Legal
Privacy Policy
Effective August 23, 2026
01Who we are
NullTrace Security LLC, doing business as NullTrace Security ("NullTrace," "we," "us"), is a security consulting firm operating in the United States. Reach us at info@nulltracesec.com.
02What this policy covers
This covers information we collect through this website and when you contact us. It does not cover data we handle inside a client engagement. That is governed by the agreement we sign with that client. Section 05 explains the split.
03What the website collects
This site is static. No accounts, no forms, no cookies we set, no analytics, no advertising trackers. Two things still happen when you load it:
- Server logs. Our host, Amazon Web Services (AWS), records standard request data (IP address, user agent, page requested, timestamp) to serve the page and block abuse.
- Web fonts. Typefaces load from Google Fonts, so your browser connects directly to Google and Google receives your IP address and user agent. Their handling is governed by Google's own privacy policy, not ours.
If we self-host the fonts instead, the second bullet goes away entirely and this section becomes shorter and more accurate. Worth doing.
04What you send us
When you email us we receive whatever is in the message: your name, your employer, and whatever you tell us about your systems.
Ordinary email is not end-to-end encrypted. Please do not send credentials, secrets, architecture diagrams you would not want intercepted, or unremediated findings over plain email. Ask and we will set up an encrypted channel first.
05Client engagement data
Work performed under contract is separate from this policy. During an assessment we may access systems, logs, source code, configurations, and data belonging to a client. How that material is handled, retained, and destroyed is set by the engagement agreement, the NDA, and the rules of engagement signed for that specific piece of work.
Where those documents and this policy disagree, those documents win.
06How we use it
- Responding to inquiries and scoping work
- Delivering and supporting engagements
- Records we are required to keep for tax, insurance, and legal reasons
- Running and securing this website
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use client data or your correspondence to train machine learning models.
07Who else sees it
- Service providers who help us operate (hosting, email, document storage), under contract and limited to what they need
- Where required by law, subpoena, or valid legal process
- A successor entity if the business is sold, bound by these same commitments
08How long we keep it
- Inquiry emails: 24 months
- Engagement records: per contract, typically 7 years for professional liability and tax
- Server logs: per our host's default, typically 30 days
09Security
Encryption in transit, access on a need-to-know basis, multi-factor authentication on business accounts, and encrypted storage for engagement material. No system is perfectly secure and we are not going to claim ours is.
10Your rights
Depending on where you live, state privacy law may give you the right to access, correct, delete, or get a copy of personal information we hold about you, and to opt out of its sale or use for targeted advertising. We do neither of those things, so there is nothing to opt out of, but the other rights stand.
Email info@nulltracesec.com to make a request. We may need to verify who you are first. We will not treat you differently for asking.
11Children
This site is not directed at anyone under 18 and we do not knowingly collect information from children.
12Changes
Revisions get posted here with a new effective date. If a change is material we will say what changed rather than quietly swapping the text.