Skip to content
RequestGuard RequestGuard
Pricing

Privacy Policy

Last updated: August 2026

1. What We Process

RequestGuard processes security signals that customers send to the API, such as IP address, email domain, domain name, user agent, event type, metadata, decision result, and request logs.

2. Why We Process It

We use this data to score abuse risk, return allow/challenge/review/block decisions, apply customer rules, deliver webhooks, show dashboard analytics, operate the service, and investigate reliability or security issues.

3. Retention

Launch access stores recent assessment logs for investigation and analytics. Customers can export event data from the dashboard. Longer retention controls will be tied to paid plans.

4. Security

API access is protected by API keys. We keep customer configuration, rules, webhooks, and logs separated by workspace key. Customers should avoid sending unnecessary personal data in metadata fields.

5. Email Fraud Check

Emails forwarded to scan@requestguard.com are processed to analyze sender, link, message, fraud, phishing, and malware signals. Unknown attachments may be submitted to VirusTotal and shared with its security partners and customers. Do not forward confidential or sensitive attachments that you are not permitted to share with VirusTotal. Forwarding an email to this address opts into that processing.

6. Public Website Scans

Website scan submissions publish the normalized apex, dated result, endpoint IPs, and available server-location evidence. RequestGuard uses a one-way IP hash for short-lived anonymous rate-limit counters and does not attach the submitter's raw IP address to the report. Results and their latest check date remain available unless suppressed for abuse or legal handling. Loading a hosted badge sends a normal image request to RequestGuard; downloading and self-hosting the dated badge avoids that request for later visitors.

7. Contact

Privacy questions can be sent to privacy@requestguard.com.