Privacy notice
Two different things are described here, and it matters which is which: this website, and the product you install in your own cluster. The product is the reason the website has so little to declare.
Controller: Portiger · security@portiger.com · Last updated 22 August 2026
This website
There is no analytics script, no tag manager, no advertising pixel and no third-party embed on these pages. Fonts, images and stylesheets are served from this domain, so loading a page tells no one but us that you were here.
The web server keeps standard access logs — IP address, timestamp, the path requested, the user agent — for up to 30 days, to keep the site running and to spot abuse. The legal basis is our legitimate interest in operating the service, and the logs are not used to build a profile of you or combined with anything else.
The site sets no cookies. See the cookie notice for the whole of that story, which is short.
The product
Portiger Kapan runs inside your own Kubernetes cluster. Your findings, image names, verdicts, exceptions and evidence packages are written to a PostgreSQL database you control. We have no access to them, no copy of them, and no channel through which they could reach us.
The operator makes exactly one kind of outbound request to us, for licensing, and the next section lists its contents field by field. There is no telemetry alongside it and no usage analytics: nothing reports what you scanned, which frameworks you opened, how many people logged in or what any of them did. Those things are counted inside your cluster where they happen, or not counted at all.
You are the controller for whatever personal data your own cluster processes, and we are not a processor of it — we never receive it.
Licensing: what leaves your cluster
Every installation is licensed, Community Edition included, so this section applies whether or not you pay us anything.
At activation, once per cluster, the installation sends the activation key
you were issued and a fingerprint of the cluster. The fingerprint is a hash of your
cluster's kube-system namespace identifier; it is an opaque value that
identifies the cluster to us without describing it, and it cannot be reversed into a name,
an address or anything about what runs there.
Once a day thereafter, the installation checks its licence with us and sends three values: the licence identifier, that same cluster fingerprint, and the operator version. The request reaches us over TLS and its source IP address appears in our server logs, as any request's does.
That is the complete list. Neither request carries:
- image names, digests, registries or any scan finding,
- CVE identifiers or anything about your vulnerabilities,
- workload, namespace, node or cluster names,
- cluster topology, size or configuration,
- user accounts, e-mail addresses or console activity,
- counts of what you scanned or which frameworks you use,
- any row, file or export from your database.
The limits your plan sets on images and frameworks are counted and enforced by the operator inside your own cluster, which is why no count needs to travel. The one limit we hold is the cluster count, because nothing inside a single cluster can see the others.
What we keep. The licence identifier, the cluster fingerprints bound to it with the date each was activated or released, the operator version last seen, and the timestamp of the most recent check. We keep these for as long as the licence exists plus the period our accounting obligations require, and the legal basis is performance of the contract — for a free licence, the same terms you accepted to obtain it. Server logs containing the source IP are kept for up to 30 days on the basis of our legitimate interest in operating and protecting the service, and are not combined with anything else.
What we do with it. Decide whether a licence may run on the cluster asking, count clusters against what was bought, and notice a key being spread across more of them than it pays for. Nothing here is used for profiling, advertising, or scoring you, and none of it is sold or shared with anyone but the processors that host the service.
When you write to us
If you e-mail kapan@portiger.com or security@portiger.com, we keep the message and your address for as long as it takes to deal with it and for a reasonable period afterwards, so a follow-up has context. Security reports are kept with the advisory they belong to.
Purchases are handled by Paddle as merchant of record. They collect billing details and handle VAT under their own privacy policy; we see the invoice and the plan, and never a card number.
Your rights
You can ask what we hold about you, ask for it to be corrected or erased, object to processing based on legitimate interest, or ask for a copy in a portable form. Write to security@portiger.com and you will get an answer within 30 days. If the answer does not satisfy you, you can complain to your local data protection authority.
We do not sell data, we run no advertising, and we make no automated decisions about you.