Privacy Policy
Last updated: May 2026
See also: Terms and Conditions · Documentation
This Privacy Policy explains how DockerSec collects, uses, stores, and protects personal data when you use dockersec.com.
DockerSec is the data controller for the purposes of UK data protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018.
This Policy should be read alongside our Terms and Conditions.
1. What DockerSec Does
DockerSec provides Dockerfile security analysis. Users may submit Dockerfile content anonymously or through an account. DockerSec analyses the submitted content and returns findings that may indicate security risks, weaknesses, or insecure configuration patterns.
2. Personal Data We Collect
We collect and process the following types of personal data.
Submitted Dockerfiles
When you submit a Dockerfile, we store a copy of the submitted content alongside the analysis results.
Dockerfiles may contain personal data or information that identifies systems, organisations, users, environments, internal hostnames, email addresses, credentials, secrets, or other sensitive values. You should review Dockerfiles before submission and avoid submitting information that is not necessary for analysis.
DockerSec automatically attempts to detect and replace credential-like values, such as passwords, tokens, and API keys, before storage. The original values are not intentionally written to the database. This process is designed to reduce risk, but it should not be treated as a guarantee that every sensitive value will be detected or removed.
Further details are provided in the Documentation.
Analysis Results
We store the findings generated from submitted Dockerfiles. These may include technical details about the submitted Dockerfile and the risks identified by DockerSec.
For registered users, analysis results may be retained as part of the user's submission history.
IP Addresses
We record IP addresses when Dockerfiles are submitted. This is used for rate limiting, abuse prevention, service security, and operational monitoring.
We also record IP addresses associated with failed login attempts to help detect and prevent unauthorised access.
IP Geolocation and Network Information
For security monitoring purposes, DockerSec sends IP addresses to ipapi.is to obtain approximate geolocation and network information. This may include an approximate country, region, city, autonomous system, and indicators of whether an IP address appears to belong to a VPN, proxy, hosting provider, or data centre.
This information is used only for security, abuse prevention, and administrative monitoring. It is not visible to other users.
Results from ipapi.is are cached in our database for up to seven days to reduce the frequency with which IP addresses are transferred to that service.
You can read ipapi.is's privacy information at: ipapi.is/privacy.html.
Account Information
If you create an account, we store your email address and a securely hashed copy of your password. Passwords are stored as cryptographic hashes in accordance with OWASP and NCSC guidance and cannot be read or recovered from the stored value.
We may also store account-related metadata, such as account creation time, login activity, verification status, and password reset activity.
Session Data
We use a session cookie to keep you signed in and to operate account features.
| Cookie | Purpose | Duration |
| --- | --- | --- |
| sid | Keeps you signed in and maintains your session | 30 days |
This cookie is used only to provide the service. It is not used for advertising or cross-site tracking.
No advertising or analytics cookies are currently used.
Transactional Email Data
If you create an account, verify your email address, reset your password, or receive service-related messages, your email address and message metadata may be processed by our transactional email provider.
3. Why We Use Personal Data
We use personal data for the following purposes:
- to provide Dockerfile analysis and return security findings;
- to maintain submission history for registered users;
- to operate user accounts;
- to authenticate users and maintain sessions;
- to prevent abuse, excessive use, unauthorised access, and attacks against the service;
- to monitor service security and reliability;
- to send transactional emails, such as account verification and password reset messages;
- to investigate faults, abuse, or security incidents;
- to comply with legal obligations.
We do not sell personal data and do not share it with third parties for advertising purposes.
4. Lawful Bases for Processing
We rely on the following lawful bases under UK GDPR.
| Purpose | Lawful basis | | --- | --- | | Providing Dockerfile analysis | Contract, or steps taken at your request before entering into a contract | | Maintaining account features and submission history | Contract | | Storing submitted Dockerfiles and results for registered users | Contract | | Rate limiting and abuse prevention | Legitimate interests | | Login security and failed-login monitoring | Legitimate interests | | IP geolocation for security monitoring | Legitimate interests | | Service security, logging, and incident investigation | Legitimate interests | | Transactional account emails | Contract or legitimate interests | | Compliance with legal obligations | Legal obligation |
Our legitimate interests include keeping DockerSec secure, preventing misuse, protecting user accounts, ensuring service availability, and detecting unauthorised or abusive activity.
Where we rely on legitimate interests, we balance those interests against the rights and freedoms of affected individuals.
5. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy.
| Data | Retention period | | --- | --- | | Submitted Dockerfiles from registered users | Until deleted on request or account closure, unless retention is required for security, legal, or operational reasons | | Submitted Dockerfiles from anonymous users | Retained for operational purposes and deleted according to our internal retention process | | Analysis results for registered users | Until deleted on request or account closure, unless retention is required for security, legal, or operational reasons | | IP addresses used for rate limiting | 24-hour rolling window | | IP addresses associated with failed login attempts | 90 days | | IP geolocation and network lookup results | Up to 7 days per IP address | | Account information | Until the account is closed, unless retention is required for security, legal, or operational reasons | | Session data | Up to 30 days of inactivity | | Transactional email records | Retained by our email provider according to its operational and compliance practices |
Where data is deleted, it may remain in backups for a limited period before being overwritten or removed through normal backup rotation.
6. Third-Party Services
We use the following third-party services that may process personal data on our behalf or in connection with the service.
| Service | Purpose | Privacy information | | --- | --- | --- | | ipapi.is | IP geolocation and network information for security monitoring | ipapi.is/privacy.html | | Postmark | Transactional email, including account verification and password reset messages | postmarkapp.com/privacy-policy |
These services may process data outside the United Kingdom. Where this occurs, we take steps intended to ensure that appropriate safeguards are in place.
7. International Transfers
Some third-party service providers may process personal data outside the UK.
Where personal data is transferred internationally, we rely on appropriate safeguards or transfer mechanisms recognised under UK data protection law, where required.
8. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, and disclosure.
These measures include password hashing, access controls, credential-like value replacement for submitted Dockerfiles, operational monitoring, and limits on administrative access.
No internet-facing service can be guaranteed to be completely secure. You should avoid submitting unnecessary secrets, credentials, personal data, or commercially sensitive information.
9. Your Rights
Under UK data protection law, you may have the right to:
- request access to the personal data we hold about you;
- ask us to correct inaccurate or incomplete personal data;
- ask us to delete your personal data;
- ask us to restrict processing;
- object to processing based on legitimate interests;
- request a copy of your personal data in a structured, commonly used, machine-readable format;
- complain to the Information Commissioner's Office.
These rights are not absolute and may depend on the circumstances.
To exercise your rights, please use the contact form provided on the DockerSec website.
We will respond without undue delay and normally within one month. If your request is complex or you make multiple requests, we may extend the response period by up to two further months, as permitted by law.
10. Complaints
If you have concerns about how we handle your personal data, please contact us first so that we can try to resolve the issue.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection.
The ICO's website is: ico.org.uk.
11. Children
DockerSec is not intended for use by children. If you believe that a child has provided personal data to DockerSec, please contact us so that we can review and, where appropriate, delete the relevant information.
12. Changes to This Policy
We may update this Privacy Policy from time to time.
When we make changes, we will post the updated version on this page and update the "Last updated" date. Where changes are material, we will take reasonable steps to bring them to users' attention.
13. Contact
For privacy-related enquiries, or to exercise your data protection rights, please use the contact form provided on the DockerSec website.