Privacy policy
Effective September 19, 2026
Perimeter is operated by Amer Mahdi, an individual based in Virginia, USA (“we”, “us”). This policy explains what we collect when you use Perimeter, why, who else handles it, and how long we keep it. Questions or requests go to support@perimeter.report.
The short version
- Perimeter only looks at what is publicly visible about a domain. We never ask for, and never store, passwords or credentials for your systems.
- We keep what we need to run your account and your reports, and nothing more.
- We don't sell your data, show ads, or use tracking or analytics cookies.
- Card payments are handled by Stripe. We never see your card number.
What we collect
If you use the free grade page without an account
- The domain you enter, which we look up to produce the grade. The result is shown to you and not stored.
- Your IP address, held briefly in memory to limit how often the page can be used. It is not written to our database.
If you create an account
- Your email address and password. The password is stored only as a one-way hash; we cannot read it.
- A login session. A cookie keeps you signed in for up to 30 days. We store only a hash of its value.
- Your businesses: the name and domain you add, and the results of every check we run on them, so you can see your grade over time.
- Your subscription: its status, renewal date and the Stripe customer reference that links it to you. Payment details stay with Stripe.
If you verify that you control a domain
- The verification method you chose. For email verification, that includes the role address at your domain we wrote to (for example
admin@). - The IP address that requested the verification and the one that completed it, with timestamps. We keep these as evidence of who proved control of a domain, because verification unlocks detailed breach findings about it.
- A record each time detailed breach findings are shown: the domain, the account, the IP address and the time.
Emails we send you
We email the address on your account about the service itself: when a nightly re-check finds a new problem with one of your domains, and when a domain verification is about to expire. We don't send marketing email.
Emails we send to people who are not our customers
When someone asks to verify a domain by email, we send a confirmation message to a role address at that domain, such as admin@ or postmaster@. When verification succeeds, we notify that domain's role addresses. These messages exist so that a domain's owner always knows if someone has claimed control of it. If you received one and did not expect it, contact us.
Who else handles data
We use a small number of service providers to run Perimeter:
- Vercel hosts the website and application.
- Neon hosts our database.
- Stripe processes subscription payments and hosts the checkout and billing pages.
- Resend delivers our emails.
- A breach-data provider (such as Enzoic or Have I Been Pwned) receives the domain being checked, to report whether addresses at it appear in known data breaches.
The other security checks query public sources directly: DNS records and the certificate a website presents. We share data with anyone else only if the law requires it.
How long we keep it
- Account, business and check data: for as long as your account exists.
- Login sessions: until you log out, or 30 days at most.
- Verification attempts that never succeeded: deleted after 30 days.
- The record of detailed breach findings being shown: deleted after 180 days.
- Successful domain verifications: kept while your account exists, as evidence of who was entitled to see a domain's findings.
- Payment records: kept by Stripe as its own policies and the law require.
Your choices
You can ask to see the personal data we hold about you, correct it, or delete your account and its data by emailing support@perimeter.report from the address on your account. We'll respond within 30 days. Cancel your subscription first if you have one; deleting your account does not cancel billing on its own.
Security
Passwords and session tokens are stored only as hashes, all traffic is encrypted in transit, and we store no credentials for your systems. No service is perfectly secure, but we design Perimeter to hold as little as possible.
Children
Perimeter is a business service and is not meant for anyone under 18.
Changes to this policy
If we change this policy, we'll update the effective date above. If a change materially affects how we use your data, we'll tell account holders by email before it takes effect.