Where your data lives

Ironimo is operated by a Netherlands-based company. Scan data — targets, findings, tool output, and reports — is processed and stored on infrastructure in the European Union. Website analytics run on the EU PostHog endpoint, and nothing is captured until a visitor accepts cookies.

We do not sell customer data, and we do not share it with advertisers or data brokers.

Credentials for authenticated scanning

If you configure authenticated scanning, the credentials you supply are handled as follows:

  • Encrypted at rest using Fernet symmetric encryption, with the key held outside the database
  • Decrypted only at scan time, inside the scan worker
  • Never written into a report, a finding, or an exported PDF
  • Never returned by the API, including to your own account
  • Deleted when you delete the target

Our recommendation is unchanged from what any tester would tell you: create a dedicated, least-privilege account for scanning rather than handing over a real administrator login.

Will a scan break production?

Default scanning is non-destructive. The default chain performs reconnaissance, fingerprinting, enumeration, and passive vulnerability detection. It reads; it does not attempt to modify or destroy data.

Tools capable of aggressive behaviour — sqlmap, hydra, commix — are gated. They run only when you explicitly enable them for a target. Our standing advice is to point those at staging first.

Two practical notes from real scans:

  • Load. Enumeration tools generate real request volume. On a small instance behind no cache, a scan is noticeable. Schedule the first run outside peak hours.
  • WAFs and rate limits. If your target sits behind Cloudflare or a similar WAF, enumeration tools will get rate-limited and results will be thinner. Ironimo detects the WAF and notes it in the report rather than pretending the empty result means you are clean.

You must be authorised to scan the target

Running these tools against a system you do not own or have written permission to test is illegal in most jurisdictions, including under the Dutch Computer Crime Act and the EU directive it implements. By submitting a target you confirm you are authorised to test it. We log target submissions, and we terminate accounts used to scan third parties without permission.

Access to your account

  • Authentication with hashed passwords; sessions are revocable
  • Organisation-scoped access — team members see only the targets in their organisation
  • Audit logging on authentication and administrative actions
  • SSO / SAML available on Enterprise

Retention and deletion

Scan history is retained for 30 days on Starter, 90 days on Pro, and indefinitely on Enterprise. You can delete a target and its scan history from the application at any time; deletion removes the findings, the stored tool output, and any credentials attached to that target. To delete your entire account and all associated data, email privacy@ironimo.online.

Where we are not yet

We would rather tell you this than have you find out in a questionnaire:

  • Ironimo is not currently SOC 2 or ISO 27001 certified. We help you produce evidence for your SOC 2 and ISO 27001 vulnerability-management requirements; we have not completed our own audit.
  • We do not yet publish a third-party penetration test report of the Ironimo platform itself.
  • We do not yet run a public bug bounty programme.

If any of these are hard requirements for your procurement process, say so at contact@ironimo.online and we will tell you honestly where we are rather than waste your time.

Reporting a vulnerability in Ironimo

If you find a security issue in Ironimo itself, we want to hear about it. Email security@ironimo.online with enough detail to reproduce it.

  • We will acknowledge your report within 3 working days
  • We will keep you updated on remediation and tell you when it is fixed
  • We will not pursue legal action against good-faith research that respects user privacy, avoids data destruction, and does not degrade our service
  • We will credit you publicly if you want the credit

Please give us a reasonable window to fix an issue before disclosing it. We do not currently pay bounties.

Subprocessors

We use a small number of third parties to run the service. The current list, what they process, and where, is available on request at privacy@ironimo.online. We will sign a data processing agreement.

Security questionnaires

We answer them. Send yours to contact@ironimo.online. If your change advisory board needs a written description of what a scan does to a production target before approving it, ask and we will write one for your specific configuration.

Last updated 25 August 2026.

Questions we did not answer here?

Ask directly. We would rather have the awkward conversation before you buy than after.

We count page views without cookies (PostHog, EU-hosted) — nothing is stored on your device until you choose. Accept for full analytics, Decline to switch it off entirely. No personal data is sold or shared with advertisers.