Skip to content
BASTION
Pricing Articles Sign in Start trial

Privacy Policy

Last updated August 6, 2026

1. Who we are

Bastion is operated by Instant City Solutions LLC, a Florida limited liability company based in Miami, Florida. This policy explains what we collect when you use bastionscan.com, why, and what control you have over it. Instant City Solutions LLC is the controller of the personal data described here.

2. What we collect

Account information. Your email address and a password. Passwords are handled by Amazon Cognito and are never visible to us in plain text. If you invite teammates, we store their email address and role.

Domains and scan data. The domains you register, the verification tokens issued for them, and the results of every scan — including response headers, certificate details, DNS records, discovered subdomains, and which common ports accepted a connection. We also store the differences between scans, and registry data about your domains such as registrar and expiry date. This describes infrastructure rather than people, but it can include personal data where a domain or DNS record contains someone's name or contact details.

Notification settings. The email addresses and webhook URLs you configure for alerts, and delivery outcomes for them.

Billing information. Payments are processed by Stripe. We receive and store a Stripe customer identifier, your plan, subscription status, and billing period. We never receive or store full card numbers.

Technical logs. Standard server and access logs — IP address, timestamp, user agent, and the request made — retained for a limited period for security, abuse prevention and debugging.

We do not use advertising trackers, and we do not sell personal data or scan results. The marketing pages of this site load no JavaScript and set no cookies at all.

3. How we use it

  • To operate the service: authenticate you, verify domain ownership, run scans, detect changes, and generate reports.
  • To send the notifications you ask for — change alerts, the weekly digest, and address-confirmation emails.
  • To enforce plan limits and process subscription payments.
  • To detect, investigate and prevent abuse, including scanning of domains the account holder is not authorized to test.
  • To diagnose faults and improve the service.
  • To comply with legal obligations.

Our legal bases, where the GDPR applies, are performance of our contract with you (running the service and billing), our legitimate interests (security, abuse prevention, service improvement), and compliance with legal obligations.

4. Who we share it with

We use a small number of processors, and only for the purposes above:

  • Amazon Web Services — hosting, storage, authentication and email delivery. Data is stored in the US East (N. Virginia) region.
  • Stripe — subscription billing and payment processing.
  • Any webhook or Slack endpoint you configure yourself, which receives the alert content you have asked us to send there.

We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights and safety of our users or the public. If the business is acquired or merged, account data may transfer as part of that transaction; we will give notice before your data becomes subject to a different policy.

5. Scanning, monitoring and third-party domains

A scan only ever runs against a domain the account holder has verified control of, using a DNS TXT record. Some checks read publicly available sources — DNS, certificate transparency logs, and RDAP registry records — which may return subdomains, certificate details or registrar information published by third parties. That information is already public; we surface it, and we store it as part of your history.

Lookalike-domain monitoring observes domains you do not own. Those domains are checked using public DNS and certificate transparency data only; they are never scanned, connected to, or probed in any way.

Our scanner identifies itself in its User-Agent so that anyone reviewing their own logs can tell what it is.

6. Cookies and local storage

The application uses browser local storage to keep you signed in — session and refresh tokens issued by Amazon Cognito. These are strictly necessary for the service to function. We do not use analytics, advertising, or cross-site tracking cookies anywhere on this site.

7. How long we keep it

  • Account, team and domain records: for as long as your account is open.
  • Scan results and detected changes: for as long as your account is open, so you can compare posture over time.
  • Generated PDF reports and evidence packs: automatically deleted one year after they are created.
  • Billing records: retained as long as required for tax and accounting purposes.
  • Technical logs: 30 days.

When you close your account, we delete your account, domains, scan data and notification settings within 30 days, except where we must retain records to meet a legal obligation.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. California residents have the right to know what we collect, to request deletion, and not to be discriminated against for exercising those rights — and we note again that we do not sell or share personal information for cross-context behavioral advertising.

Email support@bastionscan.com to make a request. We will respond within 30 days and may need to verify your identity first. If you are in the EEA or UK, you also have the right to complain to your local data protection authority.

9. International transfers

We operate in the United States and store data in the US East (N. Virginia) AWS region. If you access Bastion from outside the United States, your data will be transferred to and processed there, under appropriate safeguards where required.

10. Security

Data is encrypted in transit and at rest. Each customer's data is partitioned by account so it cannot be read across tenants. Access to production systems is limited to personnel who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and any relevant regulator as required by law.

11. Children

Bastion is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. If a change is material, we will notify the email on your account at least 14 days before it takes effect, and we will always update the date at the top of this page.

13. Contact

Instant City Solutions LLC
Miami, Florida, United States
support@bastionscan.com

© 2026 Instant City Solutions LLC · Miami, FL
Pricing Articles Terms Privacy Support Report abuse