[SESQUIVEL_SAAS_ENGINE_ONLINE]Continuous Multi-Cloud Attack Surface Management (ASM) SaaS
Return to Sesquivel Sentry
Zero-Trust Data Policy
Compliance & Data Governance Framework

Privacy Policy & Threat Telemetry Governance

Effective Date: September 2026 | Document Reference: SESQ-SEC-PRIV-v2.6 | Parent Entity: ArrowTech Marketing

1. Scope & Reconnaissance Philosophy

Sesquivel ("Sesquivel", "we", "us") operates continuous external attack surface discovery and defensive intelligence platforms, managed under ArrowTech Marketing digital infrastructure holding. We adhere to zero-retention principles for raw vulnerability payload probes. This Data Governance Policy governs our collection, storage, and isolation of perimeter telemetry and user account data.

2. Telemetry Ingestion & Non-Intrusive Probing

Perimeter discovery operates strictly on publicly accessible DNS zones, TLS certificates, internet-facing routing records, and unauthenticated public endpoints. Sesquivel does not perform invasive exploitation, data extraction, or denial-of-service tests against target perimeters.

  • Public DNS A/AAAA, CNAME, TXT, and MX routing hygiene records
  • X.509 TLS certificate transparency logs and cipher suite configurations
  • Public HTTP/HTTPS response headers and server software banners
  • Synthetic test alerts dispatched to customer-authorized webhook integrations

3. Account Security & Cryptographic Storage

All user credentials, authentication tokens, and session states are protected using Web Crypto PBKDF2 with 100,000 iterations and cryptographically unique salts. Authentication tokens are signed via HMAC-SHA256 and transmitted exclusively over TLS 1.3 with secure HttpOnly cookie encapsulation.

4. Third-Party Integrations & Sovereign Data Isolation

Sesquivel does not monetize, broker, or sell client attack surface datasets. Edge routing is protected by Cloudflare Global Anycast, and payments are processed directly via Stripe under PCI-DSS Level 1 compliance. Webhook alerts are delivered directly to customer-designated Slack and Discord endpoints over encrypted transport.

5. Contact & Statutory Inquiries

For privacy inquiries, security notifications, or data deletion requests, contact our centralized Data Governance Desk at:

ArrowTech Marketing — Governance & Security Desk

Domain Entity: sesquivel.biz

Direct Inquiries: /#contact

Physical Jurisdiction: State of California, United States