Privacy
OffPerimeter is in private beta and is reached over a private network, not as a public SaaS. This page is an operator notice, not a substitute for a negotiated DPA.
What we process
Account identifiers (name, corporate email, role), organization membership, session cookies, and security telemetry produced for the tenant (attack-surface findings, correlated leak/stealer hits, threat-intel context). Secrets in leak records stay masked in lists. An authorized user may spend one organization credit to reveal a single secret; OffPerimeter grants and refills those credits.
Who can see it
Tenant data is isolated by organization. OffPerimeter operators may access a tenant to operate the platform (scans, support, incident response) under the engagement. We do not sell customer data.
Contact
Privacy or DPA requests: security@offperimeter.com