Privacy Policy
Effective 15 September 2026. This page describes what Guardian Nexus LLC collects through auditkit.io and the AuditKit products, and what happens to it.
The short version: the website uses a few third-party tags, each of which is off until you allow it. Buying a licence involves Stripe and produces a small customer record on our side. The scanner itself runs on your computer and sends nothing to us. The rest of this page is the detail behind those three sentences.
Who we are
AuditKit is made by Guardian Nexus LLC. We are the controller of the personal data described here. You can reach us about anything on this page at hello@auditkit.io.
The website
auditkit.io is a static site hosted on GitHub Pages and served through GitHub's content delivery network. GitHub records the IP address of every request in its server logs, as any host does. Their handling of those logs is covered by the GitHub Privacy Statement. We do not receive them.
The pages load their typefaces from Google Fonts. Your browser fetches the font files from Google's servers, which means Google sees your IP address and the page you are on. This happens on every page and does not depend on the cookie banner.
Cookies and similar storage
When you first arrive, the site asks what you will allow. Your answer is stored in your browser under the name auditkit_cookie_consent and nothing else runs until you have answered. You can change the answer at any time through the Cookie Preferences link in the footer. If we add a vendor to a category you have already accepted, the banner comes back and asks again. An old answer is not taken as covering a vendor it never mentioned.
There are three categories.
Necessary. The consent record itself. If you start a trial, the confirmation page also stores a flag so that reloading it does not report the same trial twice. Neither is sent anywhere.
Analytics. Google Analytics 4. It records which pages are viewed, how far they are scrolled, which outbound links are clicked, and three events we have named: clicking a trial button, reaching the trial confirmation page, and following a link to the Community Edition repository. It sets the usual _ga cookies. We use this to understand which pages and which advertising bring people to the site and what they do afterwards. Google retains event-level data for two months, its default setting, and aggregate reports for longer. Google's own use of the data is described in How Google uses information from sites that use its services.
Marketing. The Google Ads tag and the Reddit Ads pixel. These exist for one reason: when someone who arrived from an advertisement starts a trial, the network that showed the advertisement is told a trial started, so we can see which advertising is worth paying for. With marketing allowed, the Reddit pixel records each page visit, and clicking a trial button sends Reddit a content-view event. Arriving on the trial confirmation page sends both networks a conversion carrying the Stripe checkout session identifier and the trial value. Neither network receives your email address from the browser.
Starting a trial or buying a licence
Checkout is handled by Stripe on Stripe's own pages. Stripe collects your name, email address, card details and billing address, and is the controller for the payment itself under the Stripe Privacy Policy. We never see your card number.
When a checkout completes, Stripe notifies our licence server. From that notification we keep a customer record consisting of your email address, the Stripe customer identifier, the licence key or licence file issued to you, whether the subscription is a trial or paid, whether it is active, and the dates it was created and renewed. The record lives in a database hosted by Supabase, and the licence server runs on Vercel. Both process data in the United States.
We then email you the licence file. The email goes out through Resend, which handles your address and the message for delivery. Renewals produce a fresh licence file each month, sent the same way. These emails are part of operating the subscription and are not marketing.
At the same time, if you allowed marketing cookies, the licence server reports the trial to Reddit's conversions interface with the same checkout session identifier the pixel used, so the two reports are counted once, plus a SHA-256 hash of your email address. Reddit uses the hash to match the trial to an advertisement click and does not receive the address itself. Google Ads receives nothing from the server; its report comes only from the browser as described above.
We keep the customer record for as long as the subscription exists and afterwards for as long as our accounting and tax obligations require us to hold records of the sale.
The scanner and the desktop application
AuditKit runs on your machine. It reads configuration from your AWS, Azure or GCP accounts using credentials you supply, compares what it finds against the control catalogs, and writes reports, fix scripts and evidence packages to your local disk. None of that leaves your computer for us. Your cloud credentials are used only to call your cloud provider's APIs and are never transmitted to Guardian Nexus. Results you import from ScubaGear, Prowler, Nessus, Trivy or Grype are processed locally in the same way.
The one time the scanner contacts a server that is not your cloud provider is when you run the update command. It asks GitHub for the latest release, which sends GitHub your IP address and the version you are running. It does not do this on its own; it only happens when you run that command.
AuditKit Pro verifies its licence file on your machine against a public key built into the binary. It does not call our licence server to do so. The hardware lock it creates is a hash derived from a network interface address, stored in a file next to the licence, and it stays there.
The Pro scheduler can send alerts to Slack, Microsoft Teams, email, a webhook, syslog or a file. Those go to endpoints you configure, contain whatever scan summary you configure, and pass through nothing of ours.
The desktop application is a local web server. It listens on your own machine and stores its scan history in a local database. It has no account, no login with us, and no telemetry.
Email and support
If you write to hello@auditkit.io we keep the correspondence so that we can answer you and refer back to it if you write again. We do not add support addresses to any mailing list. The only routine email we send is about your licence.
Who else sees data
The providers named above, each for the purpose named: GitHub and Google Fonts for serving the site, Google Analytics for analytics, Google Ads and Reddit for advertising measurement, Stripe for payment, Supabase and Vercel for the licence server, and Resend for licence email. We do not sell personal data and do not share it with anyone else, except where the law requires us to.
Several of these providers are in the United States. If you are in the European Economic Area or the United Kingdom, your data is transferred there when you use the site or buy a licence, under the providers' standard contractual clauses or their participation in the EU-US Data Privacy Framework, as set out in each provider's own policy.
Your rights
Depending on where you live, you may have the right to ask what personal data we hold about you, to have it corrected or deleted, to receive a copy of it, to object to or restrict how we use it, and to complain to a supervisory authority. To exercise any of these, email hello@auditkit.io from the address the request concerns. For the website tags, the practical route is the Cookie Preferences link, which withdraws consent immediately. For advertising, Google and Reddit also offer their own controls in your account settings with them.
The site and products are for businesses and are not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
When we change what we collect or who we share it with, we update this page and the effective date at the top. Where a change adds a new third party to a cookie category, the consent banner will also ask you again the next time you visit.