Privacy Policy Requirements: What Your Policy Must Disclose (Guide)
A privacy policy must disclose who you are and how to contact you, what personal data you collect, why you collect it, who receives it, how long you […]
Research & intelligence
Research, analysis, and conversations that connect privacy, AI, and cyber decisions to observed data movement.
Browse the evidence libraryInsight
Field intelligence and practical analysis.
A privacy policy must disclose who you are and how to contact you, what personal data you collect, why you collect it, who receives it, how long you […]
Session replay is a digital analytics technology that records what a visitor does on a website (clicks, scrolls, form entries, including text never submitted) and rebuilds it as […]
The General Data Protection Regulation (GDPR) is the EU’s comprehensive data privacy law, effective since 25 May 2018. It applies to any organization worldwide that offers goods or […]
Research Article
Original research with transparent methods, findings, and evidence.
Passwords and personal data don’t have to be stolen to end up somewhere they shouldn’t. When an application writes them into a URL or a page title, ordinary analytics, monitoring, and fraud tools collect them by default. A Klaviyo sign-up form with no method attribute sent our test password to 31 third-party hostnames – the same omission we measured on 7,874 websites with credential- or PII-bearing forms across the top 100,000 websites
White paper
Executive guidance for high-consequence decisions.
How non-affirmative AI coverage, hidden AI dependencies, and unobserved data flows create growing underwriting and portfolio risk.
Webinar
Live and recorded conversations with risk leaders.
The first publication in this collection is being prepared.
Case study
Evidence stories from underwriting, privacy, AI governance, and remediation workflows.
The first publication in this collection is being prepared.