Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      AI-powered autonomous agents eliminate manual testing by conducting comprehensive security assessments automatically.

    • MITRE ATT&CK Coverage

      Full coverage of MITRE ATT&CK framework tactics and techniques to simulate real-world attack scenarios.

    • OWASP Top 10 Coverage

      Complete testing coverage for all OWASP Top 10 vulnerabilities including injection attacks, broken authentication, and security misconfigurations.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Pricing
    • Faq
    • Integration
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign In
  • french
  • spanish
  • portuguese
Sign In
  1. Home
  2. /
  3. Legal
  4. /
  5. Privacy Policy

Privacy Policy

How Nubesti collects, uses, and protects personal information when you use our website, portal, and security-testing services.

Last updated: September 21, 2026

Nubesti

1111B S Governors Ave STE 23840
Dover, DE 19904, USA

[email protected]

On this page

  1. 1. Who is responsible
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. Legal bases (GDPR)
  5. 5. How we share information
  6. 6. International transfers
  7. 7. Retention
  8. 8. Your rights
  9. 9. Cookies
  10. 10. Security
  11. 11. Children
  12. 12. Changes
  13. 13. Contact

This Privacy Policy explains how Nubesti LLC (“Nubesti,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you visit nubesti.com, use app.nubesti.com, or receive our AI-powered cybersecurity services.

We designed this policy to meet expectations under Delaware and US law, the EU General Data Protection Regulation (GDPR), and Colombian data-protection rules.

1. Who is responsible

Nubesti LLC is the controller of personal data collected through our marketing website, accounts, billing, and support.

When we process personal data contained in your testing targets, reports, or platform workspace on your instructions, we act as a processor. Those activities are covered by our Data Processing Addendum.

Contact: [email protected] · [email protected]
Nubesti LLC, 1111B S Governors Ave STE 23840, Dover, DE 19904, USA

2. Information we collect

We may collect:

  • Identity and contact data: name, role, company, email, phone, billing address
  • KYC and verification data: government ID, company formation documents, beneficial-ownership or control information, proof of authority to test, and screening results
  • Account data: login identifiers, preferences, teammates you invite
  • Transaction data: plan, invoices, KYC fees, payment status (card details are handled by the payment processor)
  • Technical data: IP address, browser, device, approximate location, logs
  • Usage data: pages viewed, features used, diagnostic events
  • Security-testing data: in-scope assets, findings, evidence, and reports you generate or upload
  • Communications: demo requests, support tickets, emails, and call notes

We collect data from you directly, automatically from the site and platform, and from service providers such as hosting, analytics, payments, and support tools.

3. How we use information

We use personal data to:

  • Provide, secure, and improve the website and platform
  • Create and administer accounts
  • Complete mandatory KYC and sanctions screening
  • Run authorized security tests and deliver reports
  • Process payments, KYC fees, trials, renewals, and tax invoices
  • Respond to demos, sales, and support requests
  • Detect abuse, fraud, and unauthorized testing
  • Comply with law and enforce our agreements
  • Send product or marketing messages where permitted (you can opt out)

4. Legal bases (GDPR)

Where GDPR applies, we rely on:

  • Contract: to provide the services you request
  • Legitimate interests: to secure the platform, improve the product, and prevent abuse, balanced against your rights
  • Legal obligation: tax, accounting, and lawful requests
  • Consent: non-essential cookies and optional marketing, where required

5. How we share information

We do not sell personal information. We share data with:

  • Subprocessors that help us host, bill, support, and operate the service (list)
  • Your teammates and integrations you enable
  • Professional advisors under confidentiality
  • Authorities when required by valid legal process or to prevent serious harm

We may disclose information to defend our rights, investigate abuse, or complete a merger or asset sale, with appropriate notice where required.

6. International transfers

We are established in the United States. If you access the services from the EU, UK, Colombia, or elsewhere, your data may be processed in the United States and other countries where our subprocessors operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses.

7. Retention

We keep personal data only as long as needed for the purposes above:

  • Account and billing records: typically the life of the account plus up to 7 years for tax and legal records
  • Support communications: typically 24 months after closure
  • Security findings and workspace data: for the subscription term and a short post-termination window, unless you request earlier deletion and law allows it
  • Marketing contacts: until you unsubscribe or the relationship ends

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your data, to object to certain processing, and to withdraw consent.

California residents may have CCPA/CPRA rights, including to know, delete, and correct personal information and to opt out of sharing for cross-context behavioral advertising. We do not sell personal information.

To exercise rights, email [email protected] with:

  • Your name, company, and the email on the account
  • The right you want to exercise (access, correction, deletion, portability, restriction, objection, or CCPA “do not sell/share”)
  • Enough detail for us to find your records

We may need to verify your identity—including against KYC records—before we act. We aim to respond within 30 days, or sooner if local law requires it. You may also lodge a complaint with your supervisory authority, including an EU DPA, Colombia’s SIC, or the US FTC / Delaware Attorney General.

9. Cookies

See our Cookie Policy for details on cookies, similar technologies, and how to manage them.

10. Security

We use encryption in transit, access controls, logging, and other measures described in our Security Overview. No method of transmission or storage is perfectly secure.

11. Children

The services are not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe we have, contact [email protected] and we will delete it.

12. Changes

We may update this policy by posting a new version with a revised date. Material changes will be highlighted here or notified by email when practical.

13. Contact

Nubesti LLC
1111B S Governors Ave STE 23840, Dover, DE 19904, USA
[email protected] · [email protected] · [email protected]

Back to legal center ↗

Brand logo of nubesti

Nubesti is a cutting-edge cybersecurity platform that leverages artificial intelligence to deliver comprehensive red team operations. Our mission is to revolutionize enterprise security through autonomous AI-powered testing and advanced threat simulation.

  • facebook
  • twitter
  • instagram
  • linkedin

Quick Links

  • Pricing
  • Integration
  • AI Red Team
  • Faq

Resources

  • Blog
  • Integration

Legal

  • Legal center
  • Terms of Service
  • Privacy Policy
  • Security
  • KYC & Verification
  • Legal Notice

Subscribe to our newsletter

gats-upstart
  • Legal
  • Privacy Policy
  • Legal Notice
  • Copyright 2026
  • All Rights Reserved By Nubesti