Trust Center

Privacy Policy

Kryptx Technologies LLC operates TrapLayer and handles public observatory telemetry, customer account data, billing metadata, reports, and private attack evidence for defensive security intelligence.

Effective date: September 1, 2026. Version: 2026-09-01.

Scope

This Privacy Policy explains how TrapLayer collects, uses, discloses, retains, and protects information when you visit the public site, request access, create a trial, use customer or partner portals, purchase subscriptions, receive reports, or use TrapLayer APIs.

Production policy

TrapLayer is a business-to-business security product. The service is not designed for children, household consumer use, or submission of sensitive personal information into lures, forms, or support channels.

Information We Collect

Account dataCompany name, contact name, work email, role, tenant, reseller relationship, plan interest, subscription status, support notes, and account settings.
Authentication dataPassword hashes, password reset token metadata, login timestamps, session metadata, IP-derived security context, and account audit events.
Billing dataStripe customer IDs, checkout/session IDs, subscription IDs, product/price IDs, invoice metadata, payment status, seat/add-on counts, and billing email. TrapLayer does not store full payment card numbers.
Usage dataAPI key metadata, API-call counts, feed format usage, portal activity, report downloads, entitlement checks, rate-limit events, and service health/audit logs.
CommunicationsContact forms, reseller inquiries, signup notes, support requests, operational emails, report delivery events, and related correspondence.

Security Telemetry

Observed attacksRequests and interactions with TrapLayer decoys, APIs, documents, login pages, fake secrets, canary artifacts, SSH, SMTP, database, cloud, DevOps, AI-agent, and industrial-control lures.
Derived intelligenceClassification, risk score, confidence, timestamps, source IP indicators where licensed, ASN, country, coarse geography, client-family labels, protocol behavior, payload hashes, command-pattern labels, campaign clusters, MITRE/CVE context, and recommendations.
Private evidenceOperators may review raw or detailed evidence such as headers, payload snippets, user agents, session context, canary identifiers, and request metadata inside restricted administrative workflows.
Public outputsPublic dashboards and reports use sanitized aggregate data and exclude raw payload bodies, raw headers, usable credentials, session identifiers, canary token values, customer account data, and red evidence.

How We Use Information

TrapLayer uses information to operate and secure the platform, provide trials and subscriptions, authenticate users, enforce entitlements, deliver feeds and reports, process billing, respond to inquiries, monitor reliability, prevent abuse, improve detection quality, develop new features, comply with law, and protect TrapLayer, customers, partners, and the public service.

Threat intelligence
Telemetry is normalized, enriched, classified, aggregated, and summarized to generate public-safe observatory data and licensed customer intelligence.
Account operations
Account and usage data supports onboarding, customer portal access, partner portal access, billing status, audit trails, report delivery, and customer support.
Security and abuse prevention
Logs and metadata are used to detect unauthorized access, credential abuse, API-key misuse, scraping, service attacks, and policy violations.

How We Share Information

TrapLayer does not sell personal information. TrapLayer may share information with service providers, subprocessors, professional advisors, payment processors, hosting providers, email providers, security providers, analytics/support tooling, corporate transaction parties, law enforcement or regulators when legally required, and customers or partners as needed to provide contracted services.

Payment processorStripe processes checkout, subscription, invoice, and payment method information under its own terms and privacy practices.
Email providersEmail providers may process account setup, password reset, notification, reseller inquiry, report delivery, billing, and operational messages.
Customer reportsReports and feeds may include security indicators, derived intelligence, and account-specific usage or entitlement context according to the customer's purchased tier.
Legal/securityInformation may be disclosed when reasonably necessary to comply with law, enforce terms, investigate abuse, protect systems, or prevent harm.

Cookies and Similar Technologies

TrapLayer may use cookies, sessions, local storage, logs, and similar technologies for authentication, security, preference retention, checkout flow continuity, analytics, rate limiting, and service reliability. Browser settings may allow you to block cookies, but some portal, checkout, or authentication features may not work correctly without them.

Data Retention

TrapLayer retains information for as long as needed to operate the service, provide subscriptions and reports, maintain audit records, enforce entitlements, satisfy legal/accounting obligations, investigate security issues, and improve intelligence quality. Retention periods may differ by data type, customer tier, legal requirement, and operational configuration.

Account and billing records
Retained while the account is active and for a reasonable period afterward for audit, tax, billing, dispute, and legal purposes.
Security telemetry
Retained according to operational settings, customer agreements, and evidence-handling requirements. Aggregated or de-identified intelligence may be retained longer for trend analysis and model improvement.
API keys and passwords
API keys and passwords are stored as hashes where supported. Plaintext API keys are shown only at creation and should be stored securely by the customer.

Your Choices and Rights

Depending on your location and relationship with TrapLayer, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. Business account administrators may also control user access, API keys, notification settings, and billing contacts through the customer or partner portal where available.

TrapLayer may need to verify identity, preserve security/audit records, retain billing records, or decline a request where required or allowed by law.

International Processing

TrapLayer and its service providers may process information in the United States and other locations where infrastructure, support, billing, security, or email providers operate. By using the service, you understand information may be processed outside your jurisdiction.

Security

TrapLayer uses technical and organizational controls designed to protect account data, API keys, authentication records, billing metadata, operational telemetry, and private evidence. No system is perfectly secure. Customers remain responsible for securing their own credentials, API keys, integrations, endpoints, and downstream use of intelligence.

Children

TrapLayer is not directed to children and does not knowingly collect personal information from children. If you believe a child provided personal information to TrapLayer, contact us so it can be reviewed and removed where appropriate.

Changes to This Policy

TrapLayer may update this Privacy Policy from time to time. Material changes will be posted publicly and may require renewed acceptance for trials, purchases, or continued portal access.

For privacy, security, or data-handling questions, contact Kryptx Technologies LLC through the TrapLayer contact, customer, partner, or operator support channels configured for your account.

Intelligence summary

Summary