IAM X-ray
FeaturesModulesDemoBuyDownload the demoContactAccount
Download the demo
Privacy

IAM X-ray privacy

Effective September 6, 2026. DNA Technology, Toronto, Ontario, Canada.

Software licence termsPrivacyLegal noticesDNA Technology terms of service

This page covers the IAM X-ray website and the IAM X-ray licence service. Your DNA Technology account, the marketplace and payments are covered by theDNA Technology privacy policy. DNA Technology, Toronto, Ontario, Canada, is responsible for the information described here.

  1. This website
  2. What the app sends to the licence service
  3. What the app never sends
  4. What the licence service stores
  5. Why we use it
  6. Who we share it with
  7. How long we keep it
  8. How we protect it
  9. Your rights
  10. Changes and contact

1. This website

This site is static pages. It has no accounts, no forms, no analytics and no advertising, and it sets no cookies of its own. Two things happen when you load a page:

  • Our hosting provider (Google Firebase Hosting) receives the request, including your IP address and browser details, in order to serve the page and the download files. This is standard web server logging.
  • The pages load the Inter and JetBrains Mono fonts from Google Fonts, so your browser sends a request, including your IP address, to Google to fetch them.

When you download the software, the request for the file is logged in the same way. We do not link downloads to people.

2. What the app sends to the licence service

How often the app contacts us is your choice. In automatic delivery it contacts the licence service only for licensing: when you sign in, when you move or release a seat, and once per billing period to collect a fresh licence file. In manual delivery it makes no outbound connection at all, and you bring the licence file yourself. When it does contact us, the request carries some or all of:

ItemWhat it is
Device digestsSHA-256 digests of the Windows machine identifier, the system volume serial number and the mainboard serial number. The raw values never leave your machine. We cannot turn a digest back into the value.
HostnameThe computer name, so you can recognise the device on your account page.
App versionThe version of the software making the request.
Account id and emailThe id of your DNA Technology account and the email address on it, carried in the signed grant the marketplace issues when you confirm the sign in code.
Activation idA random identifier for the seat held by that device.
IP addressSeen by the service like any web request. It is used for rate limiting and stored only as a SHA-256 digest in the event log.

When you run iamxray update, the app fetches the update manifest and the new build from this site, which is logged as in section 1.

3. What the app never sends

The app does not send us anything it reads from your directories, tenants or hosts, or anything it derives from that: no user or group data, no findings, no reports, no snapshots, no dossiers, no automation audit records, no credentials. It has no usage telemetry and no crash reporting. In the trial and when signed out, apart from the sign in itself, it contacts nobody.

One optional feature contacts a third party: the breached password check sends the first five characters of each password hash to the Have I Been Pwned range service, which returns candidate matches without learning the full hash. It is off until you turn it on in your configuration.

4. What the licence service stores

  • Licence records: licence id, your account id and email, the marketplace offer id, tier, number of seats, trial flag, status and expiry, and the list of activations.
  • Activations: for each device holding a seat, the activation id, the device digests, the hostname, the app version, when it was activated, when it was last seen and when it was released.
  • Moves: the activation id, the hostnames involved and the time, used to apply the move allowance.
  • Sign in codes: the short code shown in the app, a hashed secret, the account that confirmed it and its status. These expire after 10 minutes.
  • Event log: an append only record of activations, refreshes, releases, moves, revocations and entitlement updates, with the client IP address stored only as a SHA-256 digest.
  • Rate limit counters: hourly counters per subject and per hashed IP address, which expire automatically.

5. Why we use it

To know how many devices hold seats on a licence and enforce that number, to let you see and release devices, to apply the trial and move rules, to stop abuse of the service, to answer support requests, and to keep a record of what happened to a licence and when. We do not use this information for advertising or profiling, and we do not sell it.

6. Who we share it with

  • The DNA Technology marketplace tells the licence service about your entitlement (account id, email, status, seats, tier, trial, expiry) whenever it changes, and reads back the list of devices for your account page. Both sides are operated by DNA Technology.
  • Google (Firebase and Google Cloud) hosts the site, the download files and the licence service and processes the data on our behalf.
  • Payment providers (Stripe and PayPal) are used by the marketplace, not by the licence service. The licence service never sees card details. See the DNA Technology privacy policy.
  • Authorities, when the law requires it.

Some of these providers store data outside Canada, in particular in the United States. It is then subject to the laws of those places.

7. How long we keep it

  • Sign in codes: 10 minutes, then deleted automatically.
  • Rate limit counters: about an hour, then deleted automatically.
  • Licence records, activations and moves: for as long as the licence exists and for up to 24 months after it ends, so we can answer support and billing questions and detect abuse.
  • Event log: up to 24 months.
  • Hosting request logs: kept by Google Firebase Hosting under its retention rules; we do not export them.

You can shorten this for your account by asking us to delete it (section 9), subject to records we must keep by law.

8. How we protect it

Device identifiers are hashed on your machine before they are sent. IP addresses are hashed before they are logged. Activation tokens are signed by us and stored on your device encrypted with Windows data protection. The licence database allows no direct client access; only our service code reads and writes it. Entitlement updates from the marketplace are authenticated with a signed partner API. No method is perfect; if we learn of a breach affecting your information we will tell you as the law requires.

9. Your rights

DNA Technology follows the Personal Information Protection and Electronic Documents Act (PIPEDA). You may ask us:

  • what personal information we hold about you and how we use it;
  • to correct information that is wrong;
  • to delete information we no longer need, subject to records we must keep;
  • to withdraw consent to a use, understanding that the licence service cannot work without the items in section 2.

Write to privacy@dnatechnology.ca. We answer within 30 days. If you are not satisfied with our answer you may complain to the Office of the Privacy Commissioner of Canada. If you live in Quebec, British Columbia or Alberta, your provincial law and commissioner may apply as well. If you live outside Canada you may have additional rights under your local law.

The software is for use by organisations and professionals. It is not directed at children and we do not knowingly collect information from anyone under 18.

10. Changes and contact

We will update this page when the site or the licence service changes what it collects. The date at the top says when the current version took effect.

DNA Technology, Toronto, Ontario, Canada. Privacy: privacy@dnatechnology.ca.

IAM X-ray and AutomationA DNA Technology productDNA Technology
Download the demoBuyMarketplaceAccountTermsPrivacyLegalContact
© 2026 DNA Technology, Toronto, Ontario, Canada.