exploit.cc has no accounts, sets no cookies of its own, and asks you for nothing in order to read it. This policy covers the little that is left: the request data every web server receives, the two analytics services we run, and what happens to any of it if this business is ever sold.
We do not sell personal information. Section 9 explains why that sentence and a possible future sale of the Site are not in conflict.
This Privacy Policy describes how EVECS, LLC ("exploit.cc", "we", "us") collects, uses and discloses information in connection with the website at https://exploit.cc and its subdomains (the "Site").
The Site is a public reference. There are no accounts, no sign-in, no paywall and nothing you have to tell us in order to read every page. That shapes everything below: we hold almost nothing about you, because the product does not need it.
What we do hold falls into three groups: the request data every web server receives, measurement data from two analytics services, and anything you choose to put in an email to us. Sections 3 through 5 cover each in turn.
Stating the absences first, because they remove most of the usual questions:
The Site runs on Cloudflare's network. Serving a page requires receiving a request, and a request carries information about the machine that sent it. That data is processed at Cloudflare's edge and in our own application logs, and includes:
We use this to serve pages, to keep the Site available, to investigate errors and abuse, and to understand load. It is not used to build a profile of you and is not combined with the analytics measurement described in section 5 to identify an individual.
If you email contact@exploit.cc, we receive your address, your message, anything you attach, and the routing data every email carries. We use it to answer you, to keep a record of the exchange, and to handle any legal or safety issue it raises.
Correspondence is retained for as long as it is useful for those purposes. Do not send us confidential material, credentials, or personal information you would not want held in an ordinary mailbox.
We measure traffic with two services. They work differently and it is worth being precise about which is which.
Cloudflare reports on traffic and performance from the requests our Site already receives at its network edge. It needs no script in your browser and sets no cookie, and it does not place an identifier on your device. This is the measurement we rely on for load, errors and performance.
We also use Google Analytics. It reaches you through Cloudflare's Google tag gateway, which changes the delivery path in a way that a reader inspecting their browser deserves to have spelled out:
The data measured this way is the usual analytics set: pages viewed, referrer, approximate location, device and browser, and a pseudonymous identifier that lets Google count a returning browser as one visitor rather than several. We use it to see which records and searches people find useful. We do not use it to identify you, and we have not enabled Google Analytics advertising or audience features that would feed it into ad targeting.
Section 12 sets out how to opt out. Our Cookie Policy lists the specific cookies involved.
We use the information described above only for the following purposes:
Where the law requires a legal basis for processing, ours are our legitimate interests in running and securing a public reference site and in understanding its use, our compliance with legal obligations, and your consent where consent is what applies.
We do not share personal information for anyone else's independent marketing. It reaches the following recipients and no others:
This section is about other people's information, not yours, and it is the one category on this Site that a visitor cannot affect by changing a browser setting.
Vulnerability records published by their issuing authorities sometimes contain personal information: the name or handle of a researcher credited with a discovery, an email address in a reference, a link to a personal blog or a social media account. We reproduce those records as the authority published them. We do not add personal information to a record, and we do not enrich, cross-reference or build a profile from what a record contains.
If a record here contains personal information about you, the authority that published it is the source of record, and correcting it there is what causes the correction to propagate everywhere, including here. Write to contact@exploit.cc and we will tell you which authority published the record. We will also consider a request about our own copy on its merits, taking into account the public interest in a complete and unaltered vulnerability record, our legal obligations, and the fact that the record will remain published upstream regardless of what we do.
We do not sell personal information. We do not rent, lease or trade it, and we do not disclose it to third parties for their own advertising or commercial exploitation. We do not "sell" or "share" personal information for cross-context behavioural advertising as those terms are defined by the California Consumer Privacy Act or comparable state laws.
A sale of the business is a different thing, and it may happen. We may sell, transfer or otherwise dispose of some or all of the Site or of EVECS, LLC, including in a merger, acquisition, financing, reorganisation, bankruptcy or sale of assets. In any such transaction the information we hold in connection with the Site, including the categories described in this policy, may be among the assets transferred to the acquirer or successor.
An acquirer would receive that information subject to this policy or a successor policy providing comparable protection, and we will give notice and any choices the law requires if a transfer would materially change how information is handled in a way that is less protective. We say this plainly rather than burying it: we do not sell user data as a product, and a future sale of this business may nonetheless include the data the business holds.
Detailed request and diagnostic logs are kept for a short operational window, measured in days rather than months, and then expire. Aggregated traffic figures, which identify nobody, are kept indefinitely. Analytics data is retained by each analytics provider according to the retention setting we have configured with that provider. Email correspondence is kept for as long as it remains relevant. Where the law requires us to keep something longer, we keep it for that period and no longer.
The Site is served over HTTPS, holds no accounts to compromise, and stores no payment details, because it takes none. Infrastructure access is restricted and logged. No system is perfectly secure and we do not claim otherwise. If you find a security problem with this Site, report it to contact@exploit.cc.
EVECS, LLC is based in the United States. Cloudflare serves the Site from data centres worldwide, so a request is normally processed near where it originates, and information may be transferred to and stored in the United States and other countries whose data protection laws differ from those where you live. Where a cross-border transfer requires a safeguard, we rely on the mechanism our provider offers for it.
The Site sets no cookie of its own. Cookies present on this domain come from Google Analytics, delivered first-party as described in section 5, and from Cloudflare's security and delivery layer. Our Cookie Policy names each one, what it does and how long it lasts.
Where the law requires consent before non-essential cookies are set, we will present a consent mechanism and honour the choice made through it.
Depending on where you live, you may have the right to request access to the personal information we hold about you, its correction or deletion, a portable copy, restriction of or objection to processing, and to withdraw consent where processing rests on consent. California residents have the rights to know, delete, correct and opt out of sale or sharing, and not to be treated differently for exercising them.
Make a request by writing to contact@exploit.cc. Be aware of what we actually hold: with no accounts, we have no record keyed to your identity, and for most visitors the only data associated with you is an IP address in a short-lived log and a pseudonymous analytics identifier we cannot connect to a person. We may need enough information to locate a record before we can act on a request, and we will not collect new identifying information solely to make a search possible.
If you are in the EEA, the UK or Switzerland, you may also complain to your local supervisory authority. We would rather you told us first.
Do Not Track was never standardised and browsers send it inconsistently, so like most sites we do not act on it. We do not sell or share personal information, so a Global Privacy Control signal has no sale to stop; where applicable law gives that signal a broader meaning, we treat it as the opt-out request the law says it is.
The Site is a professional security reference and is not directed to children. We do not knowingly collect personal information from anyone under 13, or under 16 where local law sets that threshold for consent-based processing. If you believe a child has provided us personal information, write to contact@exploit.cc and we will delete it.
We may update this policy as the Site changes. When we do, we revise the last-modified date at the top, and for a material change we will give the notice the law requires. Continuing to use the Site after an update takes effect means you accept it, to the extent the law permits. Prior versions are not archived here; if you need to know what the policy said on a particular date, ask us.
Privacy questions and requests go to:
This policy describes our practices. It is not legal advice, and it does not create rights beyond those the law gives you.