PressCEO Secure.com Named a Middle East Security Leader to Watch
PodcastListen to Our CEO on the Heavy Strategy Podcast — Now Streaming
PressTechRound interviews Secure.com CEO on the future of AI security
InterviewTahawul Tech: "Security Without Accountability Is the New Risk" — Uzair Gadit - CEO Secure.com
PressCEO Secure.com Named a Middle East Security Leader to Watch
PodcastListen to Our CEO on the Heavy Strategy Podcast — Now Streaming
PressTechRound interviews Secure.com CEO on the future of AI security
InterviewTahawul Tech: "Security Without Accountability Is the New Risk" — Uzair Gadit - CEO Secure.com
Secure.com
  • Solutions
    By Company Size
    EnterpriseA portfolio of Digital Security Teammates mapped to real security functions
    Mid-MarketScale security operations without scaling headcount
    EssentialAdvancedStrategic (Coming Soon)
    StartupFoundational security from day one, without complexity
    By Teammate
    SOC TeammateCompliance TeammateAppSec TeammateInfrastructure Security TeammateRisk & Governance Teammate
    By Role
    CISOReduce risk, stay audit-ready and prove security ROICTOShip faster while staying secure and compliant
  • Product
    Product OverviewIntegrations
  • Case Studies
    Mid-Market SaaSFrom Two Analysts to 24/7 CoverageVyro.ai × Secure.comFrom Rapid Growth to Continuous, Automated Security
  • About us
  • Resources
    BlogNewsroomWhitepaperGlossary
About us
Cookie Policy

Cookie Policy

Secure.com·Last Updated: March 2026·Version 2.0

Table of Contents

1. Introduction2. What Are Cookies?3. How and Why We Use Cookies4. Types of Cookies We Use5. Detailed Cookie List6. Your Rights & Controls7. Third-Party Providers8. Where We Use These9. International Transfers10. Region-Specific Disclosures11. Security12. Changes to This Policy13. Contact Us

1. Introduction

This Cookie Policy explains how Secure.com ("we," "us," or "our") uses cookies and similar tracking technologies when you visit our website at https://www.secure.com, use our cybersecurity platform and Digital Security Teammate services, or interact with our web applications, browser extensions, or mobile applications (collectively, the "Services").

This policy explains what cookies are, why we use them, which third parties are involved, and how you can control them at any time.

This policy should be read alongside our Privacy Policy, which governs the broader collection and processing of your personal data.

2. What Are Cookies?

A cookie is a small text file saved on your device when you visit a website. It enables the website to remember your actions and preferences over time, so you do not need to re-enter information each time you visit.

Cookies are classified as either:

  • Session cookies — deleted automatically when you close your browser; or
  • Persistent cookies — stored on your device for a defined period or until you delete them.

We also use similar technologies including tracking pixels, web beacons, software development kits (SDKs), device identifiers, and HTML5 local storage (all referred to collectively as "cookies" throughout this policy for convenience). None of these technologies give us access to your device files or any other application on your device.

3. How and Why We Use Cookies

3.1 Legal Basis and Consent

We operate a default-deny model. Non-essential cookies are never activated until you have provided valid consent.

GDPR Compliance — Consent Standard

We set non-essential cookies only with your prior, freely given, specific, informed, and unambiguous consent, as required by Article 5(3) of the ePrivacy Directive (Directive 2002/58/EC) and the GDPR consent standard (Article 4(11) and Article 7 GDPR). Our legal basis for processing personal data collected through non-essential cookies is your consent (Article 6(1)(a) GDPR).

Essential cookies may be set without consent only where strictly necessary to: (a) transmit a communication over an electronic communications network; or (b) provide an information society service you have expressly requested. The legal basis for processing personal data via essential cookies is our legitimate interests in maintaining platform security and integrity (Article 6(1)(f) GDPR).

3.2 How We Obtain Your Consent

We obtain your consent through an interactive cookie banner displayed on your first visit. Non-essential cookies are not activated until you interact with the banner and grant consent by category (Functional, Analytics, and Advertising).

3.3 Withdrawing or Changing Consent

You may withdraw or amend your consent at any time by clicking "Cookie Settings" in the footer of any page. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

3.4 Transparency and Consent Records

Our Cookie Settings panel contains a live inventory listing each cookie, its provider, purpose, duration, and category. We keep this inventory current. If we make material changes — for example, adding a new advertising vendor or changing a cookie's stated purpose — we will notify you and, where required, prompt you for renewed consent before any new cookies are activated.

4. Types of Cookies We Use

4.1 Essential Cookies

Essential cookies are required for the Services to function. They enable secure login, page navigation, fraud prevention, load balancing, and bot mitigation. These cannot be disabled without impairing functionality. They are set without your consent under the operational necessity exemption of the ePrivacy Directive.

4.2 Functional Cookies

Functional cookies remember your preferences and enable enhanced features. We set these only with your prior consent. Some functional cookies are provided by third parties.

4.3 Performance and Analytics Cookies

Analytics cookies collect information about how you use the Services — such as pages visited and errors encountered. Data is often aggregated or anonymised and helps us improve the platform. We set these only with your prior consent.

4.4 Advertising Cookies

Advertising cookies deliver relevant advertisements, limit ad frequency, and measure campaign effectiveness. This category includes social media cookies and may support cross-context behavioural advertising. We set these only with your prior consent.

5. Detailed Cookie List

The following table lists all cookies and similar technologies currently active across our Services. This inventory is updated in real time in our Cookie Settings panel.

Essential Cookies

Cookie NameProvider / DomainPurposeDuration
__cf_bm.twitter.com, .apollo.io, .linkedin.com, .t.coCloudflare bot management. Distinguishes legitimate visitors from automated bot traffic and activates threat-mitigation protocols.30 Minutes
X-CSRF-TOKENaplo-evnt.comPrevents Cross-Site Request Forgery (CSRF) using a double-submit token pattern. Required for authenticated actions.Session

Functional Cookies

Cookie NameProvider / DomainPurposeDuration
apolloAnonIdwww.secure.comGenerates a persistent, anonymous identifier for behavioural interaction mapping via the Apollo B2B platform.Persistent
68e36746427f8e001922b6d3_canTrackwww.secure.comRecords tracking capability status and your consent state for the Apollo B2B engagement suite.Persistent
68e36746427f8e001922b6d3_eventQueuewww.secure.comLocal storage buffer that queues user interaction events before transmitting them asynchronously to Apollo servers.Persistent

Analytics Cookies

Cookie NameProvider / DomainPurposeDuration
_ga.secure.comGoogle Analytics primary identifier. Tracks distinct users and aggregates site-usage metrics.2 Years
_ga_#.secure.comGoogle Analytics session tracker. Measures page views and session-level data.2 Years
s7.secure.com, .linkedin.com, .twitter.com, .t.co, aplo-evnt.comAdobe Analytics engine. Aggregates cross-domain site usage and behavioural data.Persistent
rp.gifalb.reddit.comReddit tracking pixel. Measures inbound traffic and engagement from Reddit.Session
17682254525www.google.comGoogle Analytics correlator. Tracks user sessions and mapping across Google infrastructure.Persistent

Advertising Cookies

Cookie NameProvider / DomainPurposeDuration
_fbp.secure.comMeta (Facebook) tracking pixel. Identifies visitors for personalised retargeting and ad attribution.90 Days
IDE.doubleclick.netGoogle DoubleClick. Measures ad conversion rates.1.5 Years
test_cookie.doubleclick.netDiagnostic check to verify that the browser supports cookies before delivering ads.15 Minutes
_ttp.tiktok.com, .secure.comTikTok pixel. Tracks and measures the effectiveness of TikTok advertising campaigns across devices.13 Months
_tt_enable_cookie.secure.comValidates that the browser environment can process TikTok pixel payloads.13 Months
tt_appInfowww.secure.comRecords settings and logs interactions with embedded TikTok video content.1 Year
lastExternalReferrerTimewww.secure.comMeta attribution: records the timestamp of the last inbound referral link click.Persistent
lastExternalReferrerwww.secure.comMeta attribution: records the URL that directed traffic to the site.Persistent
bcookie.linkedin.comLinkedIn browser identifier. Optimises the geographic and demographic range of LinkedIn advertising.1 Year
lidc.linkedin.comLinkedIn infrastructure routing. Optimises server-cluster selection for lower latency.1 Day
UserMatchHistory.linkedin.comLinkedIn Ad ID synchronisation. Maps anonymous site visitors to LinkedIn professional profiles for targeted advertising.1 Month
bscookie.www.linkedin.comLinkedIn Sign-In and Follow feature cookie.1 Year
ar_debugpx.ads.linkedin.comAssists in debugging LinkedIn and DoubleClick ad-serving integrations.30 Days
_gcl_au.secure.comGoogle Ads conversion linker. Tests and measures the efficiency of Google advertisement placements.3 Months
_gcl_lswww.secure.comLinks conversion events and site telemetry to the Google Marketing Platform.13 Months
guest_id.twitter.comX (Twitter) identifier. Monitors referral patterns and collects behavioural data for advertising.730 Days
personalization_id.twitter.comX (Twitter) advertising tool. Personalises ads based on social media engagement.730 Days
_rdt_uuid.secure.comReddit attribution cookie. Stores event-match data to attribute conversions to Reddit advertising campaigns.90 Days

6. Your Rights and Cookie Controls

6.1 Your GDPR Data Subject Rights

Where personal data is processed via cookies, you have the following rights under the GDPR (subject to applicable exemptions and conditions):

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate personal data.

Right to Erasure

Request deletion of your personal data.

Right to Restrict Processing

Request that we limit how we use your data.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

Right to Withdraw Consent

Withdraw consent at any time without affecting the lawfulness of prior processing.

Right to Lodge a Complaint

Contact your local supervisory authority (e.g., your EU data protection authority or the UK ICO).

To exercise any of the above rights, please contact us at legal@secure.com. We will respond within 30 days.

6.2 Cookie Settings Centre

You can manage, grant, or revoke consent by category at any time via our Cookie Settings panel, accessible through the persistent link in the footer of every page.

6.3 Browser-Level Controls

You can also block or delete cookies directly in your browser settings:

  • Google Chrome: Settings > Privacy and Security > Cookies and other site data
  • Apple Safari: Preferences > Privacy > Manage Website Data
  • Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
  • Microsoft Edge: Settings > Cookies and site permissions > Cookies and site data

Please note that blocking cookies at browser level may impair certain features of our Services.

6.4 Do Not Track and Global Privacy Control

We do not currently respond to the legacy "Do Not Track" (DNT) browser signal, as no uniform standard for its interpretation exists. We actively evaluate compatibility with the Global Privacy Control (GPC) signal. Where legally required — including under the CCPA/CPRA — we honour GPC signals as valid opt-out requests for cross-context behavioural advertising.

7. Third-Party Service Providers

We use both first-party cookies (set by our own domains) and third-party cookies (set by external providers). Our key third-party cookie providers include:

  • Security: Cloudflare, Inc.
  • Analytics: Google LLC (Google Analytics), Adobe Systems Incorporated
  • Advertising and Social Media: Meta Platforms, Inc., LinkedIn Corporation, TikTok Inc., Reddit, Inc., X Corp. (Twitter), Google LLC (Google Ads / DoubleClick)
  • B2B Marketing Engagement: Apollo.io

When you grant consent via Cookie Settings, you authorise these third-party providers to run scripts in your browser, place storage objects, and transmit data to their own servers. These providers may combine data collected on our Services with data they hold about you from other online sources. We encourage you to review their individual privacy and cookie policies.

8. Where We Use These Technologies

Cookies and similar technologies are deployed across all surfaces of our digital ecosystem:

  • Public website at https://www.secure.com — where advertising pixels, analytics, and bot-mitigation cookies are primarily active.
  • Web applications and SaaS dashboards — where session management and essential security tokens operate.
  • Browser extensions — where session-state and performance cookies may be active.
  • Mobile applications — where SDKs and device advertising identifiers (Apple IDFA, Google AAID) are used in lieu of traditional HTTP cookies.

The same purposes, legal bases, and consent choices described in this policy apply across all surfaces, subject to operating system limitations imposed by device manufacturers.

9. International Transfers

Some third-party cookie providers are based outside your country, including outside the EU/EEA and UK. Where personal data collected via cookies is transferred internationally from the EU/EEA or UK to a country without an EU or UK adequacy decision, we ensure appropriate safeguards are in place, including:

  • European Commission Standard Contractual Clauses (SCCs); and/or
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs.

For further information on international transfers, please see our Privacy Policy.

10. Region-Specific Disclosures

10.1 EU/EEA and United Kingdom (GDPR and ePrivacy Directive)

We enforce a strict default-deny posture. No non-essential cookies — including _fbp, _ga, UserMatchHistory, or any advertising pixel — are activated until you provide explicit, affirmative consent via our cookie banner. Essential cookies (X-CSRF-TOKEN and __cf_bm) operate under the operational necessity exemption only. You may withdraw consent at any time via Cookie Settings.

10.2 California, USA (CCPA/CPRA)

We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising as defined under California law. We honour Global Privacy Control (GPC) signals as valid opt-out requests. We do not use sensitive personal information to infer characteristics beyond purposes expressly permitted by the CPRA.

10.3 Brazil (LGPD)

All functional, analytical, and advertising cookies are set only on the basis of your explicit consent (LGPD, Article 7(I)). Brazilian data subjects hold the rights of confirmation, access, correction, anonymisation, portability, deletion, and information on data sharing, as further described in our Privacy Policy. Consent may be revoked at any time via Cookie Settings.

10.4 Canada (PIPEDA and Provincial Laws)

We obtain meaningful, informed consent before activating any non-essential tracking technologies. We provide clear, friction-free mechanisms to withdraw consent. Some third-party providers may process data outside Canada; please see our Privacy Policy for applicable safeguards.

10.5 United Arab Emirates

Operating under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, our consent framework ensures transparency, data minimisation, and limitations on cross-border data transfers in accordance with UAE regulatory requirements.

11. Security

We implement technical and organisational measures to protect cookie data. Specifically:

  • Secure flag — cookies are transmitted only over encrypted HTTPS connections, preventing interception.
  • HttpOnly flag — sensitive session cookies are inaccessible to client-side JavaScript, mitigating cross-site scripting (XSS) risks.
  • SameSite attribute — set to Lax or Strict where appropriate, providing a secondary layer of CSRF protection alongside the X-CSRF-TOKEN.

Cookie data is processed within environments governed by SOC 2 Type II and ISO 27001 compliance standards. Cookies cannot access files or information on your device beyond what the technology itself stored.

12. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in the cookies we use, or for operational, legal, or regulatory reasons. Please check this page periodically to stay informed.

If we make material changes — such as adding a new advertising provider, changing a cookie's stated purpose, or extending a cookie's retention period — we will notify you and, where required by law, display a renewed consent prompt before new cookies are activated.

13. Contact Us

If you have questions about this Cookie Policy, wish to exercise your data subject rights, or want to raise a concern about our use of cookies, please contact us:

Email

legal@secure.com

Privacy Policy

https://www.secure.com/privacy-policy

Postal Address

Secure.com · Nassima Tower, Office 2001 · Trade Centre 1 · Dubai, UAE

Response Time

We aim to respond to all privacy and cookie enquiries within 30 days.

© 2026 Secure.com. All rights reserved. This Cookie Policy is effective as of March 2026 and supersedes all prior versions.

Secure.com

© 2026

InstagramFacebookXLinkedIn

Product

Product OverviewFree trialIntegrations

Compare

vs AI SOCvs Dropzone AIvs Intezervs Torq

Company

About UsNewsroomPartner ProgramAffiliatesCommunity

Resources

BlogWhitepapersGlossary

Help

support@secure.comPrivacy PolicyLegal & Compliance