Privacy policy
What this site collects, what it does not, and what happens to anything you send us.
We are a security company, so we have written this the way we would want it written for us: short, specific, and describing only what actually happens. Everything on this page can be checked from outside — see Audit us.
Last updated 29 August 2026.
Reading this site collects nothing
This website is a set of static files. It sets no cookies, runs no analytics, and loads nothing from any third party — no fonts from Google, no embedded videos, no advertising or tracking pixels, no social buttons. There is no login and no database behind it.
That is not a preference, it is enforced: the site sends a content security policy that forbids scripts entirely, and an automated check refuses to publish the site if a third-party request ever appears on any page.
Our hosting provider keeps standard request logs — the kind every web server keeps, including an IP address and the page requested — for a short period, to deliver the site and to block attacks. We do not use those logs to build a profile of you, and we do not combine them with anything else.
What we collect when you write to us
Only what you type into the form, and nothing gathered quietly alongside it:
- Your name and work email address — required, so we can reply.
- Your firm’s website and what kind of firm it is — optional, so the reply is useful rather than generic.
- Your message — optional, and whatever you choose to put in it.
The form also contains one hidden field that is never sent anywhere. It exists to catch automated spam, which fills in every field it finds; a person never sees it and never fills it in. We mention it because “hidden field” sounds worse than it is.
Please do not send us confidential client information through this form. If you need to tell us something sensitive, say so and we will arrange a proper channel.
What we do with it
We use what you send us for three things, and nothing else:
- To reply to you.
- To prepare the free Security Snapshot, if that is what you asked for.
- To keep a record of the conversation, so that if we speak again we know what was already said.
Your enquiry arrives in our company email and is also recorded in our own client-management system, which we run ourselves rather than renting from a customer-data platform. We do not sell your information, rent it, trade it, or hand it to advertisers or data brokers. We do not add you to a marketing list because you asked us a question — if we ever want to send you something you did not ask for, we will ask first.
If you ask for a Security Snapshot
The Snapshot looks at your firm the way an outsider can: we read what your domain publishes publicly — the same kind of lookup any mail server or browser performs — and what your own website already shows to visitors. We do not log in to anything, test any password, or send anything to your systems. We only look at what is already public, and only after you have asked us to.
The findings are yours. We keep a copy so we can answer questions about it later, and we do not publish it or show it to anyone else.
Who else can see it
A small number of suppliers necessarily handle your message in transit: the company that hosts and delivers this website, and the company that provides our email. They act on our instructions and may not use your information for their own purposes. Nobody else receives it.
Some of these suppliers operate internationally, so your information may be processed outside Canada and, while it is there, may be accessible to the courts and authorities of that country under its laws. We would rather say that plainly than bury it.
We would disclose your information without asking you only if the law required it — a court order, for example. If that ever happened and we were permitted to tell you, we would.
How long we keep it
If you become a client, for as long as you are one and then as long as our professional and legal obligations require. If you do not, we keep your enquiry for 24 months and then delete it, so that a conversation you have forgotten about does not sit in our systems indefinitely.
You can ask us to delete it sooner, and we will.
How it is protected
The same controls we would put in place for a client: access limited to the people who need it, multi-factor authentication on the accounts that hold it, encryption in transit, and a key held by the website that can deliver mail to one address and do nothing else, so a compromise of the website cannot be used to send mail as us.
No one can promise a breach will never happen. If one did, and it created a real risk of significant harm to you, we would report it to the Privacy Commissioner of Canada and tell you — that is the law, and we have written elsewhere on this site about firms that did not.
Your rights
Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct anything that is wrong;
- delete it;
- explain what we have used it for and who has seen it.
Email contact@cyberlegionnaire.com and we will respond within 30 days. We will not charge you, and we will not ask why.
Questions, and complaining about us
Kubera Desai is accountable for privacy at Cyber Legionnaire. Write to contact@cyberlegionnaire.com with anything at all — a question, a correction, or a complaint.
If we do not resolve it to your satisfaction, you can complain to the Office of the Privacy Commissioner of Canada, who supervises us under PIPEDA: priv.gc.ca. You do not need our permission, and you do not have to come to us first.
Changes to this policy
If what we do changes, this page changes with it, and the date at the top changes too. We will not quietly broaden it: if we ever start collecting something new, it will say so here before it starts.