1. About This Policy
This Cookie Policy explains how Eureka DevSecOps Inc. ("Eureka," "we," "us") uses cookies and similar technologies on https://eurekadevsecops.com (the "Website") and in our application security platform (the "Service"). It should be read together with our Privacy Policy. Cookies are small text files placed on your device by a website. We also use similar technologies , local storage, pixels, and SDK identifiers, and this Policy covers those too. Cookies are either first-party (set by us) or third-party (set by a service we use), and either session (deleted when you close your browser) or persistent (remaining until they expire or you delete them).
2. How We Use Cookies
We use cookies in four categories. Only the first category is strictly necessary; the others are used as described below and, where required by law, with your consent.
| Category | Purpose | Can it be disabled? |
|---|---|---|
| Essential | Sign-in, session integrity, and security (including CSRF protection and anti-abuse). | No, the Website and Service cannot function without these |
| Functional | Remembering preferences such as UI state, dismissed notices, and scheduling widgets. | Yes, some convenience features degrade |
| Analytics | Understanding how visitors use the Website and how customers use the Service. | Yes |
| Marketing (future) | Measuring campaigns and tailoring outreach, not currently in use. | Yes |
3. Cookies and Technologies We Use
The inventory below reflects a scan of the live Website. We reconcile this table whenever our tag configuration changes.
| Category | Cookie / technology | Provider | Purpose | Duration |
|---|---|---|---|---|
| Essential | Session & authentication (incl. XSRF-TOKEN) | Eureka | Keep you signed in; protect against cross-site request forgery | Session / up to 30 days |
| Essential | __cf_bm and related security cookies | Cloudflare | Bot detection, anti-abuse, and load distribution | Session / up to 30 min |
| Functional | Preference cookies | Eureka | Remember UI settings and dismissed banners | Up to 12 months |
| Functional | Calendly (calendly-store) | Calendly | Enable the demo / meeting scheduling widget | Session / local storage |
| Consent | Consent record | Eureka / consent tool | Remember your cookie and contact preferences | 6–12 months |
| Analytics | _ga, _ga_* (Google tag GT-P35HXDW) | Google Analytics 4 | Distinguish visitors; measure traffic and page performance | Up to 14 months |
| Analytics | ph_* (cookies / local storage) | PostHog | Understand how the Website and Service are used (features, funnels) | Up to 12 months |
| Analytics | Cloudflare Web Analytics | Cloudflare | Privacy-friendly, cookieless traffic measurement | No cookie (cookieless) |
| Analytics / CRM | __hstc, hubspotutk, __hssc, __hssrc | HubSpot | On contact and demo forms: recognize returning visitors and connect a submission to its source | Up to 13 months |
| Marketing | None in use | , | No advertising or retargeting cookies are currently set | , |
We configure analytics conservatively: IP addresses are used to derive approximate location and are not used to identify individual visitors, and analytics tools do not receive Customer Content (your scanner findings and vulnerability data are never shared with advertising or analytics networks).
Marketing cookies (future)
We do not currently use advertising or retargeting cookies. If we introduce them (for example, LinkedIn Insight Tag or Google Ads conversion tracking), we will update this Policy and the table above before deployment, classify them as non-essential, and request consent where required by law before they are set.
4. Your Choices
4.1 Consent
Where we collect your details through a contact or demo form, we ask for your explicit consent to contact you and to store your details in accordance with our Privacy Policy. Where required by applicable law, non-essential analytics and functional cookies are used on the basis of your consent, and you can change your choices at any time using the controls described below. We honour your choice before setting non-essential cookies.
4.2 Browser controls
All major browsers let you block or delete cookies through their settings (typically under "Privacy" or "Site settings" in Chrome, Firefox, Safari, and Edge). Blocking essential cookies will prevent sign-in and parts of the Website from working.
4.3 Tool-specific opt-outs
Google Analytics: install the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout), or decline analytics cookies where a banner is presented.
PostHog: decline analytics cookies where a banner is presented; product analytics can also be addressed in enterprise agreements.
HubSpot: decline functional/analytics cookies where a banner is presented; HubSpot cookies are also removable via browser controls.
4.4 Global Privacy Control and Do Not Track
Where the CCPA or similar laws apply, we treat a Global Privacy Control (GPC) signal as an opt-out of any "sale" or "sharing" of personal information; note that we do not sell or share personal information as those terms are defined in the CCPA. There is no industry consensus on responding to legacy "Do Not Track" signals, and like most services we do not respond to DNT.
5. Third-Party Services
Third parties that set cookies through our Website process data under their own privacy policies: Google (policies.google.com/privacy), PostHog (posthog.com/privacy), HubSpot (legal.hubspot.com/privacy-policy), Cloudflare (cloudflare.com/privacypolicy), and Calendly (calendly.com/privacy). Where these providers process personal information for us, they do so under data protection terms as our subprocessors (see Privacy Policy).
6. Changes to This Policy
We will update this Policy when our cookie usage changes, including before any marketing cookies are introduced, and will refresh the "Last updated" date. Material changes will be flagged via the cookie banner or a Website notice.
7. Contact
Questions about this Policy or our use of cookies: [email protected]. Eureka DevSecOps Inc., 555 W Hastings St #1200, Vancouver, BC V6B 4N6, Canada.
Cookie Preferences
- Strictly NecessaryAlways active
Sign-in, session integrity, and security (including CSRF protection and anti-abuse).
- Functional
Remembering preferences such as UI state, dismissed notices, and scheduling widgets.
- Analytics
Understanding how visitors use the Website and how customers use the Service.
- Marketing (future)
Measuring campaigns and tailoring outreach, not currently in use.