Privacy Policy

Last updated: 23 August 2026

This Privacy Policy explains how information is handled when you use A-SDF Secure Design Review through threatmodeling.in.

A-SDF is currently operated and maintained by an individual developer/operator. This Privacy Policy describes the current data handling practices of the Service.

1. What A-SDF Does

A-SDF is an AI-assisted secure design review platform. It helps users analyse application designs, integrations, architecture diagrams, and related security information.

Depending on the functionality being used, the Service may generate security reviews, abuse cases, preventive controls, detective controls, architecture observations, and related security recommendations.

2. Information You Provide

When using A-SDF, you may provide information such as:

  • Application or system descriptions.
  • Source and destination system information.
  • Integration mechanisms such as API, SFTP, middleware, database connection, or similar mechanisms.
  • Data type and data classification.
  • Architecture and integration information.
  • Architecture diagrams submitted for analysis.
  • Other information necessary to perform a requested security design review.

3. Why We Process Your Information

Information submitted to A-SDF is processed to provide the security review or other functionality that you request.

  • Analysing submitted security design information.
  • Identifying potential abuse cases and security risks.
  • Generating preventive and detective security controls.
  • Analysing architecture diagrams and identifying interfaces where supported.
  • Generating and displaying security review reports.
  • Maintaining review history where that functionality is enabled.
  • Providing report viewing and download functionality.
  • Maintaining the security and operation of the Service.

4. AI Training and Model Improvement

A-SDF does not use your submitted security review information to train or enhance an A-SDF-owned artificial intelligence model.

Your application descriptions, integration details, architecture information, architecture diagrams, data classifications, and generated security reports are used to provide the Service you requested.

5. AI Processing

A-SDF currently uses OpenAI’s gpt-4.1-mini for applicable AI-assisted security review processing.

Information necessary to generate your requested review may therefore be transmitted from A-SDF to OpenAI’s API for processing.

OpenAI states that API inputs and outputs are not used to train or improve its models by default for API customers.

6. Third-Party Processing

A-SDF may use third-party infrastructure and service providers that are necessary to operate the Service.

This currently includes AI processing through OpenAI’s API and website and infrastructure services required to operate the platform.

7. Access to Your Reports

A-SDF does not routinely access or manually review individual user security reports.

Reports are generated and presented through the Service for the account that requested the review.

This does not constitute a guarantee that no infrastructure administrator, hosting provider, service provider, or authorized technical personnel could ever have access to information where such access is technically necessary for security, troubleshooting, maintenance, legal compliance, or service operation.

8. Information We May Store

Information Purpose
Account information Authentication and account operation.
Security review inputs Processing the requested security review.
Generated reports Displaying results and providing applicable review-history functionality.
Technical information Security, troubleshooting, reliability, and operation of the Service.

9. We Do Not Sell Your Security Review Information

A-SDF does not sell your submitted security review information or generated security reports to third parties.

Information may nevertheless be processed by technical service providers necessary to operate the Service, including hosting, infrastructure, authentication, security, or AI-processing providers.

10. Security

Reasonable technical and organizational measures are used to protect information processed by A-SDF.

These measures may include authentication, access controls, secure transport, server-side processing, user-scoped storage, protection of application secrets, and other security measures appropriate to the Service.

Important:

No internet-based service can guarantee absolute security. You should therefore avoid submitting passwords, private keys, API keys, access tokens, production credentials, or other secrets.

11. Architecture Diagrams

Architecture diagrams submitted to the Service may contain information about applications, systems, integrations, users, data flows, infrastructure, and security controls.

Such diagrams are processed for the architecture analysis and security review functionality requested by the user.

Users should remove unnecessary confidential information, credentials, secrets, or personal information before uploading an architecture diagram.

12. Review History and Reports

Where review-history functionality is available, A-SDF may store generated reports associated with the user’s account so that the user can view previously generated reviews.

Review history is not intended to make reports publicly accessible.

13. Cookies and Technical Data

A-SDF may use cookies and similar technical mechanisms necessary for authentication, sessions, security, preferences, and basic operation of the website.

The hosting infrastructure may also process technical information such as IP address, browser information, timestamps, and server logs for security and operational purposes.

14. Your Responsibility

You are responsible for ensuring that you have the necessary authority to submit information to A-SDF.

If you submit information belonging to your employer, customer, vendor, or another organization, you should ensure that your organization’s policies and contractual requirements permit such processing.

15. Data Deletion

Where the Service provides a report deletion function, you may use it to remove eligible reports from your account.

Deletion from A-SDF does not necessarily cause immediate deletion from third-party infrastructure that may have processed the information, where applicable retention or security obligations require temporary retention.

16. Changes to This Privacy Policy

This Privacy Policy may be updated when the Service, technology, third-party providers, or applicable requirements change.

The “Last updated” date at the top of this page identifies the latest revision.

17. Contact

For privacy questions or requests relating to A-SDF Secure Design Review, please use the contact method made available on the website.

threatmodeling.in

Please do not submit passwords, private keys, API keys, access tokens, or production secrets to A-SDF.

A-SDF is a security design analysis tool and should not be used as a repository for credentials or secrets.

Scroll to Top