Privacy Policy
Last updated: [DATE] · Applies to the SOPR application operated by [SHIRYON SECURITY — LEGAL ENTITY NAME] ("we," "us," "the Company")
This document reflects exactly what the SOPR application technically does, but is not a substitute for review by a qualified lawyer. Bracketed fields need to be filled in before this is published or shown to anyone.
1. Two different kinds of data, and two different roles we play
SOPR handles two categories of information, and our legal role is different for each one.
A. Account data — information about people who use SOPR itself. For this data, we are the data controller — we decide why it's collected and how it's used.
B. Client documentation data — the actual content stored inside SOPR (server details, credentials, network configuration, and any contact information that appears inside notes or fields). For this data, we generally act as a data processor — we store and protect it on instruction, but the client whose infrastructure it describes determines what's collected and why. This should be reflected in contracts with those clients, separate from this policy.
2. Account data we collect
- Username — to identify your account and control access
- Password (stored as a one-way cryptographic hash, never in readable form) — authentication
- Two-factor authentication secret and backup codes (hashed, never readable) — optional, stronger authentication
- Role and site assignments — to enforce that you only see sites you're authorized for
- Session identifier (a cookie) — to keep you signed in between page loads
- IP address and timestamp, on login attempts and significant actions — security and audit trail
- Language preference — to show the interface in your preferred language
We do not collect analytics, tracking, advertising, or marketing data of any kind, and do not sell or share this data with third parties for marketing purposes.
3. Client documentation data
Whatever your team documents inside SOPR is stored to serve the operational purpose you're using SOPR for. We do not use this content beyond providing the service back to you.
If any of this content includes personal information about people who are not SOPR account holders — for example, a client contact's name and email saved in an asset's notes — it exists in the system only because it was necessary to accurately document the relevant infrastructure, and is protected by the same access controls and encryption as everything else.
4. Cookies
SOPR uses exactly one cookie: a session identifier that keeps you signed in. It is strictly necessary for the application to function, which is why it does not require a separate consent banner under most cookie-consent frameworks. See the full Cookie Notice for technical detail.
5. How we protect this data
- Passwords and MFA secrets are never stored in readable form
- Fields marked "secret" are encrypted at rest
- Access to a site's data is restricted to accounts explicitly granted access, enforced at the database level
- Every login, edit, deletion, and credential view is logged with who, when, and from where
- Optional two-factor authentication is available on every account
6. Data retention
- Session data is automatically deleted on expiry (12 hours) or sign-out
- Audit log and login-attempt records are retained indefinitely at present — there is no automatic deletion policy for this history yet, even though the interface only displays the most recent 300 entries at a time
- Client documentation data is retained for as long as needed for its operational purpose, or until deleted by an authorized user or removed at a client's request
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your account data. For account data, contact [CONTACT EMAIL]. For client documentation data, direct the request to the relevant client relationship, since we act as a processor rather than the decision-maker for that data.
8. Changes to this policy
We will update the "Last updated" date above when this policy changes.
9. Contact
[SHIRYON SECURITY — LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[CONTACT EMAIL]