FerrumSec ID FerrumSec ID
Legal · Privacy Policy

FerrumSec Privacy Policy

FerrumSec ID is the account, single sign-on, and billing hub at the heart of the Ferrum suite — and this is the one privacy policy that covers all of it. It explains what personal data Funway Interactive SRL (through its FerrumSec division) collects across FerrumSec ID, Ferrum ResponseLab, and Ferrum Sentinel, why we process it and on what legal basis, who helps us run the service, and the rights you have over your data. We use only essential cookies — no tracking, no advertising, and we never sell your data.

Effective · Beta — June 2026 Controller · Funway Interactive SRL Applies to · the Ferrum suite

§01Who we are (data controller)

FerrumSec is a division of Funway Interactive SRL, a company registered in the Republic of Moldova. Funway Interactive SRL, acting through its FerrumSec division, is the data controller for the personal data described in this policy.

This is the single, canonical privacy policy for the whole Ferrum suite. It lives on FerrumSec ID (id.ferrumsec.com) — the account, single sign-on, organization, role, licensing, and billing layer that every product links up to — and it governs all three products operated by us:

For privacy questions or to exercise your rights, contact us at privacy@ferrumsec.com.

§02What personal data we collect

We collect only what we need to run the suite and keep it secure. Across the products this falls into three groups.

Account data

Your email address and display name, the organizations you belong to and your role in each, and how you sign in. If you use a password it is stored only as a salted, one-way hash; if you sign in with single sign-on or Google, we link your account to a stable identifier rather than storing a password.

Billing data

Where you buy a paid plan, your plan and entitlements and the billing and invoice records — including any EU VAT details — needed to manage your subscription. Card and payment details are handled by our payment processor; we do not store full card numbers.

Usage, technical & security data

The content you create in each product (see what each product processes below), audit events for security-sensitive actions such as sign-in, invitations, and report generation, and minimal operational logs needed to run and protect the service. Request logs deliberately exclude sensitive query parameters such as reset tokens.

§03What each product processes

Each product in the suite processes a different kind of working content. Identity and billing are always handled centrally by FerrumSec ID.

FerrumSec ID (the hub)

Your identity, organizations, and billing: account profile, organization membership and roles, single sign-on sessions, licensing and entitlements, and subscription and invoice records.

Ferrum ResponseLab

The exercise content your team authors during tabletop drills — scenarios, injects, decisions, observations, readiness scores, action items, and after-action reports. These exercises are fictional by design: you are asked to keep organizations and artifacts fictional and not to enter real confidential or incident data into scenarios.

Ferrum Sentinel

The domains you add and their ownership-verification records, plus external-posture scan evidence stored as structured metadata only — findings, scores, and technical evidence such as DNS records, response headers, and certificate metadata. Sentinel never stores secrets or sensitive response bodies, and its checks are safe, passive, public look-ups (for example DNS, certificate-transparency logs, mail blocklists, and cloud providers' public storage endpoints).

§04Why we use your data and legal bases

We use personal data to:

  • provide the products — run exercises and scans, score results, and generate reports;
  • authenticate you and enforce roles and organization isolation across the suite;
  • manage billing, licensing, entitlements, and invoicing for paid plans;
  • send transactional email such as verification, password reset, invitations, and report-ready notices — not marketing;
  • keep the service secure, debug problems, prevent abuse, and meet legal obligations.

We process this data under the data-protection law of the Republic of Moldova (Law No. 133/2011) and, where we offer services to or process data about people in the EU, the EU GDPR. Our legal bases are:

  • Performance of a contract — to provide the service you or your organization sign up for;
  • Legitimate interests — to secure the service, prevent abuse, and improve the product;
  • Legal obligation — to keep the billing, tax, and security records the law requires;
  • Consent — for any optional communications, which you can withdraw at any time.

We do not sell your personal data, and we do not use your content for advertising.

§05Cookies

We use only strictly necessary cookies — the ones that keep you signed in. With single sign-on, a shared session cookie may be set on the .ferrumsec.com domain so one login works across the suite; each product also sets its own secure, HttpOnly session cookie (and a CSRF token).

We set no advertising, analytics, or third-party tracking cookies. Your response to any cookie notice is stored locally in your browser, not in a cookie.

§06Subprocessors and sharing

We share personal data only with the service providers (subprocessors) that help us run the suite, under appropriate confidentiality and data-protection terms. They act only on our instructions:

  • Paddle — payments and our merchant of record, handling checkout, card processing, invoicing, and EU VAT;
  • Brevo — delivery of transactional email such as verification, invitations, and notifications;
  • DigitalOcean — cloud hosting that runs the products and stores their databases.

To do its job, Ferrum Sentinel also queries public data sources about the domains you scan — such as DNS, certificate-transparency logs, mail blocklists, and cloud providers' public storage endpoints. These are ordinary public look-ups, not transfers of your account data.

We may also disclose data where required by law or to protect the rights, safety, and security of our users and the service. We do not sell personal data to anyone.

§07International transfers

We are based in the Republic of Moldova, and our subprocessors may process data in Moldova, the European Union, the United States, or elsewhere. Where personal data is transferred across borders, we rely on appropriate safeguards — such as the European Commission's standard contractual clauses — so your data keeps an equivalent level of protection wherever it is handled.

§08Data retention

We keep account and organization data for as long as your account is active and as needed to provide the service. Product content — such as after-action reports in ResponseLab or scan reports in Sentinel — is retained according to your plan's settings, and you can delete domains, reports, and content yourself.

When an account or organization is closed, we delete or anonymize the associated personal data within a reasonable period, except where we must keep limited records to meet legal, security, tax, or billing obligations.

§09Your rights

Subject to applicable law, you have the right to:

  • Access — get a copy of the personal data we hold about you;
  • Rectification — correct data that is inaccurate or incomplete;
  • Erasure — ask us to delete your personal data;
  • Portability — receive your data in a portable, machine-readable format;
  • Objection and restriction — object to or restrict certain processing, and withdraw consent you have given.

During beta, the quickest route for organization content is your workspace administrator, who can manage members and content. For account-level requests, contact privacy@ferrumsec.com and we will respond within a reasonable time. You also have the right to complain to a supervisory authority — in Moldova, the National Center for Personal Data Protection of the Republic of Moldova, or, in the EU, your local data-protection authority.

§10How we keep your data secure

  • Organization isolation. Your data is scoped to your organization and enforced both in the application and at the database with row-level security.
  • Credentials. Passwords are stored only as salted, one-way hashes — never in plain text.
  • In transit. Traffic is served over HTTPS/TLS, with least-privilege access internally.
  • Minimized evidence. Sentinel stores scan results as structured metadata rather than raw sensitive bodies or secrets.
  • Accountability. Security-sensitive actions are recorded as audit events so your workspace stays accountable.

§11Children

The Ferrum suite is a workplace security tool intended for organizations and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact privacy@ferrumsec.com and we will delete it.

§12Changes to this policy

We may update this policy as the suite evolves. When we make material changes we will update the effective date above and, where appropriate, notify organization administrators. Because this is the canonical policy for the whole suite, an update here applies across FerrumSec ID, Ferrum ResponseLab, and Ferrum Sentinel.

§13Contact

For privacy questions or to exercise your rights, contact us at privacy@ferrumsec.com. For general or legal enquiries, use hello@ferrumsec.com. You can also reach your workspace administrator for organization-level requests.

Data controller: Funway Interactive SRL, operating the Ferrum suite through its FerrumSec division, Republic of Moldova.

Beta template — not legal advice. This is a plain-language privacy policy for our beta, written to be readable and to reflect how the Ferrum suite works today. It is a template, not legal advice. Please have qualified counsel review it before you rely on it for your organization.