shadowperimeter

Privacy policy

Last updated: October 7, 2026

In short: we only collect what you send us (name, email, domain) plus the technical details of your public domain. We do not sell your data, we keep reports confidential, and you can ask us to delete your information at any time.

Who we are

Shadow Perimeter is run by Edgar Gutierrez from Downey, California, USA. We produce external attack-surface reports for small businesses. Privacy contact: ceo@shadowperimeter.com.

What we collect

How we use it

To deliver the snapshot or report you requested, answer you, run the services you buy, send invoices, protect the site, comply with the law and improve our reports. We do not sell your data, do not share it for advertising, and do not publish your findings or name you as a client without your written permission.

Who we share it with

Only service providers that help us run the business, on our behalf, and only as needed:

How long we keep it

Your rights

You can ask us what information we hold about you, get a copy, correct it, delete it, or limit its use. Write to ceo@shadowperimeter.com. We may ask you to confirm your identity (for example by writing from the same business email). An authorized agent may act for you with your written permission. We answer within a reasonable time and at most 45 days, and we will not treat you worse for using your rights. If you are a California resident these are also your rights under CCPA/CPRA. We do not sell or share personal information, and we do not track you across sites, so there is nothing to opt out of; we honor Do Not Track and Global Privacy Control signals because we do not track.

Business outreach emails

If we email a business address, we identify ourselves, use an honest subject line and give you a clear way to ask us to stop, which we honor within 10 business days. Our unsolicited outreach, if any, relies only on public information about a domain (for example, a missing email-authentication record); it never involves accessing any system. We comply with CAN-SPAM and, for Canada, CASL.

Security

We use encrypted connections, restricted access and retention limits, and we handle reports as confidential. No system is 100% secure. If an incident affecting your information occurs, we will notify you as the law requires.

Other details

Your information is processed in the United States. Our services are for businesses and are not directed to anyone under 18. This site may link to third-party pages that have their own policies. We may update this policy; the new version will be published here with its date.