Who is responsible

Walden Cybersecurity Solutions ("WCS") is the name under which I, David Walden, provide cybersecurity consulting. WCS is a sole practitioner consultancy and not a separate registered entity, so I am personally the party responsible for the information described here. Throughout this policy, "I" and "me" mean David Walden doing business as Walden Cybersecurity Solutions.

This policy applies to waldencybersecurity.com and the tools offered on it, including the contact form and the free security checkup. If you later engage me under a signed agreement, the data handling terms of that agreement govern the work performed under it.

Information I collect

Information you provide

Contact form. When you submit an inquiry I collect your name, email address, and message, plus the organization name, phone number, and service interest you optionally provide.

Security checkup. When you start a checkup I collect your business name, website address, industry, employee count, your name, and your business email address. As you work through the assessment I store your answers, the scores calculated from them, the report generated for you, and the date and version of the privacy notice you accepted.

Documents you upload. The checkup optionally accepts policy and procedure documents (PDF, Word, text, or Markdown). The text is extracted from each file for analysis, and that extracted text is stored with your checkup record, truncated to a set length. The uploaded file itself is not stored — only the text taken from it. Please do not upload documents containing personal data, customer records, credentials, or system details you do not want retained; written policies and program documents are what the checkup is built to read.

Information collected automatically

Request and security logs. The server records standard web log information, including IP address, browser user agent, requested page, and timestamp. Your IP address is also recorded with contact form submissions and used to enforce the submission rate limits that keep the forms usable.

Checkup usage analytics. The site records internal events describing how the checkup is used — that a landing page was viewed, a questionnaire was completed, or a report was generated. These records store a cryptographic hash of the IP address rather than the address itself.

Security telemetry. Browser-reported Content Security Policy violations are collected, and requests matching suspicious patterns are logged. These records may include an IP address and user agent, and exist only to detect and investigate attacks against this site.

How I use information

The information above is used to:

  • Respond to inquiries and consultation requests.
  • Run the security checkup, calculate your scores, and produce and email your report.
  • Follow up about your checkup results and discuss whether my services fit your situation.
  • Understand which parts of the site and checkup get used, in order to improve them.
  • Operate, secure, and troubleshoot the website, including preventing spam, abuse, and automated attacks.
  • Meet legal, tax, and regulatory obligations, and establish or defend legal claims.

I do not sell your personal information, and I do not share it with third parties for their own advertising or marketing.

AI-assisted report generation

Checkup reports may be drafted with help from a third-party large language model service, reached through the OpenRouter API. When that feature is enabled, the following is transmitted to that provider so a draft report can be produced: your business name, website domain, industry, employee count, questionnaire answers, calculated scores, external scan findings, and the text extracted from any documents you uploaded.

Your name and email address are not sent to the AI provider. If AI-assisted generation is disabled or fails, the report falls back to one produced entirely by the site's own scoring logic, and no checkup information leaves my systems for that purpose.

Automated analysis can be incomplete or wrong. A checkup report is a planning aid, not a professional opinion. See the Terms of Service for the limits of what the checkup provides.

External security scanning

If you provide a website address, the checkup may run passive checks against the publicly visible configuration of that domain — email authentication records (SPF, DKIM, DMARC, MTA-STS), mail server and certificate settings, TLS versions, and HTTP security headers. These checks read information already published to the internet.

The scanner performs no intrusive testing, vulnerability exploitation, or login attempts, and is restricted to publicly routable hosts; private and internal network ranges are refused. By submitting a domain you confirm you are authorized to request these checks for it.

Domain lookups during a scan are resolved through a third-party DNS-over-HTTPS resolver, which receives the domain name being checked.

Who else receives information

Information reaches third parties only through the services that make this site work, and only as far as each needs:

  • Hosting and infrastructure providers that run the website and its database.
  • Email delivery. Google's mail service sends and receives site email, including checkup reports and contact form notifications.
  • AI report generation. A large language model provider reached via OpenRouter, as described above, when that feature is enabled.
  • DNS resolution. A public DNS-over-HTTPS resolver used for the checkup's domain lookups.
  • Content delivery networks. This site loads styling and icon assets from public CDNs. Your browser contacts those networks directly when a page loads, and they receive your IP address and user agent as part of that request.

Information may also be disclosed if required by law, subpoena, or valid legal process, or where disclosure is necessary to protect legal rights, your safety, or the security of these systems.

Cookies and tracking

This site sets cookies only where they are needed for it to work:

  • A session cookie that keeps your place while you complete a checkup or submit a form. It expires after a period of inactivity.
  • A CSRF token cookie that protects form submissions against cross-site request forgery.

Both are set with HttpOnly and SameSite protections and are transmitted only over HTTPS in production. There are no advertising cookies, tracking pixels, or third-party analytics services on this site — no Google Analytics, no ad networks. The image verification challenge on the forms is generated and served by this site, not by a third-party captcha service.

Because there is no cross-site tracking here, a browser "Do Not Track" or Global Privacy Control signal has nothing on this site to disable.

Data retention

Information is kept for as long as it is needed for the purposes described above:

  • Contact inquiries remain in email records while a potential or active engagement is under discussion, and for a reasonable period afterward as a business record.
  • Checkup records — your business profile, answers, scores, report, extracted document text, and scan findings — are retained so your results can be discussed with you and so you can request a copy later.
  • Security and request logs are kept on a short rolling basis for troubleshooting and attack investigation.

There is currently no fixed deletion schedule for checkup records. You can ask me to delete your checkup record or inquiry at any time using the contact details below, and I will do so unless I am required to keep it for a legal or accounting obligation.

How information is protected

The site enforces HTTPS with HSTS, a Content Security Policy, and modern security headers. Administrative access is restricted and authenticated, forms are rate limited and protected against automated abuse, uploads are restricted by file type and size, and IP addresses in usage analytics are stored as hashes rather than in the clear.

No system is perfectly secure, and I cannot guarantee that information will never be accessed without authorization. If a breach affects your information, I will notify you as required by applicable law.

Your choices and requests

You may contact me to:

  • Request a copy of the information held about you.
  • Correct information that is inaccurate.
  • Delete your checkup record or inquiry.
  • Stop receiving follow-up email about a checkup or inquiry.

Email contact@waldencybersecurity.com and describe what you would like. I may need to confirm your identity, or your association with the business named in a checkup, before acting on a request. There is no charge for these requests, and making one will not affect how you are treated.

Depending on where you live, you may have additional rights under state privacy law. I honor these requests regardless of whether a specific law requires it.

Children's privacy

This site and these services are intended for businesses and the people who work for them. They are not directed to children, and I do not knowingly collect personal information from anyone under 18. If you believe a child has provided information, contact me and I will delete it.

This site and its published articles link to sites I do not control, including framework documentation and vendor resources. This policy does not apply to those sites, and I am not responsible for their privacy practices.

Changes to this policy

This policy will be updated as the services change. The effective date and version at the top of this page show when it was last revised. Material changes will appear here before they take effect, and the version you accepted when starting a checkup is recorded with that checkup.

Contact

Questions about this policy, or about how your information is handled, can go to contact@waldencybersecurity.com or through the contact form.