Last updated: August 19, 2026
Security Blueprints LLC, California 94022, United States of America, operates this website (https://securityblueprints.io/) . This policy describes what the site collects, why, where it is stored, how long it is kept, and how to ask us to change or delete it. Questions about any of it go to [email protected] .
Most of the site collects nothing. Reading an analysis, an invariant or a post needs no account, and we set no cookies of our own. Two things do collect information: the consulting inquiry form, and third-party services embedded in the pages. Both are described below.
What the Inquiry Form Collects
Sending the form on the consulting page submits the following to us:
- Name. Required.
- Work email address. Required. It is how we reply.
- Company and stage. Optional. Headcount or funding stage is what the field asks for.
- Your message. Required, and the part that matters. This is free text, and what goes in it is up to you. See below.
- Timing. One of four options about when you want to start.
- Budget range. One of five bands.
- Which form you used. A hidden value recording whether the submission came from the consulting form on this site or from the enterprise form on our game site, which posts to the same backend. It identifies the form, not you.
The form sends nothing else. No tracking identifier, no advertising identifier, and no reading history: we do not connect form submissions to analytics data. Our host records the ordinary metadata of the request that carries the submission, described under Where It Is Stored .
Sending the form does not send us your inquiry. See Confirming Your Inquiry .
Confirming Your Inquiry
Submitting the form puts your inquiry in a holding state and sends one email to the address you gave. That email asks you to confirm. Until you click the link in it, nobody reads what you wrote.
This exists because anyone can type anyone’s address into a web form. Confirmation is how the address proves it is yours before we act on anything sent under it.
Two things follow, and both are deliberate:
- The confirmation email quotes nothing you wrote. Not your message, not your name, not your company. It says only that someone used this address and offers a link. If you did not submit the form, that email tells you so and tells you that ignoring it ends the matter, and it cannot be used to deliver anyone’s words to you.
- An unconfirmed inquiry is deleted. The link is good for 24 hours. Seven days after it expires we delete the record, and nothing about it is kept: not the message, not the address, not a hash of the address. If someone forged your address, the whole thing disappears without you doing anything.
Once you confirm, the inquiry is emailed to Niels Provos and retained as described under How Long We Keep It .
Why We Collect It
To read your inquiry and answer it. That is the entire purpose.
Niels Provos reads the submissions and replies. If a conversation follows, we use your email address to have it. We do not add you to a mailing list, because there is no mailing list. We do not sell inquiries, and we do not share them with anyone for marketing.
What You Write in the Message Field
People use this field to describe their organization’s security posture: what worries them, where the gaps are, what has already gone wrong. We treat everything in it as confidential business information about your company.
Concretely, that means we do not repeat it, quote it, or use it as material. The analyses published here are written from public breach disclosures and public reporting, never from inquiries. If something you told us ever seemed worth writing about, we would ask you first, and no is an answer.
Use judgment anyway. An inquiry form is a reasonable place to write that your production database has no audit logging and it keeps you up at night. It is not the place for credentials, access tokens, customer records, or the particulars of an incident under legal privilege. Write enough to make the first conversation useful and save the rest for that conversation.
Where It Is Stored
Your browser posts the form over HTTPS to a Cloudflare Worker at forms.securityblueprints.io, which writes the submission to a Cloudflare D1 database.
Cloudflare, Inc. is a processor for this: it runs the endpoint, holds the database, sends both emails and operates the Turnstile check, all on our behalf and under its own terms for those services. Cloudflare may also record the ordinary metadata of the request that carries your submission.
We store the country derived from your IP address and your browser’s user agent string alongside the inquiry. We do not store the address itself.
The database is not public. Access is limited to Niels Provos.
How Long We Keep It
We keep an inquiry for 24 months after the last contact about it, then delete it. Last contact means the most recent message in either direction, so an inquiry we answer and hear nothing further about is deleted 24 months after our reply.
That clock starts at confirmation, because an unconfirmed inquiry is not kept at all: see Confirming Your Inquiry .
Two things sit outside it. If an engagement begins, the records belonging to that engagement are kept under the engagement agreement and on its terms. Submissions rejected as spam are discarded rather than retained.
You can ask us to delete an inquiry sooner. See Your Rights .
Spam Prevention
The form carries three anti-spam measures.
- A honeypot field, hidden from view and from screen readers. A person never sees it and never fills it in; automated submitters fill in every field they find. Anything in it means the submission is discarded.
- A timing check: how long the form was open before it was sent. A form completed in under a few seconds was not read by a human. The threshold is the server’s, not a value your browser sends.
- Cloudflare Turnstile, which runs in your browser and gives us a token our server then verifies with Cloudflare. It replaces the kind of test that asks you to label photographs; in most cases it asks you to do nothing at all. Turnstile is operated by Cloudflare, Inc. under its own terms, and it may read and set data in your browser and observe signals about the browser itself in order to tell a person from a script. We receive only Cloudflare’s verdict, not those signals. Cloudflare states that it does not use Turnstile data to profile individuals or serve advertising.
The first two collect nothing about you. All three are enforced on the server, because a check that only runs in the browser is not a check.
Turnstile needs JavaScript. With JavaScript switched off the form cannot be submitted, and it says so rather than accepting six fields it cannot send.
Analytics
We use a third-party analytics service (Google Analytics) to see which pages are read. It reports traffic in aggregate. We do not use it to identify individual readers, and we do not join it to inquiry submissions.
Comments
Articles and these policy pages carry a comment section provided by Hyvor Talk, an embedded third-party service. A comment you post goes to Hyvor and is governed by Hyvor’s own privacy policy. This site is static and stores none of it.
Cookies Etc.
We set no cookies of our own. Third-party services embedded in the pages may set their own. To learn more about these and your choices in relation to them, please refer to our Cookie Policy .
How We Share Your Information
We do not sell personal information, and we do not share it with anyone for marketing.
Beyond the processors named above, which handle data so the site can function, we may disclose information:
- To comply with applicable law, regulation, court order or other legal process
- To enforce your agreements with us, including this Privacy Policy
- To respond to claims that your use of the site violates any third-party rights
If the Service or our company is merged with or acquired by another company, information held by us would transfer to the new owner.
Your Rights
Depending on the law that applies to you, you may have a right to:
- Access and rectify or erase your personal data
- Receive a copy of your personal data
- Restrict or object to the active processing of your data
- Ask us to share (port) your personal information to another entity
- Withdraw any consent you provided to us to process your data
- Lodge a complaint with a statutory authority, and such other rights as may be relevant under applicable laws
Write to [email protected] to exercise any of them. If your request is about an inquiry you sent, tell us the email address you used, so we can find it. We will respond in accordance with applicable law.
You never have to use the form. If you do, the name, email, message, timing and budget fields are required, because without them there is no inquiry to answer. Everything else on the site is readable without giving us anything.
Security
Submissions travel over HTTPS and are stored as described above, and we use reasonable measures to protect the information under our control. We will not tell you that makes it invulnerable. The rest of this site is a record of what happens when that assumption goes untested. If you would rather not put something in a web form, do not put it in this one.
Modifications to This Policy
We modify this policy as the site changes. The current version is always on this page, with the date at the top.
Changes take effect on posting for:
- Minor updates and clarifications
- New features that do not materially change what we collect
- Security improvements
- Technical necessity
- Legal compliance
For material changes to what we collect or to your rights, we will post a notice on the site for 14 days and update the date at the top of this policy.
Grievance and Data Protection Contact
If you have a question or a complaint about how your information is handled, email our Grievance Officer at Security Blueprints LLC: [email protected] . We will address it in accordance with applicable law.
Comments