Tessera Cyber
Privacy Notice
A trading name of Pepaco Group LLC.
What this notice covers
This notice explains what information Tessera Cyber (a trading name of Pepaco Group LLC, based in Sharjah, United Arab Emirates) collects, how it is used, and how it is handled in connection with the Single Renewal Pilot external security assessment service.
What we collect
- The domain name being assessed
- Contact details for the broker and the authorized client contact (name, email, firm name)
- Assessment findings tied to the domain (e.g. header configuration, TLS status, DNS records, publicly detected library versions)
We do not collect or request: login credentials, internal system access, internal-control evidence (e.g. configuration exports, backup logs, or policy documents), or any personal data belonging to the client's own customers or employees beyond the named contact(s) above.
How we use it
- To perform the external assessment described in the Methodology
- To communicate findings and remediation status with the client's IT provider or MSP
- To produce the co-branded External Security Remediation Summary for the broker
Who we share it with
Findings and related information are shared only with: the broker who authorized the assessment, the authorized client contact, and (where remediation follow-up requires it) the client's named IT provider or MSP. We do not sell information, and we do not share it with any other third party except where required by law.
Third-party services
Two public data sources are queried as part of the assessment: OSV.dev (queried only with a library name and version number) and crt.sh (a public Certificate Transparency log lookup). Neither receives any personal or client-identifying data beyond what is already public.
Retention
Assessment findings and contact details are retained for 12 months after delivery of the final summary, then deleted, unless a longer period is needed to resolve an active dispute or to comply with a legal obligation.
Your rights
You may request a copy of the information we hold about your engagement, or request its deletion, by contacting ciso@tesseracyber.com.
Changes to this notice
This notice may be updated from time to time. The version in effect at the time of your engagement will be provided on request.