Privacy and platform policy
This policy explains how Shomar handles account, workspace, security, evidence, and communication data for organizations using the platform.
Last updated: July 12, 2026
What Shomar collects
Shomar collects the information needed to provide security, compliance, reporting, billing, support, and account administration services.
- Account details such as name, work email, role, organization, and login/session activity.
- Workspace data such as projects, scans, findings, evidence, tasks, reports, integrations, and audit logs.
- Operational metadata such as IP address, browser details, timestamps, configuration choices, and support requests.
- Commercial data such as plan interest, billing contact, quote requests, invoice status, and customer success notes.
How Shomar uses data
Shomar uses data to operate the product, secure customer workspaces, support regulated evidence workflows, provide notifications, and improve service reliability.
- Run security and compliance workflows requested by an authorized organization user.
- Send account, password reset, billing, delivery, and security notifications from Shomar.
- Provide customer support, onboarding, service health, reporting, and legal/compliance administration.
- Maintain audit logs, prevent abuse, enforce usage limits, and protect platform integrity.
Security and source-code handling
Shomar supports SaaS scanning, customer-controlled scan workers, external evidence links, and customer-owned evidence storage depending on organization policy and plan.
- Organization admins can set source-code handling, secret redaction, retention, and private-worker requirements.
- Evidence storage can be Shomar-managed, customer-owned, or external-link based where supported.
- Sensitive strings may be redacted in findings and evidence payloads when configured.
Retention and deletion
Retention depends on workspace settings, legal obligations, billing obligations, audit requirements, and customer instructions. Shomar may retain security logs where needed for fraud prevention, legal compliance, or platform integrity.
Contact
For privacy, security, billing, or legal requests, contact enquiry@shomar.io. Organization users should also contact their own org admin for workspace-level access or deletion requests.