Skip to content
Asuruas
FAQ

Privacy and data FAQ

Questions about account data, website data, authorization, credentials, retention, exports, and processors.

Frequently asked questions

Privacy and data

Questions about account data, website data, authorization, credentials, retention, exports, and processors.

Primary topicPrivacy and data

Questions about account data, website data, authorization, credentials, retention, exports, and processors.

Operating outcomeAccountable improvement

Reduce avoidable exposure while preserving authorization, evidence quality, and change control.

Review statusMaintained resource

Reviewed for accuracy, clarity, and operational use.

01

What this FAQ covers

This page answers recurring questions about privacy and data for website owners, agencies, and technical teams. The answers define practical boundaries, identify the evidence that matters, and explain when a question requires account-specific, technical, contractual, or legal review.

  • What website data can an audit process?
  • Do I need authorization?
  • Should I submit secrets through the public form?
  • How long is audit data retained?
02

Use the answers responsibly

Apply each answer to the actual website, scope, agreement, and evidence. Avoid overstating a scanner result as a confirmed exploit. When the decision could affect production availability, security, accessibility, billing, privacy, or contractual commitments, document the responsible reviewer and verification plan.

Questions and answers

01What website data can an audit process?

Depending on scope: URLs, response metadata, visible content excerpts, structured data, technical evidence, crawl records, screenshots, and user notes.

02Do I need authorization?

Yes. Use Asuruas only for websites and systems you own, manage, or are explicitly authorized to assess.

03Should I submit secrets through the public form?

No. Establish a secure access and scope process separately.

04How long is audit data retained?

Retention depends on the plan, account settings, legal obligations, backup lifecycle, security need, and customer instruction.

05Is customer data sold to advertisers?

The public policy states that customer data is not sold to advertisers.

06Where are subprocessors listed?

The subprocessor register identifies the production providers used for hosting, storage, email, billing, monitoring, support, analytics, and backups. It must be kept current as providers change.

07Can I export my records?

Export availability and scope depend on the plan and customer agreement.

08How do deletion and backups work?

Primary records are deleted according to the approved process; protected backups may retain data temporarily until their lifecycle expires.

Next useful action

Turn privacy and data into an accountable record.

A clear, supportable answer set for privacy and data linked to the relevant workflow or policy.