Legal & trust

Privacy notice.

What we collect, where it lives, and how to exercise your rights. Written by the engineer who built the system — it describes exactly what the platform does today, nothing more.

Who we are

SilentBait is a honeypot-as-a-service platform operated by its founder, reachable at alachaud@silentbait.io. All infrastructure runs in the AWS Paris region (eu-west-3) — your data does not leave the EU.

What we collect

1. Console accounts

When you create an account we store:

  • Email address and name — encrypted at rest with AES-256-GCM (field-level, per-value keys). Login lookups use an HMAC-SHA256 blind index, so the plaintext email never appears in queries or logs.
  • Password — only as a bcrypt hash (cost 12). It is never stored or transmitted in readable form.
  • 2FA secret — only if you enable TOTP two-factor authentication.

2. Bait captures (the product's core data)

Decoy baits record everything an attacker does on them:

  • Attacker IP addresses, usernames and passwords entered on decoys
  • Commands typed, session recordings, HTTP headers and client metadata

This data belongs to the tenant whose bait captured it. SilentBait staff cannot read it: the admin console is architecturally restricted to platform operations metadata (details).

3. Demo requests

The demo form stores your work email, company name, infrastructure size, role and source IP. It is used once — to reply to your request. There is no newsletter, no drip campaign, no third-party sharing. Leads are deleted after the conversation ends or within 12 months.

4. This website

No cookies, no analytics, no trackers. The marketing site is static HTML/CSS/JS. The console uses a single session token for authentication — nothing else.

Where your data lives

  • Region: AWS Paris (eu-west-3) exclusively.
  • At rest: database and disks are encrypted; account PII is additionally field-level encrypted (AES-256-GCM).
  • In transit: TLS 1.2/1.3 only, everywhere.
  • Backups: encrypted, same region, automated retention.

Retention

  • Console account: kept until you ask us to delete it.
  • Bait captures: 90 days on Pro plans (rolling window).
  • Demo leads: deleted after the conversation ends, or within 12 months.
  • Audit trail: platform operations (no tenant data) kept for security review.

Your rights

Email alachaud@silentbait.io from your account address to:

  • Export everything we hold about your account,
  • Delete your account and all associated data,
  • Correct any inaccurate information.

Requests are processed manually by the founder within 30 days — usually much faster. Deletion is real deletion, executed through an audited operations runbook.

Sub-processors

  • AWS (Paris region) — hosting, database, email delivery (SES).
  • OVH — domain registration, DNS, and the silentbait.io mailboxes.

No analytics provider, no advertising network, no data broker. Ever.

Changes

Any change to this notice is posted on this page with the date below. We will never quietly start collecting something new.

Last updated: August 3, 2026 — first version, published with the public launch of the platform.
Honest status: SilentBait is a young company. This notice was written by the engineer who built the system, not a law firm. GDPR certification programs are on our roadmap — we are not yet certified, and we won't claim otherwise.