
We retain information only as long as needed to provide the Services, meet legitimate business needs, comply with legal obligations, and resolve disputes. Customer Data is retained for the duration of the customer subscription and deleted as described in the subscription agreement. Findings from free and trial use are governed by section 5 of our Terms, which does not commit us to a retention or deletion schedule for them. Customers may request deletion of their Customer Data at any time by writing to contact@tridentsecurity.io.
Security
We protect information with administrative, technical, and physical safeguards, including encryption in transit and at rest, access controls, logging, and vendor review.
Our SOC 2 report and current audit attestations are available on request through our Trust Center, which also publishes the live status of the controls behind them. If you have questions about our security practices, or want to report something, email us at contact@tridentsecurity.io.
Your choices and rights
You can unsubscribe from our marketing emails any time using the link in them. Depending on where you live, you may also be able to access, correct, delete, or get a copy of your personal information, or object to or limit certain uses. Just email contact@tridentsecurity.io — we may confirm your identity first, and we’ll respond within the time the law gives us.
If you’re a user on a customer’s account, send your request to that customer and we’ll support them in handling it.
International transfers
Esprit Labs is headquartered in the United States. Information we process may be transferred to and processed in the United States or other countries where we or our service providers operate, subject to appropriate safeguards as required by applicable law.
Changes and contact
We’ll update this policy as our practices change; the date at the top always shows the current version, and we’ll flag anything material to active customers. Questions or requests go to:
Esprit Labs Inc. (Trident)San Francisco, California, USA
contact@tridentsecurity.io
tridentsecurity.io