Privacy Policy
Last updated: 9 August 2026
This revision records that the MCP Server is read-only. Its two contribution tools have been removed from the product, so the passages describing what they collected, the scope that reached them, and how long contributed data was kept have been deleted rather than rewritten — there is no such data. Nothing else in the previous revision changes.
Introduction
This Privacy Policy describes how viaGraph B.V. ("viaGraph", "we", "our", or "us"), a private limited company registered in the Netherlands, processes personal data in connection with our website at whisper.security, our customer console at console.whisper.security, our query API at graph.whisper.security, and our Model Context Protocol server at mcp.whisper.security (the "MCP Server"). "Whisper Security" is the brand under which viaGraph offers these services.
For the purposes of the EU General Data Protection Regulation (GDPR), viaGraph is the data controller for the personal data described in this Policy. Our contact details are at the end of this Policy.
At a glance
This summary is for orientation only and does not replace the detail below.
- We do not sell personal data, and we do not use your queries, results, or conversation history to train machine-learning models owned by us.
- Every request to the MCP Server must be authenticated. The query API additionally offers a keyless anonymous tier, limited to short traversals, for evaluation.
- No tool on the MCP Server sends your data to an AI model provider. The console's optional natural-language query generator is the one feature that does, and it sends your question to OpenAI — never your results. See "AI Models and Your Data".
- The MCP Server is read-only. All seven of its tools query the graph and return results; none of them can create, modify, or delete anything, and each declares itself read-only in the metadata your AI assistant receives.
- The MCP Server cannot read your AI assistant's chat history, memory, system instructions, or uploaded files. The Model Context Protocol does not expose them to us.
- Our graph contains personal data about people who are not our customers, taken from public domain-registration records and similar sources. If that is you, see "Personal data within the graph" and "Your Rights".
- Audit logs are kept for 30 days. The query text we store has string literals removed, so the indicators inside your query do not enter our log stream.
- Our marketing website uses analytics, advertising and visitor-identification tools. None of them loads until you accept the matching category in our consent banner. They are not used on the console, the query API, or the MCP Server.
Information We Collect From You Directly
When you create a Whisper Security account, contact us, or use our services, we collect:
- Account information from your sign-up provider (Clerk): your email address, first name, last name, and, where you authenticate via a third-party identity provider (for example Google or GitHub), the identifier returned by that provider.
- Billing information collected by Stripe when you subscribe to a paid plan: your name, email, and payment method. Card details are submitted directly to Stripe and are not collected or stored by us.
- Support request information when you contact us through the console or by email: the contents of your message, attachments you choose to share, your browser type and operating system, and your IP address.
- Enquiry information when you use a form on our website: the message you write, your name and email address, and the campaign parameters that brought you to us. These are sent to our CRM.
- Marketing and attribution identifiers captured on our website and at sign-up, including analytics client and session identifiers and, where our website visitor-identification provider is able to resolve one, the company associated with your network address. See "Website analytics, advertising and visitor identification" below.
- Information you choose to provide by other means, such as by replying to a marketing email or filling in a form.
How the MCP Server Works
The MCP Server lets customers, directly or through AI assistants such as Claude Desktop, Claude.ai, Claude Code, Cursor, and VS Code, query our internet-infrastructure graph database using the Cypher query language.
Authentication is required on every MCP Server endpoint. Access is via OAuth 2.0 (using our identity provider, Clerk, with Dynamic Client Registration and PKCE-S256) or via a static API key issued from your Whisper Security account. There is no unauthenticated access path to the tool surface. Our separate query API at graph.whisper.security does serve a keyless anonymous tier, limited to short traversals, so that the documentation examples can be run without an account.
The MCP Server is read-only. It advertises seven tools, all of which query the graph and return results; none of them can create, modify, or delete graph data. Each one declares itself read-only in the tool metadata your AI assistant receives, so your assistant can see that for itself. There is no tool that writes, no tool that deletes, and no tool that reaches outside the graph into your systems. The guarantee does not rest on the tool list alone: the free-form query tool is the only place you supply a query, and every write or administrative instruction in one is rejected before it reaches the database.
Every OAuth client reaches the same seven read tools; there is no scope that grants more, because there is nothing more to grant. The scopes are documented in our MCP setup guide.
The MCP Server cannot read your AI assistant's chat history, memory, conversation summaries, system instructions, or any files you have uploaded to that assistant. The Model Context Protocol does not expose that information to MCP servers, and we have no need for it.
What Is in the Graph Database
The graph database aggregates internet-infrastructure data from public registries, open datasets, and licensed feeds, including:
- DNS records (A, AAAA, MX, NS, TXT, CNAME, DNSSEC, SPF), TLD and registrar relationships, and domain hierarchy;
- BGP routing data, IP allocations, ASN ownership, RPKI data, and routing history;
- Domain registration records obtained from WHOIS and RDAP, including registrant, administrative, technical, and abuse contact details where the source publishes them;
- TLS certificate metadata and certificate-transparency observations;
- A web-link graph derived from the open Common Crawl dataset;
- GeoIP location data licensed from MaxMind;
- Public and licensed threat-intelligence feeds covering categories such as malware, phishing, command-and-control infrastructure, scanning, spam, and anonymizing networks;
- Physical infrastructure reference data: facilities, internet exchanges, submarine cables and landing points, CDN points of presence, and cloud regions.
Personal data within the graph
The graph contains personal data about third parties. Most visibly, this is the names, email addresses, postal addresses, and telephone numbers of individuals recorded as registrants, administrative contacts, technical contacts, or abuse contacts in domain-registration records. This data is not collected from you; it is obtained from registries, registrars, and feed providers rather than from the individuals concerned. Most records of this kind relate to organizations and role mailboxes rather than to identifiable individuals, but some relate to natural persons, and those are personal data.
Legal basis. For this category of data our legal basis is GDPR Article 6(1)(f), legitimate interests: providing cybersecurity, threat-intelligence, and infrastructure-research capabilities to organizations that use them to defend networks. Recital 49 of the GDPR expressly recognizes the processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security as a legitimate interest. Recital 49 establishes the interest; it does not remove the necessity and balancing tests, and we have carried both out.
Our balancing assessment, in short. The interest is the detection and investigation of malicious internet infrastructure. The processing is necessary because attribution of infrastructure depends on the registration and routing records that identify who operates it, and no less intrusive dataset answers the question. Against that we weigh the reasonable expectations of registrants: the records were published by registries under their own policies, we do not enrich them with data from unrelated contexts, we do not build behavioural profiles of individuals, we make no automated decisions producing legal or similarly significant effects about any individual, and access to the data requires an authenticated account subject to contractual use restrictions. The full assessment is available on request from the address below.
Article 14 and the source of the data. Because we do not obtain this data from the individuals concerned, GDPR Article 14 applies. We rely on the exemption in Article 14(5)(b) for individual notification: the records reach us in bulk and generally carry no verified link between a registration record and an identified natural person, so identifying and contacting each individual would require processing more data about them than we hold today, and directly mailing hundreds of millions of registration addresses would itself be a greater intrusion than the one it cures. Article 14(5)(b) requires that, where individual notice is not given, the information is made publicly available instead. This section, together with the rights section below, is that public notice.
Redacted records. Where a registry or registrar redacts registration data, we record it as redacted. We do not attempt to reconstruct redacted fields from other sources, and we do not treat the public availability of a record as evidence that its publication was lawful.
We do not knowingly include payment data, government identifiers, biometric data, or other special categories of personal data (Article 9) in the graph.
Data We Collect When You Use the MCP Server and Query API
For each request, we record an audit log entry containing:
- An identifier for the calling account: a Clerk user ID for OAuth requests, or, for static-key requests, an identifier derived from the key rather than the key itself. On the keyless anonymous tier of the query API there is no account, and the request is instead counted against your IP address, which serves as the identifier for that tier's rate limits;
- The request path, method, and timestamp, and a correlation identifier, either one your client supplied in a correlation-ID header or one we generate, so that a single request can be traced across our systems;
- Response status, execution time, and result size, and the outcome of our query-safety validator, including which rule a rejected query tripped and whether we corrected it automatically;
- The Cypher query text with string literals replaced by a placeholder, so that the indicator values, hostnames, and addresses inside your query do not enter our log stream;
- The plan tier under which the request ran.
Your IP address and user-agent string are recorded at our edge proxy rather than by the MCP Server itself, and are retained under the same 30-day window.
We log this information because:
- it is shown back to you in your usage dashboard inside the console;
- it is required to investigate incidents, debug failed queries, and detect abuse; and
- it allows us to measure and reconcile usage accurately.
We do not use your queries, results, conversation history, or any other customer-supplied data to train machine-learning models owned by us, and we do not sell this data.
AI Models and Your Data
No tool on the MCP Server calls a language model, and neither does the query API. When you use the connector, the AI assistant you already run is the only model in the loop, and your relationship with that assistant's provider is governed by your agreement with them, not by us.
Separately from the MCP Server, our customer console offers an optional natural-language query generator: you describe what you want in plain English and we return a Cypher query for you to review and run. To produce that query we transmit your question — together with a description of the graph schema and, in a multi-turn conversation, the recent messages of that conversation — to OpenAI, which returns a candidate query.
OpenAI never receives your results. Generating the query and running it are separate steps: the query is returned to you first, and it is validated and executed by us afterwards, against the graph. No rows are sent to the provider at any point. OpenAI is the only AI model provider we use, and it is listed as a subprocessor below.
Your question is not written to our logs. Our operational logging for this path records the model used, the validation outcome, and any error — not the text you typed. Where a multi-turn conversation is used, we keep the recent messages of that conversation for 30 minutes of inactivity so follow-up questions have context; that history is held in server memory, is lost when the service restarts, and is never used for any purpose other than continuing your conversation.
Please treat the natural-language field as you would any other input you send us: it is transmitted to OpenAI verbatim, so avoid including personal data or confidential material that is not necessary to the question. If you would rather no third party saw your question, write the Cypher yourself — the generator is optional and nothing else in the product depends on it.
We also do not use your queries, results, or any other customer-supplied data to train machine-learning models owned by us.
If we introduce a further feature that sends your input to a third-party model provider, we will name that provider in the subprocessor list below and describe the data flow here before the feature is made available to you.
Website Analytics, Advertising and Visitor Identification
This section applies to our marketing website only. None of these tools runs on the customer console, the query API, or the MCP Server, none of them plays any part in the graph, and none is used to make an automated decision about you.
Everything described below loads only after you accept the matching category in our consent banner, and you can change or withdraw that choice at any time from the cookie settings on our website. Nothing in this section runs if you decline.
- Analytics (statistics category). Google Analytics via Google Tag Manager, and Microsoft Clarity, which records how pages are used — including mouse movement, clicks, scrolling and a replay of the page interaction — so we can see where the site is confusing. We do not use Clarity to identify individuals.
- CRM and marketing (marketing category). HubSpot, for enquiry forms and to understand which content leads to a conversation.
- Advertising (marketing category). Google Ads conversion tracking and remarketing, which records that a visit led to a sign-up or an enquiry and allows Google to show you our advertising elsewhere. Where you submit a form, we also send Google a cryptographic hash of your email address so that a conversion can be matched to the advertisement that produced it; we send the hash, never the address, and only if you have accepted the marketing category.
- Visitor identification (marketing category). RB2B, a business-to-business service that matches network and device signals against its own dataset and third-party identity-resolution providers — principally LiveIntent — in order to tell us which organization is visiting and, for some visitors in the United States, which individual. We use this to understand which companies are researching us and to follow up on business enquiries.
If you would prefer not to be identified this way, decline the marketing category in our consent banner — RB2B does not load at all if you do. You can additionally write to privacy@whisper.security and we will add you to the provider's exclusion list.
Subprocessors
We engage the following third-party subprocessors. We will publish updates to this list at least 30 days before they take effect for existing customers.
- Clerk, Inc. (US) — identity provider for sign-up, sign-in, OAuth 2.0, and account management. Data shared: email, name, authentication events, OAuth tokens.
- Stripe Payments Europe Ltd. (IE) / Stripe, Inc. (US) — payment processing and subscription billing. Data shared: name, email, payment method, billing address.
- Upstash, Inc. (EU) — authentication-state storage and OAuth authorization-code, session, client-registration and refresh-token storage. Data shared: API-key records, user identifier, plan tier, OAuth state.
- Better Stack (EU) — application observability, log storage, audit-log warehouse, and error tracking. Data shared: operational logs, MCP Server and query API audit logs (including query text with string literals removed), error events, request metadata.
- OpenAI, L.L.C. (US) — natural-language-to-query generation for the console's optional query generator. Data shared: your natural-language question, graph schema context, and the recent messages of a multi-turn conversation. Query results are never shared. Contracted on terms that prohibit the use of your input to train their models.
- HubSpot, Inc. (US) — customer-relationship management and website forms. Data shared: email, name, account identifier, plan tier, aggregated usage counts, the contents of enquiries you submit through our website, and the campaign parameters associated with your visit.
- Intercom Inc. (US/EU) — customer support and ticketing. Data shared: email, name, account identifier, support-ticket contents, browser metadata.
- Vercel Inc. (US/EU) — hosting of the marketing website and the customer console, hosting of the workflow-execution endpoint that the MCP Server's workflow tools call, and storage of support attachments. Data shared: console and workflow request metadata, the parameters you pass to a workflow (which may include hostnames, addresses, and other indicators), your API credential as a request header, and support-ticket attachments you upload.
- Cloudflare, Inc. (US/EU) — edge proxy, TLS termination, DDoS protection, and bot detection on sign-in. Data shared: request metadata, IP address.
- Prismic (Prismic SAS, FR) — the content management system behind our website and documentation, and the CDN serving their images. Data shared: page requests for published content. No account data.
- Cybot A/S (DK) — Cookiebot, our consent management platform. It records your consent choice and, for the audit trail the law requires, an anonymized form of your IP address. It runs before any non-essential tool and is itself strictly necessary.
- Google Ireland Limited / Google LLC (IE/US) — marketing analytics (Google Analytics, Google Tag Manager) and advertising (Google Ads conversion tracking and remarketing). Data shared: pseudonymous device and session identifiers, page-view events, conversion events, and a hashed email address where you submit a form and have accepted the marketing category.
- Microsoft Corporation (US/EU) — Microsoft Clarity, product analytics and session replay on our marketing website. Data shared: page-interaction events, device and browser metadata, and a session recording of your interaction with the page.
- RB2B (US) — business-to-business website visitor identification on our marketing site, together with the identity-resolution and enrichment providers it loads in the browser, principally LiveIntent, Inc. (US). Data shared: website page-view events, and network and device signals from which the provider infers the visiting organization and, for some United States visitors, the individual.
- MaxMind, Inc. (US) — GeoIP data licensor. No customer data is sent to MaxMind.
Where Your Data Is Processed
Our application servers are located within the European Union. The subprocessors listed above process data in the regions indicated alongside each entry.
Where a subprocessor processes personal data outside the European Economic Area, we rely primarily on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and, where relevant, additional technical and organizational measures. For transfers to the United Kingdom and Switzerland we use the UK International Data Transfer Addendum and the Swiss-recognized version of the Clauses respectively. Where a recipient additionally certifies under an adequacy decision, that adequacy may apply alongside the Clauses; we do not rely on it as our sole mechanism. A copy of the Clauses relevant to a given transfer is available on request.
Data Security
We apply technical and organizational measures designed to protect personal data, including:
- TLS encryption in transit on all customer-facing endpoints;
- Encryption at rest in our managed-service subprocessors;
- Restricted, audited access to operational systems for personnel with a need to know;
- Authentication enforced on every MCP Server endpoint, and a query validator that rejects every write and administrative instruction before it reaches the database;
- A vulnerability-disclosure channel published at /.well-known/security.txt and at security@whisper.security.
API keys are never written to our application logs. Where a failed authentication attempt must be recorded, we log only a short prefix of a cryptographic hash of the key, from which the key cannot be reconstructed. API keys are held by our key-management subprocessor in encrypted-at-rest storage for the purpose of validating them on each request. If you believe a key has been exposed, revoke it from your console immediately; revocation takes effect on the next request.
No method of transmission over the Internet is fully secure, and we cannot guarantee absolute security.
Data Retention
We retain different categories of data for different lengths of time:
- MCP Server and query API audit logs, and operational logs (request metadata and query text with string literals removed): 30 days, after which records are permanently deleted from production systems. Aggregate counts derived from these logs may be retained for billing and product purposes.
- Billing and usage aggregates (counts of queries, requests, and active users, with no query content): 13 months, to support year-over-year reporting and tax-audit windows.
- Account and identity data after account closure: 30 days, after which it is permanently deleted. During those 30 days you may request reactivation.
- OAuth tokens: access tokens expire one hour after issue. Refresh tokens last up to 180 days from issue and rotate on every use, so an actively used session is continuously renewed and does not require you to sign in again; a session left unused for the whole window expires and requires reauthentication.
- Natural-language conversation memory (console query generator): 30 minutes from last use, held in server memory, then discarded.
- Support-ticket records: the lifetime of your account plus 12 months, to enable continuity of support.
- Website analytics, advertising and visitor-identification records: retained by the providers named above under their own retention periods, and by us for no longer than 26 months.
- Other personal information you provide outside the systems above: as long as necessary to fulfill the purposes outlined in this Policy or as required by law, after which it is deleted or anonymized.
How We Use Your Information
We process the personal data described above to:
- Provide, maintain, and improve our website, console, query API, and MCP Server;
- Authenticate requests and apply the plan limits and query-safety limits that apply to your account;
- Investigate incidents, abuse, and security events;
- Reconcile billing and produce usage reports;
- Send technical notices and support communications;
- Send marketing communications, with your consent or where otherwise permitted by law;
- Comply with legal obligations.
Your Rights
Depending on your location, you may have rights under the GDPR or other applicable laws, including the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, and the right to object to processing. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
You may exercise these rights by contacting privacy@whisper.security. We will respond within one month, extendable by two further months for complex or numerous requests, and we will tell you if we need the extension.
If your personal data appears in the graph
If you are not a customer and your details appear in the graph because they were published in a domain-registration record or a similar source, write to privacy@whisper.security with the identifier concerned, for example the domain name, email address, or telephone number. We do not require you to create an account, and we will not ask you for identity documents where control of the identifier can be demonstrated more simply.
How we handle such a request:
- Objection (Article 21(1)). We assess every objection on its own facts. The burden is on us to demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. We do not refuse an objection on the ground that the data was already public.
- Restriction while we assess (Article 18(1)(d)). On request we restrict processing of the records concerned for the duration of our assessment.
- Erasure (Article 17(1)(c)). Where we cannot demonstrate overriding grounds, we erase the records and add the identifier to a suppression list so that it is not reingested from the same source.
- Where we may decline. We may decline erasure in the narrow case where the record is itself an active indicator of malicious activity, or where retention is necessary for the establishment, exercise, or defense of legal claims. We will tell you which applies and why, and you may challenge that decision.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In the Netherlands this is the Autoriteit Persoonsgegevens. We would appreciate the chance to address your concern first.
United Kingdom
Where the UK GDPR applies to our processing, the descriptions in this Policy apply equally, and the Information Commissioner's Office is the relevant supervisory authority.
You have the right to complain to us about how we have handled your personal data. Write to privacy@whisper.security with "Data protection complaint" in the subject line. We will acknowledge your complaint within 30 days and tell you the outcome of our investigation without undue delay. You may complain to the Information Commissioner's Office at any time, and you do not have to come to us first.
United States
This section is provided for transparency to users in the United States. We provide these disclosures to the extent the laws referred to apply to us; we do not represent that any particular state privacy statute currently applies to viaGraph.
Categories of personal information we collect are described in "Information We Collect From You Directly", "Data We Collect When You Use the MCP Server and Query API", and "Website Analytics, Advertising and Visitor Identification" above. In the vocabulary used by California law they are: identifiers (name, email, account identifier, IP address); commercial information (plan, subscription, and billing records); internet or other electronic network activity (page views, session interaction recordings, query and request logs); geolocation inferred at city level from an IP address; and professional information (employer, where you provide it or our visitor-identification provider infers it).
Sources are you, your sign-up identity provider, your use of our services, our website analytics, advertising and visitor-identification providers, and our payment processor.
Purposes are those set out in "How We Use Your Information". Categories of third parties with whom we share personal information are the subprocessors named above.
We do not sell personal information for money. We do, however, use advertising and visitor-identification technologies on our marketing website that may constitute "selling" or "sharing for cross-context behavioral advertising" as those terms are defined by California law — specifically Google Ads remarketing and RB2B. These load only if you accept the marketing category in our consent banner, and declining is a complete opt-out. You may also withdraw a previous acceptance at any time from the cookie settings on our website, or write to privacy@whisper.security with "Do Not Sell or Share My Personal Information" in the subject line. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit, and we do not knowingly collect personal information from children.
Your choices. You may request access to, correction of, or deletion of your personal information, and you may appeal a decision we make on such a request, by writing to privacy@whisper.security. We operate exclusively online and will handle requests through that address. We will not discriminate against you for exercising any of these rights.
Do Not Track and Global Privacy Control. There is no common industry standard for responding to browser Do Not Track signals, and our website does not currently respond to them. You can control analytics, advertising and visitor-identification tools at any time through the cookie settings on our website.
Cookies
We use cookies and similar technologies on our website and console to authenticate you, remember your preferences, secure forms, and analyze usage. Cookies that are not strictly necessary load only after you accept the corresponding category in our consent banner, and you can change or withdraw your choice at any time from the cookie settings on our website. The declaration published on this page lists the cookies in use and their purposes.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page and, where appropriate, by direct notice to account holders. Where required by law, we will obtain your consent before changes take effect.
Contact Us
viaGraph B.V.
Keizersgracht 520 H, 1017 EK, Amsterdam, Netherlands
KVK: 95822429 — VAT: NL867322433B01
Privacy questions and data-subject requests: privacy@whisper.security
Security disclosures: security@whisper.security
General legal questions: legal@whisper.security
Cookies in Use
The table below is generated automatically by our consent management provider and lists every cookie set across whisper.security and console.whisper.security, the category each falls under, its purpose, and its expiry. You can change your consent at any time by clicking the cookie icon in the bottom-left of any page.