Who we are
Response Red ("we", "us") provides AI-assisted incident response and digital forensics services through responsered.com. Response Red is part of the same security group as CyberLink Security and RaptorLabs. For anything in this policy, contact [email protected].
What we collect
- Intake and contact details. When you report an incident or contact us: name, company, work email, phone, incident type, and the description you provide.
- Payment information. Engagement fees are processed by Stripe. We receive payment status and reference details; we never receive or store full card numbers.
- Technical data. Standard connection metadata (IP address, IP-derived approximate location, and network information) used for security, anti-abuse, and the transient connection readout shown on the site. It is not used to build visitor profiles.
What you should never submit through the website
Do not submit passwords, private keys, access tokens, regulated personal data, or confidential evidence through our forms. When an engagement requires sensitive material, a specialist establishes a secure channel first. Sensitive incident details are not logged by default.
How we use information
To respond to incident reports and inquiries, deliver and invoice engagements, protect the service against abuse, and meet legal obligations. We do not sell personal data, we do not share it for advertising, and we do not use it for marketing profiles.
AI processing
The intake assistant turns your plain-language description into a structured triage summary. This processing runs on our infrastructure provider (Cloudflare Workers AI by default), its output is reviewed by human responders, and we do not use your submissions to train AI models. The assistant provides preliminary, defensive triage guidance only.
Cookies and analytics
We use no advertising or cross-site tracking cookies. Traffic measurement uses Cloudflare Web Analytics, which is cookieless. Cloudflare Turnstile protects our forms from bots and may set a strictly functional token. The staff-only operations console uses a session cookie for authorized personnel.
Service providers
We rely on a small set of processors, each bound by their own security and data protection commitments: Cloudflare (hosting, content delivery, security, analytics, and AI processing), Stripe (payments), and Resend (transactional email). Incident records are stored in Cloudflare's database infrastructure.
Retention and deletion
We keep intake and engagement records for as long as needed to deliver the engagement and to meet legal, accounting, and professional obligations. You can request access, correction, or deletion of your personal data at [email protected]; we honor requests unless a legal obligation requires retention.
International operation
Response Red serves organizations worldwide and operates on a global edge network, so data may be processed in multiple regions under the safeguards of the providers listed above.
Security
All traffic is encrypted in transit, the site enforces a strict content security policy and hardened headers, access follows least privilege, and — because incident response is our profession — we treat your data with the same discipline we bring to client engagements.
Changes
We update this page when our practices change and revise the effective date above. This site is not directed to individuals under 18.