Privacy Policy

Penetrum LLC and its related entities (“Penetrum LLC” or “Malcore” or “we” or “our”) are committed to protecting your personal information in accordance with applicable U.S. privacy laws, including but not limited to the California Consumer Privacy Act (CCPA) and other state-level data protection statutes.

1. What is "Personal Information"?

“Personal Information” refers to any information that identifies, relates to, describes, or is capable of being associated with a particular individual or household.

2. What Personal Information Do We Collect?

We may collect your name, contact information (email, phone, address), date of birth, IP address, financial/payment information, user preferences, and service usage data.

3. Why Do We Collect It?

To provide products and services, fulfill legal obligations, manage user accounts, market our offerings, and improve user experience through analytics and customization.

4. How Do We Collect It?

Through direct interactions (forms, emails, website use), third-party partners, automated tracking tools (cookies and web beacons), and customer service inquiries.

5. Information Collected via Website

Our website may collect metadata such as:

Cookies

We use cookies to enhance your experience. You may disable cookies in your browser, but this may limit functionality.

Web Beacons

We may use tracking pixels or beacons to measure engagement and improve services.

6. How We Use Your Data

7. Who Do We Share It With?

We may share data with service providers, payment processors, analytics platforms, or government entities when required by U.S. law. We do not sell your personal information.

8. Storage and Security

We employ encryption, access controls, and secure infrastructure to protect your data. Data is stored within U.S.-based infrastructure.

9. Access and Correction

You may request to review, update, or delete your personal information by contacting us at [email protected].

10. Data Retention

We retain personal information only as long as necessary for business, legal, or compliance purposes, after which it is securely deleted.

11. Extended Desktop & Plugin Policy

This Privacy Policy includes our desktop applications and browser extensions. We may collect name, email, device/system info, and usage analytics to improve features and performance.

Use and Disclosure

12. Malware Sample Retention Policy

All uploaded malware samples are retained for no more than 24 hours. They are permanently deleted using forensic-grade deletion. Users may opt out of sample use in hunting systems for a fee.

12.1 Automated File Triage Privacy

Files uploaded to Malcore’s Automated File Triage service are **not stored longer than necessary** to complete the requested analysis. Once analysis concludes, the uploaded file is securely and permanently deleted from Malcore’s systems.

**Malcore does not use uploaded files for internal AI training or model improvement.** However, certain components of the analysis process may be powered by third-party classifiers or analysis engines. These external tools may retain data according to their own privacy policies. Users concerned about extended data storage are encouraged to review the Perkins Cybersecurity Educational Fund (PCEF) Privacy Policy, which outlines any third-party data relationships relevant to public benefit services.

Analysis reports are stored temporarily in the user's browser via localStorage. Once that local session data is cleared, either manually by the user or automatically by browser behavior, the report becomes **inaccessible and unrecoverable**. Malcore does not store a copy of the report server-side, and we cannot recreate or reprocess analysis results after this session data expires.

13. Hexdump Usage

Hexdumps may be retained for internal threat hunting but do not contain executable code. They are never sold, published, or used for research outside our platform.

14. Refund Policy

All purchases are final. Refunds are not guaranteed and are issued only at our sole discretion.

15. Limitation of Liability

By using our services, you assume all risk associated with handling malware. We disclaim liability for any data loss, system damage, or security incident resulting from sample use.

16. Restricted Access Policy

Use of our platform is prohibited from restricted jurisdictions (e.g., China, Russia, North Korea, Iran). Circumventing access controls via VPNs, proxies, or anonymizers is a violation of our terms.

17. Updates

We may update this policy as required by law or internal changes. The latest version will be posted at malcore.io.

18. Contact

For questions, access requests, or concerns about this policy, email [email protected].

Last Updated: May 22, 2025 2:18pm CST