Skip to content

Siemphony is in beta and still being built. What ships today, and what does not.

Siemphony

Privacy Policy

Last updated 30 August 2026

Siemphony is a place to write detection rules and publish them. Some of what you put here is meant to be seen and some of it is not. This policy says which is which, what we do with the rest, and what you can make us do about it — in the order that matters to you rather than the order a template would use.
Drafted by the people who build Siemphony, from the actual database schema — not by a lawyer, and not reviewed by one. Every factual claim about what the software stores and does was checked against the running system. If your organisation needs a counsel-reviewed agreement before using Siemphony, write to and we will arrange one.

The short version

We store the account you create and the work you write. Your profile is private until you switch it on. Anything you publish — a rule, a comment, a verdict — is public and is meant to be. There is no advertising, no analytics, no tracking pixels and no profiling. There are no third-party scripts of any kind. We do not sell or share your personal information, and we do not read your drafts to train anything.

1. Who is responsible for your data

The data controller is the operator of Siemphony, established in the United States. For anything in this policy — access, deletion, questions, complaints — write to the Operator's privacy contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live). We answer within thirty days and usually much sooner.

We are a small operation and have not appointed a data protection officer, which our scale does not require. The address above reaches a person who can act.

2. What we collect

Your account. Your email address, and either a password — stored only as a salted hash, never in readable form — or a link to the GitHub or Google account you used, where those sign-in methods are enabled. We record when you last signed in and whether your email is confirmed.

Your profile. A handle, and optionally a display name, bio, target role, skills, avatar URL and external links. You choose all of it and can change any of it.

Your work. The rules you write, their translations and ATT&CK tags, plus the comments, verdicts, reactions and field reports you leave on rules.

Bookkeeping. Notifications recording who did what on your rules so we can tell you; and, if you report a comment, the fact that you reported it and why.

Technical logs. Our hosting and database providers keep request logs, which include IP addresses, timestamps and user agents. We use them to keep the Service running and to investigate abuse. We do not build profiles from them.

We do not collect special category data — health, biometrics, political opinions, and the rest — and you should not put any into the Service.

3. Why we use it, and on what legal basis

If you are in the UK, the EU or another place with equivalent law, these are our bases under Article 6 of the GDPR.

To give you an account and run the Service — authentication, storing and displaying your work, publishing what you choose to publish, sending service email such as confirmation and password reset. Basis: performance of a contract (Art. 6(1)(b)).

To keep the Service secure and working — rate limits, abuse investigation, debugging, backups. Basis: our legitimate interests in a service that is not flooded or broken (Art. 6(1)(f)), balanced against your interests, which is why these logs are not used for anything else.

To notify you about your work — someone commented on your rule, someone left a verdict. Basis: legitimate interests (Art. 6(1)(f)).

To publish what you have chosen to publish — a public profile, a published rule. Basis: your consent, given by switching visibility on or pressing publish (Art. 6(1)(a)), which you can withdraw by unpublishing or making your profile private.

To comply with the law — keeping records we are required to keep, responding to a lawful request. Basis: legal obligation (Art. 6(1)(c)).

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

4. What is public, precisely

Your profile is created with visibility off. Until you turn it on, an anonymous visitor cannot read it — enforced by row-level security in the database, not by the interface, so it holds against someone querying the API directly.

A rule stays a draft until you publish it. Once published on a public profile it can be read by anyone, including search engines and AI crawlers, and licensed to them under the terms in section 5 of the Terms. That is the point of the corpus, and it cannot be undone for copies already taken.

The one that catches people

Log events you paste into a field report are public. When you report that a rule fired on something benign, you can attach the event that caused it, and that event is readable by anyone who can read the rule.

Real telemetry contains hostnames, usernames, internal addresses and sometimes credentials. Once published it is out of our reach and possibly out of yours. Redact before you submit. The form says so at the point you paste; it is repeated here because it is the single most likely way to disclose something on this Service that you did not mean to.

5. Cookies

An anonymous visitor receives no cookies at all. Browse the landing page, the technique library, the translator or a public profile without signing in and nothing is set — measured, not assumed.

Signing in sets session cookies, which keep you signed in and are strictly necessary to provide a service you asked for. There is no consent banner because there is nothing non-essential to consent to: no analytics cookie, no advertising cookie, no local storage used for tracking. No third-party cookie either.

6. Who else processes it

Supabase — database hosting and authentication. Vercel — website hosting and delivery; like any host it processes request logs containing IP addresses. Our email provider sends confirmation and password-reset messages. Each acts as our processor under contract and may use your data only to provide their service to us.

That is the entire list. There are no advertising networks, no analytics vendors and no data brokers, because there is no code in this product that talks to one. If the list changes, this page changes with it.

We may also disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim or to protect someone’s safety.

7. Where your data goes

The Operator and its providers are in the United States. If you are in the UK, the EU or the EEA, using Siemphony means your personal data is transferred to and stored in the United States, which is outside your jurisdiction’s default protection.

Those transfers rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) in our agreements with our processors, or on their certification under the EU–US Data Privacy Framework where they hold one. You can ask us at the Operator's privacy contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live) which mechanism applies to which provider.

8. How long we keep it

Account and profile — while your account is open, and deleted when you close it.

Your work — until you delete it or close your account. Deleting a comment leaves a marker that a comment was removed, so a discussion does not silently lose a reply; the text goes.

Backups — deleted data persists in routine backups for a short period before those backups roll off. It is not restored to the live Service.

Technical logs — kept for a short period by our providers under their own retention schedules, then discarded.

Abuse and moderation records — a minimal record of a suspension is kept for as long as needed to enforce it and to defend a claim about it.

9. Your rights

Wherever you are, you can ask us to: give you a copy of your data; correct it; delete it; restrict or stop a particular use; or send it to you in a portable form. Where we rely on consent you can withdraw it, and where we rely on legitimate interests you can object.

Self-service, today. Everything you can see you can copy — every rule is downloadable as Sigma from its own page, and your profile is editable in settings. Making your profile private, or unpublishing a rule, takes effect immediately.

There is no self-service account deletion yet. Write to the Operator's privacy contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live) and we will delete the account, which removes the profile, rules, comments, verdicts and reactions with it — they are tied to it in the database. Published rules that other people have already copied are already copied, and a licence granted under section 5 of the Terms survives; deletion reaches our copy, not theirs.

Exercising a right costs nothing and we will not treat you differently for it. If you think we have handled your data badly, tell us first — and you also have the right to complain to your data protection authority (in the EU, the one where you live or work; in the UK, the Information Commissioner’s Office).

10. If you are in California

The categories we collect, why, and who receives them are set out in sections 2, 3 and 6 — read those as our notice at collection.

We do not sell your personal information and we do not share it for cross-context behavioural advertising, as the CCPA defines those terms. We have not done so in the past twelve months, including for anyone under 16. There is therefore no “Do Not Sell or Share” link, because there is nothing to opt out of.

You have the right to know, delete and correct, and to be free from retaliation for asking. Use the address in section 1; we will verify a request against your account email. You may use an authorised agent.

11. Children

Siemphony is for security professionals and is not directed to children. You must be 18 or older to hold an account. We do not knowingly collect data from anyone under 18; if we learn that we have, we delete it and close the account. If you believe a child has given us data, write to the Operator's privacy contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live).

12. Security, stated honestly

Access is enforced at the database with row-level security, so who can read what does not depend on the interface asking nicely. Passwords are hashed. Sessions expire and refresh. Traffic is encrypted in transit.

No service is impregnable and we are not going to tell you this one is. Siemphony is early software. We audit it and we fix what we find, including things we broke ourselves. If a breach affects your personal data and is likely to put you at risk, we will tell you and the relevant authority without undue delay, as the law requires.

Found a vulnerability? Report it to the Operator's security contact address (not yet published — the mailbox is being set up, and this page will name it the day it is live). Please give us reasonable time to fix it before publishing. We will not pursue anyone acting in good faith under this paragraph.

13. Changes

If this policy changes in a way that affects what we collect, why, or who sees it, the date at the top changes and we say so on the Service rather than hoping you re-read it. Where the law requires your consent to a change, we will ask for it.