← Back to Home

Privacy Policy

Last updated: March 18, 2026

1. Who We Are

Vantalab Pte. Ltd. ("Vantalab", "we", "us") operates the Hadrian platform at hadrian.vantalab.ai. We provide AI-powered offensive security and autonomous hardening services. Our registered address is in Singapore.

2. Data We Collect

We collect the minimum data necessary to provide our services:

  • Briefing form data: Name, work email, company, role, primary domain, and engagement driver — submitted voluntarily when you request a briefing.
  • Analytics data: We use Google Analytics 4 to collect anonymized usage data (pages visited, session duration, referral source). No personally identifiable information is collected through analytics.
  • Engagement data: During active security engagements, we process technical data about your domain infrastructure (subdomains, DNS records, HTTP headers, API responses) as necessary to deliver our services. This data is collected only with your explicit authorization.

3. How We Use Your Data

  • To respond to briefing requests and provide quotes
  • To deliver security assessments and hardening services
  • To improve our platform and understand how visitors use our website
  • To comply with legal obligations

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Data Retention

Briefing form submissions are retained for the duration of our business relationship plus 12 months. Engagement data (scan results, findings, remediation logs) is retained for the contractually agreed period, after which it is securely deleted. Analytics data is retained for 14 months per Google Analytics defaults.

5. Data Security

All data is transmitted over TLS 1.3. Our infrastructure enforces HSTS with a 2-year max-age. Engagement data is stored on encrypted volumes with access restricted to authorized personnel. We follow industry-standard security practices — as you'd expect from a security company.

6. Cookies

We use Google Analytics cookies ( _ga, _ga_*) for anonymized website analytics. No advertising or tracking cookies are used. You can opt out by using a browser extension like Google Analytics Opt-out or by enabling Do Not Track in your browser.

7. Your Rights

Under the Singapore Personal Data Protection Act (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Withdraw consent for data processing
  • Request a copy of your data in a portable format

To exercise any of these rights, email privacy@vantalab.ai.

8. Third-Party Services

  • Google Analytics 4 — website analytics (Google Privacy Policy)
  • Caddy — web server and TLS termination (no data shared externally)
  • YesWeHack — responsible disclosure platform for vulnerability reporting

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated "last updated" date. Continued use of our services after changes constitutes acceptance of the revised policy.

10. Contact

For privacy-related inquiries, contact us at privacy@vantalab.ai.

For general enquiries: enquiries@vantalab.ai