Legal

Privacy Policy

Effective 16 August 2026

PQCClear assesses how exposed an organization is to quantum-capable attacks on its cryptography. Doing that means holding information about institutions, about their vendors, and about the people who answer for both. This policy says what we hold, why we hold it, and what a stranger with a cert ID can actually see.

  1. 01

    Who this covers

    This policy applies to the PQCClear website and to the assessment platform behind it. It covers three kinds of people: visitors who never sign in, institutions that run vendor assessments from the dashboard, and vendors who answer an assessment or certify themselves.

    Where an institution uses PQCClear to assess its own vendors, that institution decides what it collects and why. We process that information on its behalf and under its instructions.

  2. 02

    What you give us

    • Contact requests. Your name, work email, institution name, your role, institution type, and optionally asset size, vendor count, and free-text notes, when you request a pilot or ask to be notified at launch.
    • Account details. Your email address and name, an authentication factor if you enable multi-factor sign-in, and your role within your organization. Passwords are handled by our authentication provider and are never stored by us in a readable form.
    • Assessment content. Vendor records, vendor contact names, email addresses and roles, questionnaire answers, internal notes, and any documents uploaded as evidence for an answer.
    • Certification content. For self-certification, your questionnaire answers and the cryptographic metadata produced by the scanner.
  3. 03

    What we collect automatically

    • Session cookies. Strictly necessary cookies that keep you signed in and protect the session. There are no advertising or cross-site tracking cookies on this site.
    • Network address. Your IP address is used to rate-limit public forms and to block abuse. It is not used to build a profile of you.
    • Aggregate usage. Page-level analytics that tell us which pages are read, without identifying individual visitors.
  4. 04

    What the scanner does not send

    The PQCClear scanner runs on your own machine or in your own pipeline. It submits cryptographic metadata: algorithms, key sizes, protocol versions, certificate parameters, and where they were found. It does not upload your source code, your data, or your keys.

  5. 05

    How we use it

    • To run assessments, produce a PQC Readiness Score and CBOM, and issue and renew certifications.
    • To authenticate you and keep each organization's records separated from every other organization's.
    • To send transactional email: assessment invitations, expiry reminders, and replies to a request you sent us.
    • To detect and prevent abuse of public forms and lookups.
    • To recalibrate the scoring model. Model work uses assessment data in aggregate, never a named vendor as an example.

    We do not sell personal information, and we do not use it for advertising or share it with advertisers.

  6. 06

    What a public lookup reveals

    A cert ID lookup is deliberately narrow. Anyone holding a cert ID can see the certified organization, its PQC Readiness Score, and whether the certification is current or expired.

    A lookup does not reveal questionnaire answers, uploaded evidence, CBOM detail, findings, or anything about who checked the ID. Publishing the trust seal is the certified organization's choice; the underlying assessment record stays private.

  7. 07

    Who else processes it

    We keep the list of third parties short, and each one processes data only to deliver the service.

    • Supabase. Database, authentication, and encrypted file storage for evidence documents.
    • Vercel. Application hosting and aggregate page analytics.
    • Resend. Delivery of transactional and notification email.

    Assessment results are also visible to the institution that initiated the assessment. That is the point of the product, and a vendor is told which institution invited it before it answers anything.

  8. 08

    How it is protected

    Every read of tenant data is scoped by row-level security at the database, so one organization cannot query another's records even if application code is wrong. Evidence files live in a private bucket and are served only through short-lived signed links, never a public URL. Vendor portal links are credentials in their own right and are re-validated on every request. Multi-factor authentication is available on accounts.

    No system is perfectly secure, and we will not claim otherwise. If we learn of a breach affecting your information, we will tell you and act on it.

  9. 09

    How long we keep it

    Assessment and certification records are kept while your account is active, because an audit trail that disappears is not an audit trail. Contact requests are kept while we are still in touch with you about them. When you close an account, we delete or anonymize the associated personal information within a reasonable period, except where we are required to retain it.

  10. 10

    Your choices

    You can ask us for a copy of the personal information we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Depending on where you live, laws such as the GDPR, the UK GDPR, or United States state privacy laws may give you these rights formally. We honor the requests regardless of where you are.

    If your information sits inside an assessment run by an institution, we will forward your request to that institution and support them in answering it.

  11. 11

    Where it is processed

    PQCClear serves institutions in North America, the European Union, and Japan, and our infrastructure providers operate in multiple regions. Your information may be processed outside the country where you live. Where that transfer needs a legal basis, we rely on the safeguards our providers offer.

  12. 12

    Children

    PQCClear is a business product. It is not directed at children and we do not knowingly collect information from them.

  13. 13

    Changes to this policy

    When this policy changes we update the effective date at the top. If a change materially affects how we handle your information, we will tell account holders directly rather than rely on you noticing the date.

Questions about this document?

Write to us and a person will answer. Include the clause number if your question is about a specific one.

contact@pqcclear.com