/ Privacy policy

Clear disclosure for a public security-tooling site.

Last updated: September 17, 2026.

Overview

Ahlyx Labs is an open-source security tools and research portfolio. This policy describes the technical data flows of the website and its tools. It is an operational disclosure, not a promise that every provider or visitor is subject to a particular privacy-law regime.

Website infrastructure

Ahlyx Labs uses Cloudflare for DNS and the public web edge, Vercel for the static frontend and web analytics products, and Render for the Go API. Normal HTTP requests necessarily provide relevant infrastructure providers with ordinary technical request information, such as IP address, user agent, time, and requested resource, so they can deliver, secure, and troubleshoot the service. Ahlyx Labs does not claim that these providers maintain no access or security logs.

Analytics and consent

Vercel Analytics and Speed Insights are loaded to understand aggregate site performance and use. Google Analytics 4 is not loaded until the visitor accepts the site banner. The browser remembers that choice in localStorage under analytics_consent. Provider processing is governed by the applicable provider terms and privacy materials.

Browser storage

The enrichment page may store recent IP, domain, and file-hash searches in the visitor's own browser under searchHistory. Full URL searches are not persisted there. Relay credentials are held only in page memory long enough to construct a WebSocket and are not stored in localStorage or placed in query strings.

Threat-intelligence submissions

Do not submit passwords, API keys, private invitation/reset links, signed URLs, recovery codes, or other secrets. To perform an enrichment request, Ahlyx Labs sends the submitted indicator to relevant third-party sources. This can include AbuseIPDB, VirusTotal, IPinfo, AlienVault OTX, Google Safe Browsing, MalwareBazaar, CIRCL HashLookup, and public DNS, WHOIS, or TLS lookups, depending on the indicator type. An IP address, domain, URL, or hash is therefore not appropriate for secret material.

URLScan

URLScan active submission is optional. It occurs only when the site operator has enabled it and the visitor explicitly selects the URLScan option. The application is configured to use unlisted or private visibility; public visibility is rejected. When the operator flag is false, no active URLScan submission occurs.

Temporary enrichment cache and operational telemetry

To reduce repeated third-party lookups, submitted indicators and enrichment results may be held temporarily in the application's in-memory TTL cache. Fully successful results may be cached for up to one hour; partial results may be cached for up to 15 minutes; total source failures are not cached. This process-memory cache is separate from the aggregate query-telemetry database and is cleared when the application process restarts.

Ahlyx Labs' own query telemetry intentionally records aggregate fields such as tool, indicator type, verdict, source count, and response time. It does not store the submitted IP address, domain, URL, or hash in that query-telemetry database. This does not prevent Cloudflare, Vercel, Render, or third-party intelligence sources from maintaining ordinary access or security logs under their own systems and policies. No fixed retention period is promised here because it is not technically enforced by this application.

PCAP Agent

In local mode, the browser connects directly to the local PCAP Agent and packet-analysis metadata does not transit the Ahlyx Labs relay. Relay mode is explicit and optional. In relay mode, source/destination address metadata, ports/protocol, DNS metadata, MAC observations, security alerts, and aggregate statistics may traverse the Ahlyx Labs relay. Raw packet payloads are not sent through the relay.

Hardware Dashboard

The Hardware Dashboard displays aggregate telemetry from the Ahlyx Labs cloud backend. It does not inspect or display telemetry from a visitor's personal machine.

Contact and changes

Questions about this policy can be sent to [email protected]. Security reports and official-channel verification guidance are available at ahlyxlabs.com/security and security.txt. Material changes to this page will be reflected in its last-updated date.