Legal

Privacy Policy

Last updated: April 13, 2026 | Effective: April 13, 2026

Forensk (“we,” “our,” or “us”) operates the Forensk MSP Security Operations Platform at forensk.com and app.forensk.com. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our platform, website, agents, and services.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Name, email address, phone number
  • Organization name and billing address
  • Payment information (processed by Stripe; we do not store card numbers)
  • Role and user preferences

1.2 Platform Usage Data

When you use the Forensk platform, we collect:

  • Cases, tickets, and investigation data you create
  • Integration configurations (encrypted credentials stored using AES-128 Fernet encryption)
  • Reports, compliance assessments, and QBRs you generate
  • Audit logs of actions taken within the platform

1.3 Endpoint Data (Forensk Agent)

When you deploy the Forensk Agent on endpoints, it collects:

  • System baseline: hostname, OS, kernel version, uptime
  • Security software status: antivirus, EDR, firewall configuration
  • User accounts and recent authentication events
  • Running processes and network connections
  • Persistence mechanisms (scheduled tasks, startup items, services)
  • Disk usage and installed software inventory

The Forensk Agent is read-only. It does not modify system files, install kernel drivers, or intercept network traffic. All data is transmitted via HTTPS (TLS 1.3) to the Forensk API.

1.4 Forensic Evidence

During investigations, forensic evidence files (log files, memory dumps, disk images) may be uploaded to the platform. This data is:

  • Encrypted at rest using AWS S3 server-side encryption (KMS)
  • Stored in versioned S3 buckets with public access blocked
  • Subject to chain-of-custody tracking with integrity hashing (SHA-256)
  • Retained according to your organization’s retention policy (default: 3 years)

1.5 Website Analytics

Our marketing website may collect standard analytics data (page views, referral sources, browser type). We do not use third-party tracking cookies for advertising purposes.

2. How We Use Your Information

  • Provide the Service: Operate the platform, process investigations, generate reports, manage tickets, run compliance assessments
  • AI Processing: Send anonymized or pseudonymized data to Anthropic’s Claude API for investigation analysis, report generation, and ticket categorization. We log every AI decision for audit purposes.
  • Security Monitoring: Detect threats, correlate alerts, execute auto-healing playbooks, and monitor your security posture
  • Billing: Process payments, manage subscriptions, track usage against tier limits
  • Support: Respond to support requests, provide onboarding assistance, conduct QBRs
  • Improvement: Analyze platform usage patterns to improve features (aggregated, non-identifiable data only)

3. How We Share Your Information

We do not sell your personal information. We share data only in these limited circumstances:

  • Anthropic (Claude AI) — AI-powered investigation and report generation. Data shared: Anonymized investigation context, no PII unless in evidence.
  • AWS — Cloud infrastructure (hosting, storage, database). Data shared: All platform data (encrypted at rest and in transit).
  • Stripe — Payment processing. Data shared: Billing information only.
  • Integration Partners — NinjaOne, SentinelOne, etc. — only when you connect them. Data shared: API credentials you provide (encrypted), sync data.
  • Law Enforcement — When required by valid legal process. Data shared: As specified in the legal request.

4. Data Security

We implement defense-in-depth security:

  • Encryption in transit: TLS 1.3 for all connections
  • Encryption at rest: AWS KMS for S3, RDS encryption, Fernet (AES-128) for integration credentials
  • Access control: Role-based access control (RBAC) with 6 role levels
  • Multi-tenancy isolation: PostgreSQL Row-Level Security (RLS) ensures tenants cannot access each other’s data
  • Audit logging: Immutable audit trail with SHA-256 integrity chains
  • Authentication: JWT with 30-minute access tokens, bcrypt password hashing, MFA support
  • Infrastructure: AWS VPC with private subnets, security groups, NAT gateway

5. Data Retention

  • Account information: Duration of account + 30 days after deletion
  • Investigation data and cases: Per your organization’s setting (default: 3 years)
  • Forensic evidence files: Per your organization’s setting (default: 3 years)
  • Audit logs: 7 years (regulatory requirement)
  • AI decision records: 3 years
  • Tickets and comments: 3 years after closure
  • Integration sync logs: 90 days
  • Agent snapshots: Rolling 1 year

You may request earlier deletion of your data by contacting privacy@forensk.com.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate personal data
  • Deletion: Request deletion of your data (subject to legal retention requirements)
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing of your data for certain purposes
  • Restriction: Request limited processing of your data

To exercise these rights, contact privacy@forensk.com. We respond within 30 days.

7. CCPA Disclosure (California Residents)

Under the California Consumer Privacy Act, California residents have additional rights including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.

8. GDPR Compliance (EU/EEA Residents)

For users in the EU/EEA, we process data under the following legal bases:

  • Contract performance: Processing necessary to provide the service you subscribed to
  • Legitimate interest: Security monitoring, fraud prevention, service improvement
  • Legal obligation: Compliance with applicable laws and regulations
  • Consent: Marketing communications (opt-in only)

For data transfer outside the EU/EEA, we rely on AWS’s Standard Contractual Clauses.

9. Children’s Privacy

Forensk is a B2B service not directed at individuals under 18. We do not knowingly collect data from children.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or platform notification at least 30 days before they take effect.

11. Contact Us

For privacy-related inquiries: