Privacy

ThreatScope Check privacy notice

How submitted domains, operational data, public data sources and correspondence are handled for ThreatScope Check.

In plain English:

  • You can run a ThreatScope Check without creating an account.
  • Submitted domains are used to perform the live check.
  • Checks remain stateless: ThreatScope Check does not intentionally maintain lookup history or profile submitted domains.
  • Correspondence does not: information you choose to send through Contact & feedback or email is delivered for review and may be retained as reasonably necessary to respond, investigate or administer the project.
  • Operational infrastructure may process request metadata for security, reliability and abuse prevention.
  • ThreatScope Check does not use advertising cookies, behavioural tracking cookies or third-party marketing tags.

Stewardship and operations

ThreatScope Check is owned and stewarded by Bryan Chetcuti.

The Vigo Group may provide operational services involved in delivering or administering ThreatScope Check. Operational support does not change project ownership or stewardship.

Submitted domains

Submitted domains are used to run the live check. ThreatScope Check does not create user accounts, maintain lookup history or intentionally profile submitted domains, but operational infrastructure such as Cloudflare may process request metadata for security, reliability and abuse prevention.

Correspondence

If you use the Contact & feedback form or email a ThreatScope Check contact address, the information you choose to provide is used to review the submission, respond where appropriate, investigate issues, maintain the Provider Catalogue, improve documentation or protect the service.

The intake Worker routes correspondence to ThreatScope Check-controlled email addresses and does not intentionally persist submission content in a case database, D1, KV or R2, or log submission bodies. Once delivered, correspondence may be retained in email systems for as long as reasonably necessary for review, follow-up, project administration, security or record-keeping.

Correspondence is not published automatically. Please do not include passwords, credentials, private keys, confidential system information or other sensitive material. For a security concern that may require sensitive exchange, begin with security@threatscopecheck.com.

Analytics

ThreatScope Check may use privacy-preserving operational analytics to understand service availability, usage volume, errors and abuse patterns. These are not used to create user profiles.

Cookies and tracking

ThreatScope Check does not use advertising cookies, behavioural tracking cookies or third-party marketing tags. Essential security or infrastructure cookies may be used if required to operate or protect the service.

Public and third-party data sources

When you run a check, ThreatScope Check may query public DNS, web, mail and registration data sources to produce the result. These checks are performed against public domain-layer information. The operators of those public or third-party systems may receive normal technical request information as part of responding to those checks.

See the method page for more context on public signal areas and limits.

Retention

ThreatScope Check does not intentionally maintain lookup history. Operational logs may be retained for limited periods for security, reliability and abuse prevention. Correspondence is separate from lookup activity and may be retained as described above.