Updated April 23, 2026
Erbab.dev takes data privacy seriously. This privacy policy explains who we are, how we collect, share and use Personal Information, and how you can exercise your privacy rights.
We recommend that you read this Privacy Policy in full to ensure you are fully informed. However, to make it easier for you to review the parts of this Privacy Policy that apply to you, we have divided up the document into sections that are specifically applicable to Clients (Section 2), Targets (Section 3), and Visitors (Section 4). Sections 1 and 5 are applicable to everyone.
If you have any questions or concerns about our use of your Personal Information, contact us using the contact details provided at the end of Section 5.
To the extent we provide you with notice of different or additional privacy policies, those policies will
govern such interactions.
Erbab.dev is an AI-powered application security (AppSec) platform ("we," "us," "our," and "Erbab.dev"). Our Service enables software development teams to identify, prioritize, and remediate security vulnerabilities in code, dependencies, and configurations through automated scanning, AI-assisted fix suggestions, and compliance reporting.
In this privacy policy, these terms have the following meanings:
"Affiliate" means an entity that directly or indirectly Controls, is Controlled by or is under common Control with an entity.
"Repository" means a version-controlled code repository connected to the Service by a Client for the purpose of security scanning and vulnerability analysis.
"Control" means an ownership, voting or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question. The term "Controlled" shall be construed accordingly.
"Erbab.dev Site(s)" has the meaning given to it in our Terms of Service.
"Client" means any person or entity that is registered with us to use the Service.
"Personal Information" means any information that identifies or can be used to identify an individual directly or indirectly. Examples of Personal Information include, but are not limited to, first and last name, date of birth, email address, gender, occupation, or other demographic information.
Service has the meaning given to it in our Terms of Service.
"Visitor" means, depending on the context, any person who visits any of our Erbab.dev Sites, offices, or otherwise engages with us at our events or in connection with our marketing or recruitment activities.
"you" and "your" means, depending on the context, either a Client or a Visitor.
This section applies to the Personal Information we collect and process from a Client or potential Client through the provision of the Service. If you are not a Client, the Visitors or Targets section of this policy may be more applicable to you and your data. In this section, "you" and "your" refer to Clients and potential Clients.
The Personal Information that we collect depends on the context of your interactions with Erbab.dev, your Erbab.dev account settings, the products and features you use, your location, and applicable law. However, the Personal Information we collect broadly falls into the following categories:
This information may include
When you use the Service, we and our third-party partners may automatically collect or receive certain information about your device and usage of the Service (collectively Service Usage Data). In some (but not all) countries, including countries in the European Economic Area (EEA), this information is considered Personal Information under applicable data protection laws. We and our third-party partners use cookies and other tracking technologies to collect some of this information.
Device information: We collect information about the device and applications you use to access the Service, such as your IP address, your operating system, your browser ID, viewfinder size, and other information about your system and connection.
Log data: Our web servers keep log files that record data each time a device accesses those servers and the nature of each access, including originating IP addresses and your activity in the Service (such as the date/time stamps associated with your usage, pages and files viewed, searches and other actions you take (for example, which features you used)), device event information (such as system activity, error reports (sometimes called crash dumps)), and hardware settings. We may also access metadata and other information associated with files that you upload into our Service.
Usage data: We collect usage data about you whenever you interact with our Service, which may include the dates and times you access the Service and your browsing activities (such as what portions of the Service you used, session duration, links clicked, non-sensitive text entered, and mouse movements). We also collect information regarding the performance of the Service, including metrics related to the deliverability of emails and other communications you send through the Service. This information allows us to improve the content and operation of the Service, and to facilitate research and analysis of the Service.
Examples of the information we receive from other sources include demographic information (such as age and gender), device information (such as IP addresses), location (such as city and state), and online behavioral data (such as information about your use of social media websites, page view information and search results and links). We use this information, alone or in combination with other Personal Information we collect, to enhance our ability to provide relevant marketing and content to you and to develop and provide you with more relevant products, features, and service.
We may use the Personal Information we collect or receive through the Service (alone or in combination with other data we source) for the purposes and on the legal bases identified below:
We may use the Personal Information we collect or receive through the Service, as a processor and as otherwise stated in this privacy policy, to enable your use of the integrations and plugins you choose to connect to your Erbab.dev account.
We and our third-party partners may use various technologies to collect and store Service Usage Data when you use our Service (as discussed above), and this may include using cookies and similar tracking technologies, such as pixels and web beacons. For example, we use web beacons in the emails we send on your behalf, which enable us to track certain behavior, such as whether the email sent through the Service was delivered and opened and whether links within the email were clicked. Web beacons allow us to collect information such as the recipient's IP address, browser, email client type and other similar data as further described above details. We use this information to measure the performance of your campaigns, to provide analytics information, enhance the effectiveness of our Service, and for other purposes described above.
Our use of cookies and other tracking technologies is discussed in more detail in our Cookie Policy available here.
In order to use certain features of the Service, you connect your code repositories to the platform. We use and process repository data (including source code, commit metadata, and dependency manifests) solely to provide the security scanning Service in accordance with our contract with you and this Privacy Policy.
Repositories can be connected via GitHub OAuth or API integration. We do not, under any circumstances, sell your repository data or source code. We do not retain source code beyond what is necessary to complete each scan; only scan findings and reports are stored in our system.
Depending on the country in which you reside, you may have the following data protection rights:
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection law. We may ask you to verify your identity in order to help us respond efficiently to your request. We respond to all data protection requests in accordance with applicable law.
This section applies to the code, repository data, and related information that Clients connect to our Service for the purpose of security scanning and analysis. When a Client connects a repository, Erbab.dev processes that data as a processor on behalf of the Client. For purposes of this section, "you" and "your" refer to Clients.
When you connect a repository to the Service, we may process the following categories of data:
We use repository and code data solely for the following purposes:
We do not use your source code or repository data for advertising purposes, and we do not sell or share it with third parties except as necessary to provide the Service (e.g., cloud infrastructure providers bound by confidentiality obligations).
Source code is processed in memory during scanning and is not permanently stored on our systems. Scan findings, vulnerability reports, and remediation history are retained for the duration of your active subscription and for a reasonable period thereafter as required by applicable law or for dispute resolution purposes.
As a Client, you may request access to, correction of, or deletion of data we hold about your repositories and findings by contacting us at [email protected]. We respond to all requests in accordance with applicable data protection laws.
This section applies to Personal Information that we collect and process when you visit the Erbab.dev
Sites, and in the usual course of our business, such as in connection with our recruitment, events, sales and
marketing activities or when you visit our offices. In this section, "you" and "your" refer to Visitors.
The Personal Information we collect may include:
The information we collect automatically includes:
Device information: such as your IP address, your browser, operating system, device information, unique device identifiers, mobile network information, request information (speed, frequency), the site from which you linked to us (referring page), the name of the website you choose to visit immediately after ours (called exit page), information about other websites you have recently visited, the web browser you used (software used to browse the internet) including its type and language), and viewfinder size and scripts errors.
Usage data: such as information about how you interact with our emails, Erbab.dev Sites, and other websites (such as the pages and files viewed, session duration, links clicked, searches, non-sensitive text entered, mouse movements, operating system and system configuration information and date/time stamps associated with your usage).
We may use the information we collect through our Erbab.dev Sites and in connection with our events and marketing activities (alone or in combination with other data we collect) for a range of reasons in reliance on our legitimate interests, including:
Blog. We have public blogs on the Erbab.dev Sites. Any information you include in a comment on our blog may be read, collected, and used by anyone. If your Personal Information appears on our blogs and you want it removed, contact us at [email protected]. If we are unable to remove your information, we will tell you why.
Social media platforms and widgets. The Erbab.dev Sites include social media features, such as the Facebook Like button. These features may collect information about your IP address and which page you are visiting on our Erbab.dev Site, and they may set a cookie to make sure the feature functions properly. Social media features and widgets are either hosted by a third party or hosted directly on our Erbab.dev Site. We also maintain presences on social media platforms, including Facebook, Twitter, and Instagram. Any information, communications, or materials you submit to us via a social media platform is done at your own risk without any expectation of privacy. We cannot control the actions of other users of these platforms or the actions of the platforms themselves. Your interactions with those features and platforms are governed by the privacy policies of the companies that provide them.
Links to third-party websites. The Erbab.dev Sites include links to other websites, whose privacy practices may be different from ours. If you submit Personal Information to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any website you visit.
Contests and sweepstakes. We may, from time to time, offer surveys, contests, sweepstakes, or other promotions on the Erbab.dev Sites or through social media (collectively, "Promotions"). Participation in our Promotions is completely voluntary. Information requested for entry may include Personal Information such as your name, address, date of birth, phone number, email address, username, and similar details. We use the information you provide to administer our Promotions. We may also, unless prohibited by the Promotions rules or law, use the information provided to communicate with you, or other people you select, about our Service. We may share this information with our subsidiaries or Affiliates and other organizations or service providers in line with this privacy policy and the rules posted for our Promotions.
We and our third-party partners use cookies and similar tracking technologies to collect and use Personal Information about you, including to serve interest-based advertising about Erbab.dev and its Affiliates. For further information about the types of cookies and tracking technologies we use, why, and how you can control them, please see our Cookie Policy available here.
Depending on the country in which you reside, you may have the following data protection rights:
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. We may ask you to verify your identity in order to help us respond efficiently to your request.
We may share and disclose your Personal Information with our subsidiaries or Affiliates and to the following types of third parties for the purposes described in this privacy policy (for purposes of this section, "you" and "your" refer to Clients and Visitors unless otherwise indicated).
We may also share anonymized, aggregated information with selected third parties for statistical purposes.
If you are located in the EEA or UK, our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.
However, we will normally collect and use Personal Information from you where the processing is in our legitimate interests and not overridden by your data-protection interests or fundamental rights and freedoms. Our legitimate interests are described in more detail in this privacy policy in the sections above titled Use of Personal Information, but they typically include improving, maintaining, providing, and enhancing our technology, products, and services; ensuring the security of the Service and our Erbab.dev Sites; and supporting our marketing activities.
If you are a Client, we may need the Personal Information to perform a contract with you. In some limited cases, we may also have a legal obligation to collect Personal Information from you. Where required by law, we will collect Personal Information only where we have your consent to do so.
If you have questions or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided in the "Questions and Concerns" section below.
Clients and Visitors who have opted into our marketing emails can opt out of receiving marketing emails from us at any time by clicking the "unsubscribe" link at the bottom of our marketing messages.
Also, all opt-out requests can be made by emailing us using the contact details provided in the "Questions and Concerns" section below. Please note that some communications (such as service messages, account notifications, billing information) are considered transactional and necessary for account management, and Clients cannot opt out of these messages unless you cancel your Erbab.dev account.
We take appropriate and reasonable technical and organizational measures designed to protect Personal Information from loss, misuse, unauthorized access, disclosure, alteration, and destruction, taking into account the risks involved in the processing and the nature of the Personal Information. If you have any questions about the security of your Personal Information, you may contact us at [email protected].
(i) We operate in Turkey and the European Union.
Our company is headquartered in Ankara, Turkey. Our servers and offices are located in Turkey and/or the European Union. Your data will be processed in jurisdictions that maintain data protection standards consistent with GDPR and Turkish Law No. 6698 (KVKK). We take appropriate technical and organizational measures to protect your Personal Information wherever it is processed.
(ii) For clients located in the EEA, United Kingdom, and Switzerland, Erbab.dev processes Customer Data in compliance with the General Data Protection Regulation (GDPR) and applicable national data protection laws. If you have questions about data transfer safeguards, please contact us at [email protected].
We retain Personal Information where we have an ongoing legitimate business or legal need to do so. Our retention periods will vary depending on the type of data involved, but, generally, we'll refer to these criteria in order to determine retention period:
When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymize it or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") grants data subjects in Turkey specific rights regarding their Personal Information. If you are located in Turkey or if your Personal Information is processed under Turkish jurisdiction, you have the right to:
To exercise any of these rights, please contact us at [email protected] or by postal mail at our address below. We will respond to all requests within 30 days in accordance with KVKK requirements.
Erbab.dev acts as the data controller ("veri sorumlusu") for Personal Information processed in connection with the Service. Our Data Controller registration information is maintained with the Turkish Personal Data Protection Authority (KVKK).
Certain state laws require us to indicate whether we honor Do Not Track settings in your browser. Erbab.dev adheres to the standards set out in this Privacy Policy and does not monitor or follow any Do Not Track browser requests.
We may change this privacy policy at any time and from time to time. The most recent version of the privacy policy is reflected by the version date located at the top of this privacy policy. All updates and amendments are effective immediately upon notice, which we may give by any means, including, but not limited to, by posting a revised version of this privacy policy or other notice on the Erbab.dev Sites. We encourage you to review this privacy policy often to stay informed of changes that may affect you. Our electronically or otherwise properly stored copies of this privacy policy are each deemed to be the true, complete, valid, authentic, and enforceable copy of the version of this privacy policy that was in effect on each respective date you visited the Erbab.dev Site.
If you have any questions or comments, or if you have a concern about the way in which we have handled any privacy matter, please contact us by postal mail or email at:
Erbab.dev
Beştepe Mah. Nergis Sok. Via Flat Plaza, Söğütözü – Ankara, Türkiye
Email: [email protected]
Phone: +90 (507) 906 1137