This Privacy Policy explains how Surface Security, Inc. ("Surface Security," "we," "us," or "our") collects, uses, and shares personal information when you:
- visit surface-security.com (the "Site") or contact us through it;
- deal with us as a customer, prospective customer, partner, or event attendee; or
- use Surface Guard, our free browser extension.
It also explains our role when organizations use the Surface Security enterprise platform (the "Enterprise Platform"). Most data the Enterprise Platform processes is controlled by the organization that uses it, not by us. See Enterprise Platform below.
Summary
- We do not sell personal information or use it for targeted advertising.
- Surface Guard analyzes pages on your device and does not send us a list of the sites you visit. When it flags a page as malicious, it can send us a report about that page and the redirects that led to it, after removing common personal details on your device. Reports are on by default, except in the European Economic Area (EEA) and the United Kingdom, where they are off unless you turn them on. You can change this at any time.
- Organizations run the Enterprise Platform in their own environment, on-premises or in their own cloud tenant, and the browsing data it processes is stored there. We access it only as the organization authorizes, for example for support or to operate a managed deployment. When we host a trial environment for an organization, we process the data in it only on that organization's behalf.
- On the Site, we collect what you enter into our forms and use Microsoft Clarity to understand how the Site is used.
Who We Are
Surface Security, Inc. is a Delaware corporation located at 131 Continental Dr Suite 305, Newark, DE 19713, US. For the Site, Surface Guard, and our business relationships, we are the "controller" (or "business") responsible for your personal information. You can reach our privacy team at legal@surface-security.com.
Information We Collect
You do not have to give us information through our forms or Surface Guard. If you leave out required form fields, we cannot respond to you. Surface Guard works without an account, and its threat reports are optional.
Information you give us
- Forms. When you use our contact, support, trial, or event meeting forms, we collect your first and last name, email address, and, except on the Surface Guard support form, your company or organization. On the contact form, we take your company from your email domain. Some forms also ask for your job title, what you are looking for, your main security challenge, your timeline, how you heard about us, or your preferred meeting times, along with anything you write in the message. The support form also asks which product you need help with, the type of issue, and how much it affects you.
- Communications. Emails, support requests, attachments, and other messages you send us.
- Agreements. When you sign an agreement with us online, we collect your organization's name and address, your name, title, and email address, your typed signature, and the times and IP addresses of your signature and confirmation. We keep a record of the signed documents.
- Business relationships. If you are a customer, trial participant, or partner (or you work for one), we collect business contact details and job titles. We also collect contract, licensing, and billing information needed to provide our services and invoice for them. We do not collect payment card numbers through the Site.
- Events. Information you share with us at conferences and events, such as details from a business card or a badge scan.
Please do not include passwords, secrets, health information, or other sensitive personal information in forms or support requests.
Information collected automatically on the Site
- Technical information. Your IP address, browser and operating system, device type, the page that referred you, the pages you view, and the date and time of your visit. Our hosting provider records this in server logs.
- Analytics. We use Microsoft Clarity to understand how visitors use the Site. Clarity records how you interact with our pages, such as clicks, scrolling, and mouse movement, and can produce heatmaps and session recordings. See Cookies and Similar Technologies for how your choice in our cookie banner affects Clarity.
- Bot protection. Pages with a form load Google reCAPTCHA to block spam and abuse. reCAPTCHA collects information about your device, browser, and interactions with the page and sends it to Google for analysis. This site is protected by reCAPTCHA, and the Google Privacy Policy and Terms of Service apply.
We host our fonts ourselves, so loading the Site does not send your IP address to a font provider.
Information from other sources
We may receive business contact information from event organizers (for example, when your badge is scanned at our booth), from partners and referrals, and from publicly available professional sources such as company websites and professional networking sites.
Surface Guard Browser Extension
Surface Guard protects you from phishing, scams, scareware, and other attacks in your browser. It does not require an account, and it does not ask for your name or email address.
What stays on your device
To detect attacks, Surface Guard examines the pages you visit. The following analysis happens on your device, in your browser:
- page content and structure, such as text, images, links, and forms;
- screenshots of the visible tab, which are analyzed with on-device text recognition;
- web addresses, redirects, and the network requests pages make; and
- signals about how pages behave and how you interact with them, such as signing in, entering information into a form, copying to your clipboard, or responding to a permission prompt.
Surface Guard also stores the following on your device:
- your settings, the sites you have allowlisted, and the sites it has blocked. Each block lifts automatically 30 days after the site was last flagged;
- a record of up to 50 sign-in pages you have recently signed in on, including their address, page title, distinctive words on the page, the sites the page loads content from, layout fingerprints, and how often and when you last signed in. Surface Guard uses this only on your device, to recognize copies of those pages;
- the sites it flagged in the last 24 hours, so it doesn't report the same threat on a site more than once a day, and a count of the threats it has caught;
- the detection rules and text-recognition data it has downloaded, and its install token (described below); and
- reports it has not sent yet, which are discarded after 7 days, and a copy of the last 50 reports it sent.
None of this is sent to us, except as described under What Surface Guard sends to us. All of it is deleted when you uninstall the extension.
What Surface Guard sends to us
Detection rules and updates. Whether or not threat reports are on, Surface Guard downloads updated detection rules from us every few hours. It also downloads language data for on-device text recognition when it needs it. Extension updates come from your browser's extension store. Like any internet request, these downloads reveal your IP address to our servers.
Registration (only when threat reports are on). When threat reports are on, Surface Guard registers with our servers the first time you browse and renews its registration periodically. It sends its version and your browser type. It also sends the results of simple checks that help us detect automated or fake installations: whether the browser appears to be automated or headless, uses software graphics rendering, or reports no languages or plugins, and whether the extension has seen normal page activity. We respond with a random install token. The token is not linked to your name or email address. Surface Guard uses it to authenticate its reports and help us prevent abuse.
Threat reports. In the EEA and the UK, threat reports are off unless you turn them on. Everywhere else, they are on by default. When they are on, Surface Guard sends us a report:
- automatically, when it flags a page as malicious; and
- when you click Report on certain warnings, such as a scareware or full-screen warning. If you report a warning on a device sign-in page (a page that asks you to enter a code to sign in on another device), the report is about the page that sent you there.
A report can include:
- the address of the page and up to 20 redirects that led to it. Before the report leaves your device, usernames and passwords in these addresses are removed. Values that look like email addresses, phone numbers, payment card or bank account numbers, ID numbers, long numbers, or tokens are replaced with placeholders, and very long values are shortened;
- the hostname (not the full address) of the page that linked to it;
- the detection result, including the time (to the nearest minute), the verdict and its confidence, whether the page was blocked or you were warned, and which detectors were triggered;
- fingerprints computed on your device: a similarity hash of the page's code, a visual hash computed from a screenshot of the page, a hash of its site icon, the number of forms, password fields, and frames on the page, and a hash of the outside site its forms send data to. A report can also include a hash of the page title, the brand the page appears to impersonate, the phishing kit it appears to use, the page's certificate issuer, and its language. These fingerprints help us recognize the same attack elsewhere. They are too short to rebuild the page or the screenshot; and
- the extension version and browser type.
Reports are sent with your install token and, like any internet request, from your IP address. You can see the contents of your last 50 reports under What we've sent in the extension's settings.
What Surface Guard does not send
Surface Guard does not send us a list of the sites you visit. Apart from the pages and redirects described above, it sends nothing about the pages you browse. It never sends a copy of any page's text, images, or code, or any screenshot (only the fingerprints described above). It never sends cookies, or the passwords and other information you type into a page's form fields. If a page puts information into its own web address, such as a search term, that address can be included after scrubbing (see Limits you should know about). Surface Guard never asks for your name or email address.
Limits you should know about
- Scrubbing happens automatically and is based on patterns. The addresses in a report could still contain personal information in a format the extension does not recognize, and hostnames are not changed.
- No detection is perfect. A legitimate page may occasionally be flagged and reported.
- If you use Surface Guard on a work device, reports may include your organization's internal web addresses. Surface Guard is intended for personal use, so please check with your organization before installing it on a device it manages.
Your choices
- Turn threat reports on or off at any time with the Threat-intel sharing switch in the extension's settings. Turning reports off discards any reports that have not been sent yet and stops registration. Detection rule downloads continue while the extension is installed.
- Allowlist a site with Trust this site in the Surface Guard toolbar menu, or under Allowlisted sites in the extension's settings. Surface Guard then stops reporting that site and stops phishing, sign-in, ClickFix, scareware, and full-screen warnings about it. Skimmer, HTML-smuggling, navigation-tarpit, and permission-prompt warnings still appear.
- Unblock a site from the toolbar menu or the settings page. A block page also lets you continue to the site for one hour.
- Uninstall Surface Guard at any time through your browser. This stops all communication with our servers and deletes the data the extension stored on your device.
How we use Surface Guard data
We use Surface Guard data to deliver and update protection, improve our detections, and protect our services from abuse. Our security researchers may review threat reports to investigate attacks, abuse, and false positives.
From threat reports we derive indicators, such as malicious web addresses, domains, and phishing-kit fingerprints. Indicators mainly describe attacker infrastructure. A web address or domain can sometimes relate to a person, however, such as the owner of a hacked website. To protect people against phishing, malware, and fraud, we use indicators in Surface Guard and in our enterprise products. We also share them with blocklist operators, security partners, computer emergency response teams, hosting and domain abuse teams, and organizations that use our enterprise products to protect their users. We do not include install tokens, IP addresses, or report times in the indicators we share. We will not try to identify the people who sent the reports behind them.
We do not sell Surface Guard data, and we do not try to identify individual Surface Guard users.
Chrome Web Store Limited Use. Surface Guard's use and transfer of the information it receives adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide and improve Surface Guard's protection against phishing, scams, and malicious websites, to protect our services from abuse, and to protect people against malware, phishing, fraud, and abuse through the indicators described above, including in our enterprise products. We transfer it only:
- to service providers that help us operate Surface Guard;
- to protect against malware, phishing, fraud, or abuse, as described above;
- to comply with the law; or
- in a merger or acquisition, with your prior consent.
We do not use it for advertising or to determine creditworthiness. People read it only for security purposes, such as investigating attacks, abuse, or false positives, or when the law requires it.
Automated assessments. Surface Guard's warnings and blocks are automated assessments about websites, not about you. They do not have legal or similarly significant effects on you, and you can always continue past a warning or unblock a site. If you own a website we flagged, you can ask a person to review our verdict, as described below.
If you own a website we flagged
Our verdicts are automated. If you believe Surface Guard flagged your site in error, contact us through our support page. A person will review it. If we agree it was a mistake, we will remove the site from our detections and indicators, and ask the partners we shared it with to remove it too.
Enterprise Platform
- Deployments in your environment. Organizations deploy the Enterprise Platform in their own environment, either on-premises (including air-gapped networks) or in their own cloud tenant, for example as a managed application. The platform processes data about the organization's users, such as browsing activity, page content, detections, and session forensics, and that data is stored in the organization's deployment. The organization, usually your employer, controls this data and decides how it is used. We access a deployment only as the organization authorizes, for example in a support session it starts or, for managed deployments, to operate and update it as set out in our agreement. When we do, we act as the organization's processor or service provider.
- Hosted trials. When we host a trial environment for an organization, it chooses which users and data to connect to it. We process that data only on the organization's behalf, as its processor or service provider, under our signed agreement with it. We delete trial environments and their data within 30 days after the trial ends, unless the organization signs an agreement to continue. The trial console uses Microsoft Clarity, only with each user's consent, to understand how administrators use it. On-screen content is masked, so Clarity records clicks and navigation, not the data shown.
- Support. When an organization shares data from its deployment with us, for example logs or diagnostic files in a support request, we process it only on the organization's behalf and under our agreement with it.
- Updates. Unless configured to run offline, deployments may contact our servers to download software and detection updates, which reveals the deployment's IP address and version information.
If your browser is protected by an organization's Surface Security deployment or trial, please direct your questions and requests to that organization. We are the controller only for the business contact details of the customer staff we work with, such as administrators and billing contacts, for the technical information deployments send when they check for updates, and for de-identified threat indicators derived under our evaluation agreement.
How We Use Personal Information
If you are in the EEA, the United Kingdom, or Switzerland, we rely on the legal bases shown below.
| Purpose | Examples | Legal basis |
|---|---|---|
| Responding to you | Answering contact and support requests, scheduling meetings, arranging trials | Taking steps at your request before a contract; our legitimate interest in responding to inquiries |
| Providing our services | Delivering trials and subscriptions, providing support, managing licenses, invoicing | Performing our contract with you, or our legitimate interest where the contract is with your employer |
| Providing Surface Guard | Downloading detection rules and updates | Performing our agreement with you to provide the extension |
| Surface Guard threat reports | Registration and threat reports | Your consent in the EEA and the UK; in Switzerland, our legitimate interest, and our users', in protecting people from attacks |
| Sharing threat indicators | Blocklists, security partners, abuse teams, enterprise customers | In the EEA and the UK, the consent you gave to threat reports; in Switzerland, our legitimate interest, and that of the recipients and the public, in network and information security |
| Security and abuse prevention | reCAPTCHA, server logs, install tokens, detecting fraud and misuse | Our legitimate interest in keeping the Site and our services secure |
| Site analytics without cookies | Microsoft Clarity before you accept cookies, or after you decline | Our legitimate interest in understanding how the Site is used |
| Site analytics with cookies | Microsoft Clarity after you click Accept | Your consent |
| Marketing | Product updates and event invitations for business contacts | Our legitimate interest in promoting our products; your consent where the law requires it, such as for individuals in the EEA and UK who are not customers |
| Legal and compliance | Complying with the law, enforcing our terms, handling disputes | Compliance with our legal obligations; our legitimate interest in protecting our rights |
Where we rely on legitimate interests, we have balanced them against your rights, and you can ask us about that balancing.
Your right to object. Where we rely on legitimate interests, including for security logs, analytics, business marketing, and, in Switzerland, Surface Guard threat reports and indicator sharing, you can object at any time on grounds relating to your situation. You can object to direct marketing at any time, for any reason, and we will stop. To stop Surface Guard threat reports, turn off Threat-intel sharing in the extension's settings, which takes effect immediately. For anything else, email legal@surface-security.com.
Cookies and Similar Technologies
- Necessary and preferences. We store your cookie choice, and when we last showed the Site's intro animation, in your browser's local storage.
- Bot protection. On pages with a form, Google reCAPTCHA may set cookies and read information from your device to tell people and bots apart. Google also uses this information for its own purposes.
- Analytics. Microsoft Clarity loads on the pages of the Site, except our agreement-signing pages. Unless you click Accept, we tell Clarity not to use cookies. Without cookies, Clarity still records how pages are used, but it does not connect your visits to each other. If you click Accept, Clarity uses analytics cookies to recognize repeat visits. We tell Clarity not to use advertising cookies. Microsoft processes Clarity data under the Microsoft Privacy Statement.
- No advertising cookies. We do not use advertising cookies, and we tell Clarity not to use its advertising cookies.
You can change your choice at any time with Cookie settings at the bottom of our pages. You can also block or delete cookies in your browser, although some features, such as reCAPTCHA on our forms, may stop working. Because we do not sell personal information or use it for targeted advertising, our Site does not change its behavior in response to Global Privacy Control or "Do Not Track" signals. Use Cookie settings to control analytics cookies.
How We Share Personal Information
- Service providers. Companies that process personal information on our behalf and only for our purposes, under contracts with us. Currently these are Microsoft (Azure hosting, content delivery, form processing, and the servers Surface Guard connects to) and Twilio SendGrid (delivering form submissions to our inbox), along with Microsoft 365 (our email and productivity provider) and our customer relationship management provider.
- Microsoft and Google. Microsoft (for Clarity) and Google (for reCAPTCHA) receive the information described above and also use it for their own purposes under their own privacy policies.
- Threat intelligence recipients. Indicators about malicious websites, as described under How we use Surface Guard data.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy. We will ask for your consent before transferring Surface Guard data in such a transaction.
- Legal and safety. When required by law or legal process, or when needed to protect the rights, property, or safety of Surface Security, our users, or others. For Surface Guard data, we do this only as the Chrome Web Store Limited Use commitments above allow.
- With your consent or at your direction.
We may also share de-identified or aggregated information that cannot reasonably be linked to you. We keep such information in de-identified form, we do not try to re-identify it, and we ask recipients not to either.
International Transfers
We are based in the United States. When you use the Site or Surface Guard, you send information directly to us in the United States, and we and our service providers process it there. When we disclose personal information about people in the EEA, the United Kingdom, or Switzerland to others outside those regions, we rely on one of these mechanisms:
- the recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions; or
- the European Commission's Standard Contractual Clauses, with the UK Addendum and Swiss amendments where they apply; or
- another mechanism permitted by applicable law, such as for threat indicators we share with security organizations to protect people against attacks.
You can ask us for a copy of the relevant safeguards.
How Long We Keep Personal Information
We keep personal information only as long as we need it for the purposes described in this policy:
- Form submissions and communications: while we are responding to you or have an ongoing business relationship, then for a limited period for record-keeping.
- Customer and contract records: for the length of the relationship, and afterward as long as legal, tax, and accounting requirements demand.
- Hosted trial data: until 30 days after the trial ends, as set out in our agreement with the organization.
- Signed agreements: for as long as the agreement and any related legal obligations last.
- Server and security logs: for a limited period, unless we need them to investigate a security incident or abuse.
- Clarity analytics: Microsoft keeps session recordings for about 30 days and aggregated analytics for up to about 13 months under Clarity's standard settings.
- Surface Guard: see What stays on your device for data kept on your device. On our servers, we keep install registrations while they are being renewed. We keep threat reports and the indicators derived from them as long as they are useful for threat research and detection.
We may keep information longer when the law requires it or when we need it to resolve disputes or enforce our agreements.
Security
We use appropriate technical and organizational measures to protect personal information, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Your Rights
EEA, United Kingdom, and Switzerland
You have the right to:
- access the personal information we hold about you and get a copy of it;
- correct inaccurate information;
- have your information deleted;
- restrict our processing, or object to it as described in Your right to object under How We Use Personal Information;
- receive your information in a portable format; and
- withdraw your consent at any time, where we rely on consent. This does not affect processing that already took place.
You also have the right to complain to the data protection supervisory authority where you live or work, such as the Information Commissioner's Office in the UK or the Federal Data Protection and Information Commissioner in Switzerland.
United States
Depending on your state of residence, you may have the right to:
- know what personal information we have collected about you and access it;
- correct inaccurate information;
- delete your information; and
- opt out of the sale of personal information, targeted advertising, and certain profiling.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use it for targeted advertising or profiling. We do not intentionally collect sensitive personal information. If we receive it incidentally, for example in a web address or a support file, we use it only to provide our services and for security. We will not discriminate against you for exercising your rights.
In the past 12 months we have collected the following categories of personal information:
| Category | Examples | Sources | Purposes | Disclosed to | Kept for |
|---|---|---|---|---|---|
| Identifiers | Name, email address, IP address, Surface Guard install token | You; your browser | Responding to you, providing services, security | Service providers; Microsoft and Google (Clarity and reCAPTCHA) | As described under How Long We Keep Personal Information |
| Professional information | Company, job title | You; event organizers | Responding to you, providing services, marketing | Service providers | While we have a business relationship, then a limited period |
| Customer records | Billing contacts, trial, license, and contract records | You; your organization | Providing services, invoicing, legal compliance | Service providers | As long as legal, tax, and accounting requirements demand |
| Internet activity | Site interactions, session recordings, Surface Guard threat reports | Your browser | Analytics, security, protecting people from attacks | Service providers; Microsoft (Clarity); threat intelligence recipients (indicators only) | As described under How Long We Keep Personal Information |
| Audio or visual information | Screenshots or files you attach to support requests | You | Providing support | Service providers | While we are responding, then a limited period |
| Approximate location | Location derived from IP address | Your browser | Security, analytics | Service providers; Microsoft and Google | As described under How Long We Keep Personal Information |
We do not draw inferences about you to create a profile.
How to make a request
Email legal@surface-security.com. We will confirm that we received your request within 10 business days, and verify it by matching the information you give us with the information we hold. You can use an authorized agent, but we may ask for proof that you authorized them and ask you to confirm your identity directly. We respond within one month in the EEA, the UK, and Switzerland, and within 45 days in the United States. In both cases we may extend the deadline where the law allows.
If we deny your request, you can appeal within 45 days of our decision by emailing us with "Appeal" in the subject line. We will respond in writing within 45 days, or 60 days where state law allows, and explain our reasons. If you are not satisfied, you can contact your state attorney general.
Surface Guard data. Surface Guard reports are not linked to your name or email address. To access or delete reports sent from your browser, send us the report IDs shown under What we've sent in the extension's settings. Only your last 50 reports are listed, and the list is deleted when you uninstall, so note the IDs first.
If your organization uses the Enterprise Platform, please direct requests about that data to your organization.
Children
The Site and Surface Guard are not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete any information we can link to them.
Third-Party Links
The Site links to websites we do not control, such as browser extension stores and social media. Their own privacy policies apply.
Changes to This Policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top. If we make a material change, we will give notice on the Site and, where appropriate, in Surface Guard, before the change takes effect. We will not make a material change to the information Surface Guard sends us, or use information already collected in a materially different way, without first asking for your consent in the extension.
Contact Us
If you have questions or requests about this policy or our privacy practices, contact our privacy team:
Surface Security, Inc.
131 Continental Dr Suite 305, Newark, DE 19713, US
Email: legal@surface-security.com