Platform
Capabilities AI Agents Zero-Day Suite Reports & Evidence Integrations
Compare
Why PhantomYerra vs Mythos AI vs GPT-5.4 Cyber
Resources
Help Docs What's New Ask PhantomYerra Methodology Release Notes
 
Contact Request Access Client Login
Privacy Policy

How we handle your data

PhantomYerra is an authorized penetration testing platform. Client scan data is the most sensitive category of information any security tool will ever see — so our architecture is built around the principle that it does not leave your machine. This page explains exactly what data PhantomYerra collects, what it sends, and what it does not.

Effective: 2026-04-15 Applies to: PhantomYerra v45.x Publisher: Ravi Yerra Contact: privacy@phantomyerra.com

1 Scope

This policy applies to (a) the PhantomYerra desktop application (Windows, Linux, macOS), (b) the PhantomYerra marketing website at phantomyerra.com, (c) the PhantomYerra license service, and (d) the PhantomYerra auto-updater. It does not apply to third-party scanners or frameworks the user may configure outside the product.

PhantomYerra is produced by Ravi Yerra. References to “we”, “us”, and “PhantomYerra” refer to the publisher.

2 Client scan data stays local

Confidentiality architecture Scan targets, URLs, IP addresses, hostnames, company names, discovered credentials, extracted data, evidence, raw HTTP traffic, and PoC output never leave the operator’s machine unless the operator explicitly exports a report or uploads evidence to their own system.

PhantomYerra performs security scans on the operator’s own workstation. All raw telemetry — hosts, responses, headers, payloads, captured evidence — is written to the local database in %APPDATA%/PhantomYerra/data (Windows) or ~/.config/PhantomYerra/data (Linux/macOS).

When the optional AI-agentic mode is enabled, PhantomYerra runs a reference-token substitution layer before every AI API call. Real URLs, IPs, and company names are replaced with placeholders ([TARGET_URL_1], [COMPANY_REF], etc.) before the payload leaves the machine. The mapping table never leaves the local process.

Operators running in air-gapped or maximum-privacy mode can route all AI calls to a local model (such as Ollama), at which point no network egress occurs at all.

3 What is sent off the machine

Only a minimal, enumerable set of signals are sent outside the operator’s machine by default:

4 Telemetry and analytics

The PhantomYerra desktop application has telemetry off by default. We do not place analytics scripts that fingerprint the workstation. We do not send keystrokes, screen recordings, or clipboard contents.

The marketing website (phantomyerra.com) uses standard web-server access logs (source IP, User-Agent, path, timestamp) for security and abuse prevention. These logs are retained for 30 days and are not used to profile visitors. The site does not use third-party advertising trackers, cross-site tracking pixels, or ad cookies.

5 Contact form and lead data

When you submit the contact form on phantomyerra.com/contact, we collect:

This information is stored in a local SQLite database on the web server, used solely to respond to your inquiry, and retained for 24 months for sales-history purposes. You can request deletion at any time by emailing privacy@phantomyerra.com.

Lead data is not sold, rented, shared, or provided to third parties. Anti-spam honeypots and a 2-second time-check are in place; automated submissions are silently rejected.

6 Cookies

The marketing website uses only strictly necessary cookies for session integrity on authenticated pages (the client login portal). No advertising or analytics cookies are set. The PhantomYerra desktop application does not use browser cookies.

7 Security of stored data

8 Your rights

If you are in the EU, UK, California, or another jurisdiction with statutory privacy rights, you may:

Send requests to privacy@phantomyerra.com. We respond within 30 days.

9 International transfers

The PhantomYerra license service and marketing site are hosted in AWS us-east-1 (Northern Virginia, USA). If you are outside the United States, your lead-capture data will be transferred to and stored in the USA. Where required (EU, UK), transfers rely on Standard Contractual Clauses and additional technical safeguards (TLS 1.2+, encrypted at rest).

10 Children

PhantomYerra is not directed to users under 16. We do not knowingly collect data from minors. If a parent or guardian believes we have inadvertently collected such data, please contact privacy@phantomyerra.com and we will delete it.

11 Changes to this policy

Material changes are announced on the marketing site and reflected in the Effective date above. Continued use of the product after a change constitutes acceptance. You can review the commit history of this page in our public repository if you want to see what changed.

12 Contact

Privacy: privacy@phantomyerra.com
Security issues: security@phantomyerra.com — see our security policy.
General: phantomyerra.com/contact