What the site collects. What it does not. Plainly.
This notice describes the public website and the project's local-first approach to sensitive research artifacts. It does not make claims about unverified product telemetry or formal compliance controls.
Last updated: 11 August 2026.
1. Operator identity
SecHive is an independent cybersecurity research project operated by Charles Vosburgh, a United States-based sole proprietor. SecHive is not an LLC, corporation, registered company, or entity established in the European Union.
For privacy questions, contact [email protected].
2. Categories of data
2.1 Website
This public site does not include account registration, payment processing, or a contact form. Standard web infrastructure may process request data such as IP address, user agent, requested page, and time to deliver the site and address abuse.
- Email. If you email the public contact address, the message contains the information you choose to provide.
- Infrastructure telemetry. SecHive does not add advertising or marketing trackers. Cloudflare serves the public site and email routing and may process request, security, delivery, and performance metadata under its own terms.
2.2 Platform
My research workflow is local-first: I handle sensitive research artifacts locally unless I deliberately share material for coordinated disclosure, authorized collaboration, backup, or another documented purpose. I do not give third parties access to restricted research systems, AI accounts, or credentials.
3. Lawful basis
Where applicable, request data and correspondence are handled for legitimate operational interests such as serving the website, addressing abuse, maintaining security, and responding to inquiries. Additional legal bases may apply where required by law.
4. Retention
I keep correspondence and disclosure records only as long as reasonably needed for their operational, security, coordinated-disclosure, or legal purpose. Cloudflare and the origin-hosting provider may apply their own documented retention schedules.
5. Your rights
Depending on where you live, privacy law may provide rights concerning personal information. Send requests to [email protected]. Identity or authority may need to be verified before a request is completed.
6. International transfers
The project is operated in the United States. Website hosting, email, and linked third-party services may process data in other locations under their own terms and privacy notices.
7. Subprocessors
Cloudflare provides public-site delivery and email routing. The origin-hosting provider may process request metadata needed to operate the server. Contact [email protected] for current infrastructure information.
8. Security
The public site uses HTTPS and restrictive browser security headers. No internet service can guarantee absolute security.
9. Children
The website is directed to security researchers, maintainers, developers, and technical teams, not children. The project does not knowingly solicit personal information from children through this site.
10. Changes
Material changes to this notice will be announced at the top of this page with an updated revision date.