Kryptx Technologies LLC operates TrapLayer and handles public observatory telemetry, customer account data, billing metadata, reports, and private attack evidence for defensive security intelligence.
Effective date: September 1, 2026. Version: 2026-09-01.
Scope
This Privacy Policy explains how TrapLayer collects, uses, discloses, retains, and protects information when you visit the public site, request access, create a trial, use customer or partner portals, purchase subscriptions, receive reports, or use TrapLayer APIs.
Production policy
TrapLayer is a business-to-business security product. The service is not designed for children, household consumer use, or submission of sensitive personal information into lures, forms, or support channels.
Information We Collect
Account data
Company name, contact name, work email, role, tenant, reseller relationship, plan interest, subscription status, support notes, and account settings.
Stripe customer IDs, checkout/session IDs, subscription IDs, product/price IDs, invoice metadata, payment status, seat/add-on counts, and billing email. TrapLayer does not store full payment card numbers.
Usage data
API key metadata, API-call counts, feed format usage, portal activity, report downloads, entitlement checks, rate-limit events, and service health/audit logs.
Communications
Contact forms, reseller inquiries, signup notes, support requests, operational emails, report delivery events, and related correspondence.
Security Telemetry
Observed attacks
Requests and interactions with TrapLayer decoys, APIs, documents, login pages, fake secrets, canary artifacts, SSH, SMTP, database, cloud, DevOps, AI-agent, and industrial-control lures.
Derived intelligence
Classification, risk score, confidence, timestamps, source IP indicators where licensed, ASN, country, coarse geography, client-family labels, protocol behavior, payload hashes, command-pattern labels, campaign clusters, MITRE/CVE context, and recommendations.
Private evidence
Operators may review raw or detailed evidence such as headers, payload snippets, user agents, session context, canary identifiers, and request metadata inside restricted administrative workflows.
Public outputs
Public dashboards and reports use sanitized aggregate data and exclude raw payload bodies, raw headers, usable credentials, session identifiers, canary token values, customer account data, and red evidence.
How We Use Information
TrapLayer uses information to operate and secure the platform, provide trials and subscriptions, authenticate users, enforce entitlements, deliver feeds and reports, process billing, respond to inquiries, monitor reliability, prevent abuse, improve detection quality, develop new features, comply with law, and protect TrapLayer, customers, partners, and the public service.
Threat intelligence
Telemetry is normalized, enriched, classified, aggregated, and summarized to generate public-safe observatory data and licensed customer intelligence.
Account operations
Account and usage data supports onboarding, customer portal access, partner portal access, billing status, audit trails, report delivery, and customer support.
Security and abuse prevention
Logs and metadata are used to detect unauthorized access, credential abuse, API-key misuse, scraping, service attacks, and policy violations.
How We Share Information
TrapLayer does not sell personal information. TrapLayer may share information with service providers, subprocessors, professional advisors, payment processors, hosting providers, email providers, security providers, analytics/support tooling, corporate transaction parties, law enforcement or regulators when legally required, and customers or partners as needed to provide contracted services.
Payment processor
Stripe processes checkout, subscription, invoice, and payment method information under its own terms and privacy practices.
Email providers
Email providers may process account setup, password reset, notification, reseller inquiry, report delivery, billing, and operational messages.
Customer reports
Reports and feeds may include security indicators, derived intelligence, and account-specific usage or entitlement context according to the customer's purchased tier.
Legal/security
Information may be disclosed when reasonably necessary to comply with law, enforce terms, investigate abuse, protect systems, or prevent harm.
Cookies and Similar Technologies
TrapLayer may use cookies, sessions, local storage, logs, and similar technologies for authentication, security, preference retention, checkout flow continuity, analytics, rate limiting, and service reliability. Browser settings may allow you to block cookies, but some portal, checkout, or authentication features may not work correctly without them.
Data Retention
TrapLayer retains information for as long as needed to operate the service, provide subscriptions and reports, maintain audit records, enforce entitlements, satisfy legal/accounting obligations, investigate security issues, and improve intelligence quality. Retention periods may differ by data type, customer tier, legal requirement, and operational configuration.
Account and billing records
Retained while the account is active and for a reasonable period afterward for audit, tax, billing, dispute, and legal purposes.
Security telemetry
Retained according to operational settings, customer agreements, and evidence-handling requirements. Aggregated or de-identified intelligence may be retained longer for trend analysis and model improvement.
API keys and passwords
API keys and passwords are stored as hashes where supported. Plaintext API keys are shown only at creation and should be stored securely by the customer.
Your Choices and Rights
Depending on your location and relationship with TrapLayer, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. Business account administrators may also control user access, API keys, notification settings, and billing contacts through the customer or partner portal where available.
TrapLayer may need to verify identity, preserve security/audit records, retain billing records, or decline a request where required or allowed by law.
International Processing
TrapLayer and its service providers may process information in the United States and other locations where infrastructure, support, billing, security, or email providers operate. By using the service, you understand information may be processed outside your jurisdiction.
Security
TrapLayer uses technical and organizational controls designed to protect account data, API keys, authentication records, billing metadata, operational telemetry, and private evidence. No system is perfectly secure. Customers remain responsible for securing their own credentials, API keys, integrations, endpoints, and downstream use of intelligence.
Children
TrapLayer is not directed to children and does not knowingly collect personal information from children. If you believe a child provided personal information to TrapLayer, contact us so it can be reviewed and removed where appropriate.
Changes to This Policy
TrapLayer may update this Privacy Policy from time to time. Material changes will be posted publicly and may require renewed acceptance for trials, purchases, or continued portal access.
For privacy, security, or data-handling questions, contact Kryptx Technologies LLC through the TrapLayer contact, customer, partner, or operator support channels configured for your account.