We’re upgrading Seclum to RAVIONIX.

Privacy Policy

Last updated: 2026-09-25

Ravionix is operated by Angstroma, Inc. (“Ravionix,” “we,” “us”). We built Ravionix because the consumer-security market has a credibility problem. This page is the literal accountability for the promises on our home page.

1. The short version

2. Who we are

Data controller: Angstroma, Inc., a Delaware C-corporation operating the Ravionix brand. Mailing address: c/o Stripe Atlas registered agent, Wilmington, Delaware, USA. Reach us at privacy@ravionix.com.

3. What we collect

Account data (paying customers)

Check data

The reasoning summary may quote signal-bearing fragments of your input — for example, “the URL contains ‘paypa1’ instead of ‘paypal’.” That is the product. The full original input is never stored.

Password breach check

Email breach check & monitoring

Waitlist (if you email us to join)

Billing data (if you buy credits or subscribe)

Operational telemetry

4. What we never collect or store

4b. The free checker (no account)

You can run a few checks on our website without creating an account. Here is exactly what happens to what you submit:

5. Why we process what we do (lawful basis under GDPR)

5b. If your employer uses Ravionix Team (phishing-awareness training)

You may be reading this because you clicked a link in an email that turned out to be a simulated phishing test run by your own employer. Here is exactly where you stand.

Your employer is the data controller, and Ravionix is only their processor. They chose to run the simulation, they decided who to include, and they hold your data. We act on their instructions and nothing else. If you want to know why you were included, or you want your data erased, ask your employer — they direct us, and we will help them act on it.

What we hold about you, on their behalf:

What we do not hold:

The email was written by an AI model, and the model never saw your address — it is given a scenario, not a person. Under our terms, your employer may not use simulation results for hiring, firing, discipline, promotion, or performance evaluation. A click is a teachable moment, not a mark on your record. If you believe results are being used against you, tell us at legal@ravionix.com.

6. How long we keep what we keep

7. Who else processes your data (sub-processors)

We use the following service providers. Most include a Data Processing Agreement in their standard terms; where a provider requires a separate signature, we complete it. Have I Been Pwned is covered by its own terms of use.

Google is deliberately not on this list. When a Ravionix Team customer connects their Google Workspace mailbox to send phishing-awareness training, that mailbox is their system, not our sub-processor — the mail leaves their tenant, under their own mail policy, using a grant they can revoke at any time. See Terms §4d. Google and Microsoft are also the sign-in services you choose when you create an account; for that sign-in they act under their own privacy policies.

8. Your rights

If you are in the EU, UK, EEA, Switzerland, California, or any jurisdiction with similar law:

9. Children

Ravionix is not directed to children under 13 (under 16 in the EU/EEA and UK). We do not knowingly collect data from children under those ages. If you believe we have, email privacy@ravionix.com and we will delete it.

10. International transfers

Our infrastructure runs primarily in US-East. If you are outside the US, your data is transferred to and processed in the US under Standard Contractual Clauses (SCCs) with each sub-processor named above.

11. Security

All traffic is TLS-encrypted. Secrets at rest are stored in Vercel's encrypted environment variables. The audit log is immutable at the database layer (a Postgres trigger blocks updates and deletes outside of the retention rotation cron). We describe our threat model and mitigations in our internal Data Protection Impact Assessment, available on request to enterprise customers under NDA.

12. Breach notification

If we suffer a breach affecting your data, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires (GDPR Article 33), and notify affected users without undue delay where the breach is likely to put their rights at high risk (GDPR Article 34).

13. Changes to this policy

If we make material changes, we will email you at the address on your account and post a notice at the top of this page for at least 30 days. The “Last updated” date at the top reflects the most recent revision.

14. Contact

Privacy questions, GDPR / CCPA requests, or anything you want clarified: privacy@ravionix.com.