
Infrared Security, LLC d/b/a Endura Security ("Endura," "Endura Security," "we," "us," or "our") respects your privacy and is committed to protecting personal information.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit www.endurasecurity.com (the "Website"), communicate with us, apply for employment, or use Endura software, managed services, and related offerings (collectively, the "Services").
Our role with respect to personal information depends on the circumstances in which we process it.
Endura acts as the data controller or business for personal information we collect for our own purposes, including:
When Endura hosts Team Server or otherwise processes Customer Data on behalf of a customer, Endura generally acts as a data processor or service provider with respect to that Customer Data, and the customer acts as the data controller or business.
We process such Customer Data to provide, secure, maintain, support, and administer the Services in accordance with the customer's instructions and our contractual obligations.
Endura may separately act as a controller for limited account, subscription, security, billing, and business-administration information necessary to operate our business and provide the Services.
When a customer operates Team Server entirely within customer-controlled infrastructure, Endura generally does not have access to the data stored in that Team Server instance.
Runtime Sensor may also operate in standalone mode without reporting runtime activity to Team Server.
Endura may nevertheless process limited information relating to a self-hosted customer when necessary for licensing, subscription administration, communications, support, or other services requested by the customer.
If a customer provides Endura with logs, diagnostics, exports, screenshots, configuration information, or access to a self-hosted environment for support purposes, we will process that information as necessary to provide the requested assistance.
Customers requiring a Data Processing Agreement ("DPA") may contact us at info@endurasecurity.com.
The information we collect depends on how you interact with Endura.
When you visit the Website or contact us, we may collect:
When your organization evaluates, purchases, or uses Endura, we may collect:
Depending on deployment and authentication configuration, Team Server may process:
Runtime Sensor observes security-relevant activity on protected Linux systems and workloads.
Depending on configuration, operating mode, security policy, and the activity being evaluated, information processed by Runtime Sensor may include:
In standalone deployments, this information may remain within customer-controlled infrastructure.
When Runtime Sensor is connected to Team Server, applicable runtime information is transmitted to the configured Team Server so that Team Server can associate activity with builds or workloads, manage policies, record violations, and provide centralized visibility.
When a customer configures CI/CD integrations, Team Server may retrieve or receive information necessary to discover and protect pipelines, such as:
The specific information available depends on the CI/CD provider and the permissions granted by the customer.
Team Server may process:
When a customer configures an integration, the Services may process information required to communicate with that third-party system.
Depending on the integration, this may include:
Integration credentials are used to provide the functionality configured by the customer.
When notification integrations are configured, Team Server may transmit information about policy violations to the third-party destination selected by the customer.
Notification content may include information such as:
Customers are responsible for determining which notification destinations and recipients are appropriate for their organization.
If you request technical support, we may collect information you provide to diagnose or resolve the issue, including:
You should review support materials before providing them to Endura and avoid including information not necessary to resolve the issue.
If you apply for employment with Endura, we may collect:
We may collect personal information:
We use personal information and Customer Data as appropriate to:
Where applicable data-protection law requires a legal basis for processing, we rely on one or more of the following:
We process information when necessary to enter into or perform a contract, including providing the Services and administering customer relationships.
We may process information when necessary for legitimate business interests, including:
We consider the potential impact on individuals before relying on legitimate interests.
We rely on consent where required, including for certain marketing communications, optional cookies, or other processing for which applicable law requires consent.
You may withdraw consent at any time where processing is based on consent.
We may process information when necessary to comply with applicable laws, regulations, court orders, or other legal obligations.
When Endura processes Customer Data as a processor or service provider, the customer determines why and how that information is processed.
If your personal information appears in Customer Data because you are an employee, contractor, developer, or other user of an Endura customer, you should generally direct privacy requests relating to that information to the organization that controls the applicable Endura deployment.
Where required, Endura will assist customers in responding to valid data-subject requests in accordance with our contractual obligations and applicable law.
We do not sell personal information.
We may disclose information in the following circumstances.
We may use service providers to support functions such as:
These providers may process personal information only as necessary to provide services to Endura and are subject to appropriate contractual obligations.
Information associated with a Team Server user may be visible to authorized administrators and other users of that customer's organization according to Team Server roles, access scope, and policy permissions.
At a customer's direction, Endura may transmit information to CI/CD providers, notification platforms, identity providers, or other integrated services.
Information transmitted to those services is then subject to the applicable third party's terms and privacy practices.
We may disclose information where we reasonably believe disclosure is necessary to:
Information may be transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction.
We may disclose information when you or your organization directs us to do so or where you otherwise consent.
Endura does not sell personal information for monetary or other valuable consideration.
Endura does not currently share personal information for cross-context behavioral advertising or use personal information for targeted advertising across unrelated websites or services.
If our practices change, we will update this Privacy Policy and provide any opt-out mechanisms required by applicable law.
The Website may use strictly necessary cookies and similar technologies for purposes such as:
Based on our current Website configuration, Endura does not use advertising or cross-site behavioral tracking cookies.
If we introduce optional analytics, advertising, or similar technologies, we will update our cookie disclosures and obtain consent where required by law.
Additional information may be provided in our Cookie Policy.
Team Server may also use cookies or similar technologies necessary for authentication and session management.
We may send information about Endura products, research, events, or other business-related topics where permitted by applicable law.
Where consent is required, we will obtain consent before sending such communications.
You may unsubscribe from marketing communications at any time using the unsubscribe instructions in the communication or by contacting us.
We may continue to send non-marketing communications relating to an existing business relationship, such as security, legal, billing, subscription, or service notices.
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to contractual requirements, customer configuration, legal requirements, and legitimate business needs.
Website inquiries, sales communications, and business records are retained for as long as necessary to manage the relationship, respond to inquiries, comply with legal obligations, and maintain appropriate business records.
Customer Data stored in an Endura-managed Team Server is retained according to:
Following termination, applicable Customer Data is deleted or returned according to the governing agreement and applicable retention requirements.
For self-hosted Team Server and standalone Runtime Sensor deployments, the customer controls the retention and deletion of data within its environment.
Support records and diagnostic information may be retained for as long as necessary to provide support, maintain service history, investigate recurring issues, and satisfy legal or contractual obligations.
Account, billing, license, transaction, and contractual information may be retained for the term of the customer relationship and thereafter as necessary for accounting, tax, legal, security, and audit purposes.
Job-application information is retained for the duration of the recruiting process and for a reasonable period afterward for legal, administrative, and future recruiting purposes, subject to applicable law.
Where required, we will obtain consent before retaining applicant information for unrelated future opportunities.
Endura uses administrative, technical, and organizational safeguards designed to protect personal information appropriate to the nature of the information and the Services.
Depending on the applicable Service, safeguards may include:
No security measure, software product, or network can guarantee absolute security.
For managed Services, Endura is responsible for the security of infrastructure and systems under Endura's control, subject to the applicable agreement.
Customers remain responsible for Customer-controlled systems, users, identity providers, credentials, security-policy configuration, and endpoints.
Customers operating self-hosted Team Server or Runtime Sensor deployments are responsible for the security of their infrastructure, including:
If Endura becomes aware of a security incident involving personal information for which Endura acts as controller, we will investigate and provide notifications as required by applicable law.
Where Endura acts as a processor or service provider and becomes aware of a security incident affecting Customer Data, we will notify the affected customer in accordance with applicable law, the applicable DPA, and the governing Service Agreement.
The customer remains responsible for determining whether notification to individuals, regulators, or other parties is legally required unless otherwise specified by law or contract.
Endura does not generally monitor customer-controlled self-hosted infrastructure for breaches.
Customers operating self-hosted environments are responsible for detecting, investigating, responding to, and providing legally required notification regarding incidents within their infrastructure.
If Endura identifies a security vulnerability in Endura software that may affect customers, Endura may communicate appropriate security or remediation information to affected customers.
Endura is based in the United States.
Personal information may be processed in the United States or other jurisdictions where Endura or its service providers operate.
Where applicable law requires safeguards for international transfers of personal information, we may rely on mechanisms such as:
For self-hosted deployments, customers determine the geographic location of their own infrastructure and are responsible for complying with applicable international-transfer requirements.
If a self-hosted customer provides information to Endura for support or other services, that information may be transferred to the United States.
If applicable privacy law provides you with data-protection rights, those rights may include:
To exercise these rights, contact info@endurasecurity.com.
Where GDPR or UK GDPR applies, we generally respond to valid requests within one month, subject to extensions permitted by law.
We may request information necessary to verify your identity and authority to make the request.
If Endura processes your information solely on behalf of a customer, we may direct your request to that customer or assist the customer in responding.
Residents of California, Colorado, Connecticut, Delaware, Virginia, and other U.S. states may have privacy rights under applicable state law.
Depending on your jurisdiction and whether the applicable law applies to Endura, these rights may include:
Endura does not sell personal information or currently use personal information for cross-context behavioral advertising.
To submit a privacy request, contact info@endurasecurity.com with the subject line "Privacy Request."
We may need to verify your identity before fulfilling a request.
Where permitted by law, an authorized agent may submit a request on your behalf, subject to verification of the agent's authority.
If applicable law provides a right to appeal our response, you may submit an appeal using the same contact information and identifying the request being appealed.
We will not discriminate against you for exercising applicable privacy rights.
Where required by applicable law, Endura will recognize legally valid browser-based opt-out preference signals, such as Global Privacy Control, for processing to which such signals apply.
Because Endura does not currently sell personal information or use it for cross-context behavioral advertising, such signals generally do not change our current Website processing.
There is no universally accepted standard for responding to general browser "Do Not Track" signals.
The Website and Services are intended for businesses and professional users and are not directed to children under 18.
We do not knowingly collect personal information from children under 18.
If we learn that we have collected personal information from a child in circumstances where such collection is not permitted, we will take reasonable steps to delete it.
Endura uses automated policy evaluation to determine whether security-relevant system operations comply with customer-defined security policies.
In enforce mode, these automated security decisions may block system operations or terminate offending processes.
These decisions concern the operation and security of computer systems and workloads. Endura does not use this functionality to make decisions about individuals relating to employment, credit, housing, insurance, education, or other legal or similarly significant personal matters.
We may update this Privacy Policy from time to time to reflect:
When we update the Policy, we will revise the Last Updated date.
If a change materially affects how we use personal information, we may provide additional notice as appropriate or required by law.
We encourage you to review this Policy periodically.
Questions, privacy requests, or concerns regarding this Privacy Policy may be directed to:
Infrared Security, LLC
d/b/a Endura Security
18376 Southampton Drive
Lewes, DE 19958
United States
Email: info@endurasecurity.com
For privacy-rights requests, please use the subject line:
Privacy Request
This Privacy Policy should be read together with our:
A Data Processing Agreement is available to eligible customers upon request.
This Privacy Policy describes Endura's privacy practices but does not alter the terms of any mutually executed Service Agreement or Data Processing Agreement. If a conflict exists with an applicable DPA regarding the processing of Customer Data, the DPA controls for that processing.
