Legal

Privacy Policy

How ExeQuantum collects, uses and protects your personal information.

ExeQuantum Pty Ltd (ABN 86 680 683 738)
Level 1, 23-27 Wellington Street, St Kilda, VIC 3182, Australia
Last updated: 20 July 2026

1. About this policy

This Privacy Policy explains how ExeQuantum Pty Ltd ("ExeQuantum", "we", "us", "our") collects, uses, discloses and protects personal information. We are committed to complying with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the General Data Protection Regulation (GDPR) where applicable to EU and UK data subjects.

2. Information we collect

We collect personal information in two contexts:

Website visitors

When you visit exequantum.com, request a demonstration or contact us, we may collect your name, email address, phone number, organisation name, job title and any information you provide in enquiry forms.

Platform users

When your organisation uses our platform (CipherScout, CipherWatch, CipherForge or EQCore), we collect account credentials and user profile information necessary to provide the service. Authentication is managed by our identity provider, Clerk (SOC 2 Type II certified).

Cryptographic scan data: production engagements

For production engagements, ExeQuantum operates a Bring Your Own Database (BYOD) architecture. All scan results, cryptographic asset inventories and reports generated by our platform are stored in a database provisioned and controlled by the client. ExeQuantum does not retain, hold or have persistent access to client scan data under this model.

Cryptographic scan data: complimentary evaluation

ExeQuantum offers a complimentary two-week evaluation programme, provided through a guided onboarding process. During the evaluation period, scanning is limited to publicly accessible assets only, and scan data is hosted within ExeQuantum's managed environment rather than a client-provisioned database. ExeQuantum personnel may access this data to support the evaluation and demonstrate platform capabilities. Upon conclusion of the evaluation, all scan data generated during the programme is securely deleted. Organisations that proceed to a production engagement transition to the BYOD architecture described above.

3. How we use your information

We use personal information to:

  • Provide, maintain and improve our products and services
  • Respond to enquiries and provide customer support
  • Manage user accounts and authentication
  • Send service-related communications (e.g. security notifications, platform updates)
  • Comply with legal and regulatory obligations
  • Protect the security and integrity of our platform

We do not use personal information for automated decision-making or profiling.

4. Legal basis for processing (GDPR)

Where the GDPR applies, we process personal information on the following bases:

  • Contractual necessity: to deliver the services you or your organisation have engaged us to provide
  • Legitimate interests: to operate, improve and secure our platform, and to respond to enquiries
  • Legal obligation: to comply with applicable laws and regulations
  • Consent: where you have given explicit consent, such as opting in to marketing communications

5. Disclosure of information

We do not sell personal information to third parties.

We may share personal information with the following categories of recipients, solely for the purposes described in this policy:

  • Service providers. We use third-party service providers to support our operations, including Clerk (authentication), DigitalOcean (infrastructure hosting) and payment processors. These providers are contractually required to protect personal information and use it only for the purposes for which it was disclosed.
  • Professional advisors. We may disclose information to legal, accounting or insurance advisors as necessary.
  • Legal and regulatory authorities. We may disclose information where required by law, regulation, court order or governmental request.

6. Data security

We maintain an Information Security Management System (ISMS) certified to ISO/IEC 27001:2022. Our security measures include:

  • Encryption of all data in transit using TLS 1.3
  • Encryption of all data at rest
  • Role-based access control with least-privilege principles
  • Multi-factor authentication for all administrative access
  • Regular vulnerability scanning and penetration testing by CREST-accredited firms
  • Automated security tooling integrated into our development pipeline, including secret detection, dependency vulnerability scanning and container scanning

For on-premises deployments, infrastructure security is managed within the client's own controlled environment.

7. International data transfers

ExeQuantum is headquartered in Australia. Where we transfer personal information outside of Australia, or outside of the European Economic Area (EEA) where GDPR applies, we ensure that appropriate safeguards are in place in accordance with applicable data protection laws. Our infrastructure hosting provider maintains data centres in multiple regions, and deployment location can be configured to meet jurisdictional requirements.

Under our BYOD architecture, clients control the location and jurisdiction of their own database, ensuring scan data remains within the client's chosen geography.

8. Data retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:

  • Website enquiry data is retained for the duration of the business relationship and a reasonable period thereafter.
  • Platform account data is retained for the duration of the service agreement. Upon termination, residual client configuration data is securely deleted and confirmation provided.
  • Cryptographic scan data (production) is not retained by ExeQuantum. Under BYOD architecture, all scan data resides in the client's own database and is subject to the client's own retention policies.
  • Cryptographic scan data (evaluation) generated during the complimentary two-week evaluation programme is hosted within ExeQuantum's managed environment and securely deleted upon conclusion of the evaluation.
  • Application logs containing metadata are purged per defined retention schedules.

9. Your rights

Australian residents

Under the Australian Privacy Act 1988, you have the right to access and request correction of your personal information. You may also make a complaint if you believe we have breached the APPs.

EU and UK residents

Under the GDPR, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Object to or restrict processing of your information
  • Request data portability
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, please contact us using the details below.

10. Cookies

Our website uses cookies and similar technologies to improve your browsing experience and analyse website usage. You can manage your cookie preferences through your browser settings. Essential cookies required for website functionality cannot be disabled.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal requirements. The "Last updated" date at the top of this page indicates when the policy was most recently revised. We encourage you to review this page periodically.

12. Contact us

If you have questions, concerns or complaints about this Privacy Policy or our handling of your personal information, please contact us:

Email: team@exequantum.com
Address: Level 1, 23-27 Wellington Street, St Kilda, VIC 3182, Australia

If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Questions about how we handle your data?

We are happy to walk through our data handling practices, BYOD architecture or any other aspect of this policy.