NetworkPilot is operated by PilotSuite LLC. These policies are written for the NetworkPilot service and its authorized security assessment workflow.
Scope and operator
This Privacy Policy explains how PilotSuite LLC, doing business as NetworkPilot ("NetworkPilot," "we," "us," or "our"), handles personal information when you visit networkpilot.io, create a workspace, run authorized diagnostics or security assessments, configure monitoring, purchase a subscription, or contact us.
This policy applies to NetworkPilot. It does not govern a third-party service under that provider's own privacy policy.
Information we collect
We collect the following categories of information:
- Account and contact information: name, email address, authentication identifiers, workspace identity, and communications with us.
- Authorized asset information: domain names, public IP addresses, labels, DNS verification records, authorization attestations, verification status, and relevant timestamps.
- Assessment and evidence information: selected scan profiles and port ranges, scope snapshots, public DNS and registration information, observed services, TLS and web-security signals, findings, scores, remediation guidance, scanner activity, report exports, and evidence integrity digests.
- Monitoring information: schedules, status, prior public-exposure snapshots, detected changes, run history, and operational errors.
- Billing information: subscription plan, price, status, renewal and cancellation state, and Stripe customer, subscription, and event identifiers. Stripe processes payment-card details; NetworkPilot does not store full card numbers.
- Technical and security information: IP address, browser or device information, request metadata, authentication events, service logs, and signals used to protect the platform, enforce limits, and investigate abuse.
Where information comes from
We receive information directly from you, from administrators who invite or manage you, from our authentication and billing providers, and from the systems you deliberately authorize NetworkPilot to assess.
Network diagnostics also use public sources such as DNS, RDAP or registration services, certificate endpoints, and publicly reachable services on the selected asset. Those providers and target systems may receive the queried hostname or IP address and ordinary network request metadata as a necessary part of performing the requested check.
How we use information
We use information to:
- authenticate users and operate secured workspaces;
- verify scope and run the diagnostics, scans, and monitors you request;
- generate reports, evidence bundles, and change history;
- deliver focused vendor remediation briefs at your direction and retain vendor acknowledgements or implementation evidence submitted through a scoped response link;
- administer subscriptions, invoices, entitlements, and support;
- enforce plan limits and the authorized-use requirements in our Terms;
- protect NetworkPilot, customers, targets, and the public from fraud, misuse, and security incidents;
- debug, maintain, and improve service reliability and safety; and
- comply with law, resolve disputes, and enforce agreements.
Where applicable, our legal bases include performing our contract with you, our legitimate interests in operating and securing the service, your consent, and compliance with legal obligations.
When we disclose information
We disclose information only as reasonably necessary for the following purposes:
- Service providers: Clerk for authentication, Vercel for hosting and delivery, Neon for managed database infrastructure, Stripe for billing and customer self-service, and SendGrid for transactional service communications.
- Your organization:workspace owners or authorized administrators when you use NetworkPilot on an organization's behalf.
- Safety and legal process: when we reasonably believe disclosure is necessary to comply with law, protect rights or safety, investigate fraud or abuse, or respond to valid legal process.
- Business transactions: in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and continued protection.
- At your direction: when you export or share a report or otherwise ask us to disclose information.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use customer scan evidence to train advertising or generative-AI models.
Retention and deletion
We retain account, authorized-asset, scan, monitoring, and evidence information for as long as reasonably necessary to provide the service and the history available under your plan. We may retain billing, authorization, security, abuse-prevention, dispute, and transaction records longer when reasonably necessary for legal, audit, fraud-prevention, and enforcement purposes.
When information is no longer needed, we delete or de-identify it using reasonable measures. Deletion from backups and provider logs may take additional time. You may delete an account from NetworkPilot mobile Settings or use our web account-deletion request. Legal and security exceptions may apply.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated access, owner-scoped records, transport encryption, encrypted provider secrets, restrictive browser security headers, signed Stripe webhooks, destination validation, rate limits, and abuse controls.
No method of storage or transmission is completely secure. You are responsible for protecting account credentials, controlling report exports, and promptly notifying us if you suspect unauthorized access.
Organizations, MSPs, and customer data
If an organization or MSP uses NetworkPilot for a client, that organization determines the authorized scope and purpose of the assessment and is responsible for required notices, permissions, and lawful instructions. NetworkPilot processes the resulting workspace data to provide the service and protect the platform.
Do not submit passwords, private keys, payment-card data, protected health information, or other regulated content to target labels, scan fields, or reports. NetworkPilot is not designed as a repository for those data types and does not provide HIPAA business-associate services.
Your privacy rights
Depending on your location and applicable law, you may have the right to request access, correction, deletion, portability, restriction, or an explanation of our processing. You may also object to certain processing or withdraw consent where consent is the legal basis. NetworkPilot will not discriminate against you for exercising a privacy right.
Account deletion is available from NetworkPilot mobile Settings. If you cannot access the app, use the account-deletion page. Other privacy requests may be sent to pilotsuite.admin@pilotsuite.design. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, subject to appropriate verification.
You may update subscription billing details through the Stripe Customer Portal and account identity information through the authentication interface. You may also complain to your local data protection authority where that right applies.
International use
NetworkPilot is operated from the United States. If you access the service from another country, information may be processed in the United States or other locations where our service providers operate. Where required, we rely on lawful transfer mechanisms and provider commitments intended to protect transferred information.
Children
NetworkPilot is a professional security service and is not directed to children. You must be at least 18 years old to create an account or use active scanning features. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information to the service.
Changes to this policy
We may update this policy as NetworkPilot, our providers, or applicable requirements change. We will post the revised policy with a new effective date and provide additional notice when a change is material and required by law. Prior versions may be requested by contacting us.
Contact us
Questions, privacy requests, and concerns may be sent to:
PilotSuite LLC — NetworkPilot Privacy
Reno, Nevada, United States
pilotsuite.admin@pilotsuite.design
For service rules, billing terms, and authorized-use requirements, review our Terms of Service.