Effective date: October 2, 2026
What changed on October 2, 2026: section 1.4 now explains that registry.defectdojo.com fetches image manifests from Docker Hub on your client's behalf, that we also use reverse DNS to identify networks, and how to download straight from Docker Hub. It also says that we may ask organizations that download DefectDojo for feedback, that the address also helps protect the service from abuse, and that encrypted backups are kept for up to 30 days (section 6). On October 1, 2026 we added section 1.4 on downloads of our container images and Helm charts, described our own website tracker in sections 1.2 and 3, described how we use public activity in our open-source repositories and community Slack workspace in section 1.3, and gave a retention period for those records in section 6.
This Privacy Policy explains how DefectDojo, Inc. (“DefectDojo”, “we”, “us” or “our”) collects, uses and shares personal information about:
- visitors to defectdojo.com and our other websites that link to this policy, including docs.defectdojo.com and trust.defectdojo.com (together, the “Websites”);
- people who contact us, request a demo or quote, create or manage an account in our cloud portal, attend our events or webinars, or subscribe to our communications;
- business contacts at our customers, prospective customers, partners and suppliers;
- people who download our container images or Helm charts through registry.defectdojo.com or charts.defectdojo.com, take part in DefectDojo's public GitHub repositories, or join the DefectDojo community Slack workspace; and
- job applicants.
DefectDojo, Inc. is a Delaware corporation headquartered in Texas, USA. It is responsible for (the “controller” of) the personal information described in this policy. DefectDojo has no parent company, subsidiaries or affiliates.
What this policy does not cover
- Customer data in DefectDojo Pro. When an organization uses DefectDojo Pro as a service, we process the data it puts into the platform, including its users' account details, on its behalf and under our agreement with that organization. That organization decides how the data is used. If you are a user of a customer's DefectDojo Pro instance, please contact that organization with privacy questions.
- Self-hosted software. Self-hosted DefectDojo Pro and the open-source Community Edition run in your own environment. We do not receive the data you put into them. If you download our images through registry.defectdojo.com, the download is recorded as described in section 1.4.
- Third-party services. Sites and services such as GitHub, LinkedIn, YouTube and Slack have their own privacy policies, which cover what they collect. What we collect from your public activity on GitHub and in the DefectDojo community Slack workspace is described in section 1.3.
1. Information we collect
1.1 Information you give us
- Contact and professional details, such as your name, work email, phone number, job title, company and country, when you fill in a form, request a demo or quote, register for an event or webinar, or email us.
- Account details for our cloud portal, such as your name, email, login details, organization and subscription information. If you pay by card, our payment processor (Stripe) collects your card details directly. We do not see or store full card numbers.
- Communications, such as emails, support requests, meeting notes and, where you are told in advance, recordings of calls or webinars.
- Marketing preferences, such as whether you want to receive our emails.
- Job applications, such as your CV, work history and anything else you choose to send us. If we make you an offer, we may run a background check, and we will tell you about it (and ask for your consent where the law requires) before we do.
1.2 Information we collect automatically
When you use the Websites or our cloud portal, or open our emails, we and our providers use cookies, pixels, tags and similar technologies to collect:
- your IP address and the approximate location it indicates;
- browser, device and operating system information;
- the pages you view, links you click, forms you interact with, the page that referred you, campaign parameters and time spent on the Websites;
- searches you run in our documentation, where on a page you click and how far you scroll, and errors a page reports (we do not record keystrokes or what you enter in forms);
- when you create an account, sign in or activate a plan in our cloud portal; and
- whether you open our emails and which links you click in them.
1.3 Information we get from other sources
- Business data providers and professional networks, such as Apollo, Hunter and LinkedIn, which give us business contact details and company information (for example name, job title, company and work email).
- Visitor identification providers, such as Reo.dev and Apollo, which match IP addresses and other signals to the organization a visitor works for and, in some cases, to a professional profile. These providers may also tell us about public activity related to DefectDojo's open-source projects, such as on GitHub.
- Public open-source and community activity. When you star, fork or watch DefectDojo's public GitHub repositories, or open or comment on an issue, pull request or discussion in them, we record that activity together with the public parts of your GitHub profile (username, name, company, location, website and social handles, and your email address if you have made it public). If you join the DefectDojo community Slack workspace, we record your name, email address and the organization it indicates, and when you join or post in a public channel. We do not read private channels or direct messages. We also keep links to public posts that mention DefectDojo on sites such as Hacker News, Stack Overflow, Reddit, Mastodon, Bluesky and dev.to, with the author's public handle, so we can answer questions about the project. We use all of this to understand which organizations use and contribute to our open-source software, and to decide which organizations to tell about our products.
- Event organizers and co-sponsors, when you register for or attend an event and agree to share your details with us.
- Resellers and partners, when you buy through them or they refer you to us.
- Public sources, such as company websites, public professional profiles and public code repositories.
1.4 Downloads of our container images and Helm charts
When you download the DefectDojo container images through registry.defectdojo.com, or our Helm charts through charts.defectdojo.com, we record the download. These hosts do not store the software: image layers come straight from Docker Hub and chart packages from GitHub, where they are published. Image manifests (the small files that describe each image) are fetched from Docker Hub by registry.defectdojo.com on your client's behalf, using DefectDojo's own Docker Hub account, so your own Docker Hub pull limits do not apply to our images. When that isn't possible, your client is sent to Docker Hub directly. When your client contacts these hosts we record the time, the image or chart and version requested, the client software and its version (for example Docker 29.8 or Helm 3.16) and the IP address the request came from.
We use the IP address to find out which organization or network it belongs to, by looking it up in the public registries that record this (such as ARIN and RIPE) and in reverse DNS, and to protect the service from abuse. We then delete the address, within three days at the latest. Encrypted backups of our database are kept for up to 30 days (see section 6). What we keep is the time, the image or chart, the client software and the type of network (for example a business, a university or an internet service provider) and, for an organization's own network, its name and country. Downloads from home internet connections, hosting providers, VPNs and proxies are counted but not linked to any organization. We do not record who ran the command, and we learn nothing about your DefectDojo instance or the data in it.
We use these records to understand which organizations download DefectDojo, together with the other activity described in this section, and to decide which organizations to contact about our products or to ask for feedback. We do not sell or share these records. To download straight from Docker Hub instead, pull the images from docker.io (for example docker pull defectdojo/defectdojo-django) or from your own registry mirror. You can also object to this processing at any time (see section 7).
We do not ask for sensitive personal information (such as health data or government ID numbers) through the Websites. Please do not send it to us.
2. How we use your information
If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, the law requires a legal basis for each use. The table below lists both.
| Purpose | Legal basis (EEA, UK, Switzerland) |
|---|---|
| Answering your questions and requests, including demos, quotes and support | Taking steps at your request before a contract; performing a contract; our legitimate interest in responding to people who contact us |
| Setting up and managing cloud portal accounts, subscriptions and billing | Performing a contract; complying with tax and accounting law |
| Running and securing the Websites, including preventing spam, fraud and abuse | Our legitimate interest in operating secure websites |
| Understanding how the Websites are used and measuring our campaigns | Your consent, where required for cookies; otherwise our legitimate interest in improving the Websites |
| Understanding which organizations use our open-source software and how, from website and documentation use, downloads of our container images and Helm charts, and public activity in our GitHub repositories and community Slack workspace | Our legitimate interest in understanding how our open-source software is adopted and in marketing our products to organizations that use it. You can object at any time (see section 7). |
| Sending marketing emails and newsletters | Your consent, where the law requires it; otherwise our legitimate interest in telling business contacts about our products. You can unsubscribe at any time. |
| Contacting business professionals who may be interested in our products | Our legitimate interest in marketing software to organizations that may use it; your consent where local law requires it |
| Showing and measuring ads on platforms such as Google, LinkedIn and Reddit | Your consent, where required |
| Running events and webinars | Performing our agreement with you; our legitimate interest in running events |
| Recruiting | Taking steps at your request before a contract; our legitimate interest in hiring; complying with employment law |
| Meeting legal obligations, enforcing our terms and protecting our rights | Complying with the law; our legitimate interest in protecting our business |
Where we rely on legitimate interests, we have weighed them against your rights. You can object at any time (see section 7).
We use some tools, including AI features provided by our service providers, to help us route, summarize and answer support requests and to organize sales and marketing information. We do not make decisions that have legal or similarly significant effects on you based only on automated processing.
3. Cookies and similar technologies
We use these kinds of cookies and similar technologies:
- Strictly necessary: to run the Websites, keep them secure, stop bots (for example CAPTCHA) and remember your cookie choices.
- Analytics: to understand how the Websites are used, through HubSpot and Google Analytics.
- Advertising and measurement: to show our ads on other sites and measure how they perform, through Google Ads, the LinkedIn Insight Tag, the Reddit Pixel and HubSpot's ad tools.
- Visitor identification: to understand which organizations visit the Websites, through our own tracker, served from t.defectdojo.com, and providers such as Apollo and Reo.dev. Our tracker sets a first-party cookie (
_dds_vid) that lasts 13 months, and it never identifies individual visitors in the EEA, the UK or Switzerland. - Embedded content: videos from YouTube and similar services, which may set their own cookies.
Your choices. Outside the United States, we use cookies other than strictly necessary ones only after you accept them in our cookie banner. In the United States, those cookies may be set when you arrive, and you can turn them off at any time by choosing “Decline” in the banner or through the cookie settings link. You can also block or delete cookies in your browser settings, and opt out of personalized ads from Google and LinkedIn.
Global Privacy Control and Do Not Track. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of advertising cookies and of “sale” or “sharing” of your information for that browser. Our Websites do not respond to Do Not Track signals, because there is no common standard for them.
4. How we share your information
We share personal information only as described here:
- Service providers that work for us under contracts that limit how they may use the information. They include providers of cloud hosting (Google Cloud), our website, CRM and marketing tools (HubSpot), sales tools and business data (Apollo, Hunter), visitor identification (Reo.dev), analytics (Google Analytics), AI models (Anthropic), email, collaboration and meetings (Google Workspace, Slack, Zoom), customer support (Intercom), payments (Stripe), accounting (Intuit) and HR and payroll (Gusto, Remote). Contact us for a current list.
- Advertising and social media platforms, such as Google, LinkedIn and Reddit, which receive information through their tags on the Websites. They may use it under their own privacy policies, for example to measure our ads and show you ads on their platforms.
- Resellers and partners, when you buy our products through them or they refer you to us, to the extent needed to handle your purchase or inquiry.
- Event co-sponsors, where you are told at registration that your details will be shared with them.
- Professional advisers, such as lawyers, accountants, auditors and insurers, who are bound by confidentiality.
- Legal and safety reasons: when the law requires it, to respond to valid legal process, or to protect the rights, property or safety of DefectDojo, our users or others.
- Business transfers: to a buyer, investor or successor in connection with a merger, acquisition, financing or sale of all or part of DefectDojo's business, under confidentiality obligations.
- With your consent or at your direction.
Sale and sharing. We do not sell personal information for money. Some US state laws treat our use of advertising cookies and pixels as a “sale”, “sharing” for cross-context behavioral advertising, or “targeted advertising”. You can opt out as described in section 3.
5. International transfers
DefectDojo is based in the United States. Our personnel and service providers work in the United States and other countries, including Canada, the United Kingdom and countries in the European Union, so your information may be processed outside the country where you live. Those countries may have different data protection laws, and in some cases courts or authorities there may be able to access the information.
When we transfer personal information from the EEA, the UK or Switzerland to a country that does not have an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or the Swiss equivalents where they apply) or on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You can ask us for a copy of the relevant safeguards.
6. How long we keep information
We keep personal information only as long as we need it for the purposes in this policy, and then delete or de-identify it. How long depends on the type of information:
- Business contact and marketing records: while you are a customer or appear interested in our products. If you unsubscribe or ask us to delete your details, we keep a minimal record so we can respect that choice.
- Account and billing records: for as long as your account is active, and afterward for as long as tax, accounting and other laws require.
- Support and other communications: for the length of the customer relationship and a reasonable period after it.
- Job applications: for the recruitment process and a limited period after it to deal with any legal claims, or longer if you agree that we can consider you for future roles.
- Website, download and open-source activity records: up to 13 months in a form that can be linked to a browser, device or individual. After that we keep only organization-level summaries.
- Backups: encrypted backups of our databases are kept for up to 30 days, so a deleted record can remain in a backup for that long.
- Cookie data: for the lifetime of each cookie, which you can see in your browser settings.
7. Your rights and choices
Marketing emails. You can stop our marketing emails at any time with the unsubscribe link in each email or by emailing us. You have the right to object to direct marketing at any time, and we will stop.
Downloads and open-source activity. To keep your downloads out of our records, pull straight from Docker Hub as described in section 1.4. To object to our use of your public GitHub or community Slack activity, or of our website tracker, email us and we will stop and delete what we hold about you.
Everyone. Wherever you live, you can ask us to tell you what personal information we hold about you, to correct it, or to delete it. We will do what we reasonably can, subject to the law.
EEA, UK and Switzerland. You have the right to access, correct, delete, restrict and port your personal information; to object to processing based on legitimate interests; to withdraw consent at any time, without affecting processing that already happened; and to complain to a data protection authority.
US states. Depending on where you live, you may have the right to know about, access, correct, delete and receive a copy of your personal information, and to opt out of its sale, sharing, use for targeted advertising, and certain profiling. We will not discriminate against you for using these rights. You can use an authorized agent, and we may ask the agent for proof of authorization. If we deny your request, you can appeal by replying to our decision or emailing us with “Appeal” in the subject line. If we deny your appeal, you can contact your state attorney general.
Canada. You can access and correct your personal information and withdraw consent, subject to legal and contractual limits. If you are in Quebec, you also have the rights provided by Quebec law, including asking us to stop disseminating your information.
How to make a request. Email compliance@defectdojo.com. To protect your information, we will confirm your identity, usually by checking that the request comes from, or is confirmed through, the email address we have on file. We will not ask for more information than we need. We respond within the time the applicable law requires, usually within one month.
8. Complaints
If you have a concern about how we handle your personal information, please email us first. We will acknowledge your complaint within 30 days and tell you what we have done about it. You also have the right to complain to your local data protection authority, such as a data protection authority in the EEA, the UK Information Commissioner's Office, the Swiss Federal Data Protection and Information Commissioner, the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
9. Security
We use administrative, technical and physical safeguards to protect personal information, including access controls and encryption in transit. Our security program is independently audited under SOC 2 Type II, and our security policies are published at trust.defectdojo.com. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Children
Our Websites and products are meant for businesses and are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, please contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. When we do, we will change the effective date at the top. If we make a material change, we will post a notice on this page before it takes effect and, where the law requires, notify you by email or ask for your consent. We will not apply a material change to information we collected before the change without your consent where the law requires it.
12. Contact us
DefectDojo, Inc.
1515 E Cesar Chavez St, Suite 100 PMB 1061
Austin, TX 78702
USA
Email: compliance@defectdojo.com
Our Chief Executive Officer is the person responsible for the protection of personal information, including for the purposes of Canadian and Quebec privacy law, and can be reached at the same email address.