Privacy Policy
Privacy is not a footnote for us — it is part of what we teach. This policy explains what this website collects, why, how long we keep it, and what you can do about it.
1.Who is responsible for your data
| Website | cyberdilmeth.com |
| Data controller | The Publisher, CyberDilmeth |
| Location | Colombo, Sri Lanka |
| Privacy contact | [email protected] |
| General contact | [email protected] |
CyberDilmeth is an independent, brand-led publication. Articles are attributed to named contributors and technical reviewers rather than to a single owner. This is a deliberate editorial choice: it keeps the focus on verifiable expertise and transparent standards rather than on one person's reputation.
That choice does not reduce our accountability. The individual responsible for this site as data controller will disclose their identity on request to any data subject exercising their rights, and to any supervisory authority. Write to [email protected] and we will respond.
2.Scope
This policy covers cyberdilmeth.com and its subdomains.
It does not cover external websites we link to. When you follow a link to a vendor advisory, a CISA page, or any other third-party site, that site's own privacy policy applies. We have no control over, and accept no responsibility for, how those sites handle your data.
3.What we collect at a glance
Collected automatically
IP address, browser and device type, pages requested and timestamps — written to server and security logs so the site stays online and attacks get blocked.
Information you give us
Your email address if you subscribe to the newsletter, and whatever you write if you email us. We never ask for your name.
Only with your consent
Aggregated analytics showing which articles get read, and cookies used by our advertising partner. Reject the banner and neither is set.
| What | Lawful basis | How long |
|---|---|---|
| Server and security logs | Legitimate interests | Up to 30 days |
| Your cookie consent choice | Legal obligation / consent | Up to 12 months |
| Newsletter subscription | Consent | Until you unsubscribe |
| Analytics | Consent | Up to 14 months |
| Advertising | Consent | Set by our advertising partner |
We do not sell, rent or trade your personal data. This site does carry advertising, and advertising cookies are set only if you consent to them. Advertisers never receive our subscriber list, and they have no influence over what we publish.
4.What we collect automatically
4.1 Server and security logs
Like every website, our server records requests made to it. This typically includes your IP address, the page requested, the time, your browser and operating system version, and the page you arrived from.
Our hosting is provided by Namecheap, Inc., which processes this data on our behalf in order to serve the website.
We use these logs only to operate the site, diagnose faults, and identify malicious traffic. We do not use them to identify you personally or to build a profile of you.
4.2 Security and content delivery (Cloudflare)
We use Cloudflare, Inc. as a content delivery network and web application firewall. Traffic to this site passes through Cloudflare's network before reaching our server. Cloudflare processes your IP address and request metadata in order to filter attacks, mitigate denial-of-service traffic, and serve pages quickly.
Cloudflare sets a small number of strictly necessary cookies for this purpose. These are listed in our Cookie Notice.
4.3 Application firewall
We run a security plugin that inspects requests for attack patterns and may temporarily block IP addresses that behave maliciously. It records IP addresses and request details associated with blocked or suspicious activity.
If you are blocked in error, contact us and we will look into it.
5.Information you give us
5.1 Newsletter
Our newsletter is delivered using Mailchimp (Intuit Inc.) and uses double opt-in. You enter your email address; we send you a confirmation email; you are only subscribed if you click the link in it. This protects you from being signed up by someone else and gives us a record that consent was genuinely given.
We store your email address, the date and time you confirmed, and which page you subscribed from. We do not require your name.
Mailchimp also records standard delivery and engagement events — whether an email was delivered, opened, or a link clicked. We use this only to understand which content is worth writing more of, and to stop sending to addresses that bounce.
Every email we send contains a one-click unsubscribe link. When you unsubscribe we retain a minimal suppression record — essentially a note that your address has opted out — so that we do not accidentally email you again. You can ask us to delete that too.
5.2 Contacting us
If you email us, we receive your email address and whatever you write. We use it to respond to you and nothing else. We will never add you to a mailing list because you contacted us.
We keep correspondence for up to 24 months after our last exchange, then delete it.
5.3 Comments
Reader comments are disabled on this site. We do not operate a comment system and do not collect any data through one. If we introduce comments in future, this policy will be updated before we do so.
6.Our interactive tools — please read this
This is the part of the policy that matters most, because it is where a security site earns or loses your trust.
6.1 Tools that never transmit anything
The following tools run entirely inside your web browser. The values you type are processed by JavaScript on your own device. They are never sent to our servers, never stored, and never logged:
- Password Generator
- Password Analyzer / strength checker
- Password Policy Checker
If you disconnect from the internet after the page loads, these tools still work. That is the test, and you are welcome to verify it with your browser's developer tools — we would rather you checked than took our word for it.
6.2 The Password Breach Check — an honest explanation
The breach check is different, and we will not pretend otherwise.
To tell you whether a password has appeared in a known data breach, we have to compare it against a breach corpus that is far too large to load into your browser. We use a technique called k-anonymity so that this can be done without ever revealing your password.
What actually happens when you check a password
- Your browser calculates a SHA-1 hash of your password on your device.
- Your browser sends only the first five characters of that hash to the Pwned Passwords API operated by Have I Been Pwned.
- That service returns a list of several hundred hash suffixes beginning with those five characters.
- Your browser compares the rest of your hash against that list locally and shows you the result.
Your password never leaves your device. Neither does the full hash of it.
The five characters we send are shared by many thousands of different passwords, so they cannot identify yours. The service on the other end cannot know which password you were checking, and by design does not log the queries.
Your IP address is, unavoidably, visible to that service in the course of making the request — as it would be for any web request. If you would prefer not to make that request at all, simply do not use the breach check; every other password tool on the site works without it.
6.3 No analytics on tool inputs — ever
We deliberately exclude all tool input fields from analytics, session recording, and error reporting. No script on our tool pages captures what you type into them.
This is a design rule we hold ourselves to, not a best-effort intention. A security tool that quietly leaks the secrets it is meant to protect would be worse than no tool at all.
7.Cookies, analytics and advertising
We use a consent management platform to ask for your permission before setting any cookie that is not strictly necessary.
- Strictly necessary cookies are set without consent, because the site cannot function securely without them. These relate to security filtering and to remembering your cookie choice itself.
- All other categories are set only if you accept them, and you can change your mind at any time using the consent icon in the corner of the page.
Google Analytics
We use Google Analytics 4 to understand which articles are read and which are ignored, so that we write more of what is useful.
Analytics runs only if you accept the Analytical cookie category. If you reject it, or dismiss the banner without accepting, no Analytics script loads and no Analytics cookies are set.
Where it is enabled, Google Analytics records pages viewed, approximate location derived from your IP address, device and browser type, referring site, and basic interaction events. Google Analytics 4 does not store IP addresses. We have configured it so that:
- Google Signals and advertising personalisation features are disabled
- Data is not shared with Google for advertising purposes
- Data retention is set to the shortest useful period (14 months)
- Tool input fields are excluded from all measurement (see section 6.3)
Google acts as our data processor for this. You can also opt out independently using Google's browser add-on at tools.google.com/dlpage/gaoptout.
Advertising
This site carries advertising. Advertising is part of what keeps the guidance here free to read, and we would rather say so plainly than bury it three levels down.
Advertising cookies are set only if you accept the Advertisement category. If you reject it, you may still see ads, but they are non-personalised — chosen from the content of the page rather than from anything about you.
Advertising on this site is served by [AD NETWORK], which may collect your IP address, device and browser information, and the pages you view, in order to select, deliver and measure ads. That partner determines its own purposes for this processing and acts under its own privacy policy, which we link from the Cookie Notice.
No advertising runs on our tool pages. The password tools handle sensitive input. We do not allow third-party scripts anywhere near those fields, and no ad network is permitted on them.
Advertising buys space, never coverage. Advertisers get no influence over what we publish, no advance sight of articles or advisories, and no placement in threat intelligence. Anything sponsored is labelled as sponsored, every time.
Full details, including the specific cookies used and how to withdraw consent, are in our Cookie Notice.
8.Threat intelligence content
Our Threat Intelligence section is compiled from public sources including the CISA Known Exploited Vulnerabilities catalog, the National Vulnerability Database, and EPSS data published by FIRST.org.
This content describes software vulnerabilities. It contains no personal information about you, and reading it does not tell us anything about you beyond the ordinary server log described in section 4.1.
9.Who else processes your data
We keep this list deliberately short. Each service is used because it is necessary, not because it is convenient.
| Who | What they do | What they see |
|---|---|---|
| Namecheap, Inc. (USA) | Hosts the website | Server logs; anything stored on the site |
| Cloudflare, Inc. (USA) | CDN, DDoS protection, web application firewall | IP address, request metadata |
| Intuit Inc. / Mailchimp (USA) | Delivers the newsletter | Email address, consent record, delivery and engagement events |
| Google LLC (USA) | Website analytics, only with your consent | Pageviews, approximate location, device and browser data |
| [AD NETWORK] | Serves advertising, only with your consent | IP address, device and browser data, pages viewed, ad interactions |
| Have I Been Pwned | Answers breach-check queries | A five-character hash prefix and your IP address, only when you use that tool |
We do not permit any of these parties to use your data for their own marketing purposes.
10.International transfers
We are based in Sri Lanka. All the providers listed above are based in, or process data in, the United States. This means your data may be processed outside Sri Lanka and outside your own country.
Where that happens we rely on the safeguards those providers offer — including Standard Contractual Clauses, the EU–US Data Privacy Framework where the provider is certified, and equivalent binding commitments — and we keep the amount of data transferred to the minimum the service needs to work.
If you would like details of the safeguards applying to a specific provider, ask us and we will tell you.
11.How long we keep things
| Data | Retention |
|---|---|
| Server and security logs | Up to 30 days |
| Cookie consent records | Up to 12 months, then you are asked again |
| Email correspondence | Up to 24 months after our last exchange |
| Confirmed newsletter subscribers | Until you unsubscribe |
| Unconfirmed newsletter sign-ups | Deleted after 30 days if never confirmed |
| Unsubscribe suppression records | Kept unless you ask us to delete them, solely to avoid contacting you again |
| Google Analytics data | 14 months |
| Advertising cookies | As set by our advertising partner — see the Cookie Notice |
When a retention period expires we delete the data or irreversibly anonymise it.
12.Your rights
Depending on where you live, you have rights over your personal data. We extend the following rights to everyone who contacts us, regardless of location — it is simpler, and it is the right thing to do.
You may ask us to:
- Access — tell you what data we hold about you and give you a copy
- Rectify — correct anything inaccurate
- Erase — delete your data, where we have no overriding reason to keep it
- Restrict — pause our use of your data while a dispute is resolved
- Port — provide your data in a structured, machine-readable format
- Object — object to processing we carry out on the basis of legitimate interests
- Withdraw consent — at any time, without giving a reason, and without affecting anything done before you withdrew it
To exercise any of these, email [email protected]. We will respond within 30 days. We do not charge for this. We may need to ask a question or two to confirm you are the person the data relates to — we will ask for the least information necessary to do that.
Given how little we collect, the honest answer to most access requests is likely to be "your email address and the date you subscribed." We will say so plainly rather than sending you a document that pretends otherwise.
Complaints
If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority: the Data Protection Authority of Sri Lanka, or the data protection regulator in your own country if you are elsewhere.
13.Children
This site is intended for a general adult audience and is not directed at children under 16. We do not knowingly collect personal data from children.
If you believe a child has provided us with personal information, contact us and we will delete it.
14.How we protect your data
We practise what we publish. Measures in place include:
- HTTPS enforced across the entire site
- A web application firewall and content delivery network in front of the origin server
- Multi-factor authentication on all administrative accounts
- Minimal third-party code, reviewed before installation
- Encrypted, access-controlled backups
- A written incident response plan, including breach notification
No system is completely secure, and we will not claim otherwise. If a breach affecting personal data occurs, we will notify the relevant authority within the required timeframe and tell affected individuals directly where there is a significant risk to them. We will also say what happened publicly, because concealing an incident on a security education site would be indefensible.
If you have found a security issue in this website, please report it to [email protected]. We welcome good-faith research and will not pursue action against researchers who follow our Responsible Disclosure policy.
15.Changes to this policy
We will update this policy when our practices change. The version number and "last updated" date at the top always reflect the current version.
If we make a change that materially affects your rights or how we use your data, we will say so prominently on the site rather than quietly editing the page. A "last updated" date that does not reflect a real review is a trust violation, and we treat it as one.
16.Contact
| Purpose | Address |
|---|---|
| Privacy, data requests, complaints | [email protected] |
| Security vulnerability reports | [email protected] |
| Editorial corrections | [email protected] |
| Contributing to CyberDilmeth | [email protected] |
| Everything else | [email protected] |
CyberDilmeth — Privacy Policy v1.0, 24 July 2026.
See also: Cookie Notice · Terms of Use · Responsible Disclosure