Account-free by design

Privacy

CASCA is a public, account-free vulnerability-intelligence service. It does not offer user accounts, accept customer asset or scanner data, process payments, send outbound application email, or sell personal information.

Effective date: August 5, 2026

Information handled

To deliver, secure, and operate the service, CASCA may process limited technical information such as IP address, request time, requested path, response status, and security or reliability events. The product analytics log stores only a masked network prefix, a path with its query removed, response status, and a referrer hostname with its path removed. It does not store request headers, user agents, cookies, raw addresses, or pasted triage text. This analytics log is retained for no more than eight days. Separate security incident records may be retained for up to 30 days when needed and documented.

CASCA uses those short-lived host logs only to produce privacy-preserving aggregate service measurements: page, returning-network, and dossier-referrer counts. A network is not a person, so returning-network counts are directional rather than user identities. CASCA does not create tracking profiles or use third-party advertising trackers or cross-site behavioral advertising.

Search and browser state

Search terms and URL state are processed to return a result. Account-free preferences or saved investigation state may be stored locally in your browser and can be removed through browser controls.

The Check your list tool extracts CVE IDs and joins public index files entirely in your browser. Pasted text and extracted IDs are not sent to CASCA or stored by it. If you separately request design-partner access, CASCA stores only the normalized email address and request timestamp in private first-party storage for up to 180 days. That address may be used for manual design-partner follow-up and can be deleted on request.

Public vulnerability data

CASCA ingests and analyzes public cybersecurity records from the providers identified on its Sources and Methodology pages. Those records concern vulnerabilities, software, vendors, advisories, and related public security evidence; they are not customer exposure records.

Sharing and security

Technical information may be processed by infrastructure providers as necessary to host and protect the service or disclosed when legally required. CASCA does not sell it. Reasonable technical controls are used to limit access, protect logs, and keep internal data services private, but no Internet service can promise absolute security.

Policy changes and contact

Material changes will be published on this page with a revised effective date. Accounts, customer data, billing, email alerts, or materially different analytics require a policy review before activation.

For privacy questions, corrections, or security reports, contact admin@lanzalabs.io.