Who we are
Response Red ("we", "us") provides incident response and digital forensics services through responsered.com.
What we collect
- Intake details. When you report an incident: name, company, work email, phone, incident type, and the description you provide.
- Payment information. Engagement fees are processed by our payment provider. We receive payment status and reference details; we never receive or store full card numbers.
- Technical data. Standard connection metadata (IP address, IP-derived approximate location, and network information) used for security, anti-abuse, and the transient connection readout shown on the site. It is not used to build visitor profiles.
What you should never submit through the website
Do not submit passwords, private keys, access tokens, regulated personal data, or confidential evidence through our forms. When an engagement requires sensitive material, a specialist establishes a secure channel first. Sensitive incident details are not logged by default.
How we use information
To respond to incident reports and inquiries, deliver and invoice engagements, protect the service against abuse, and meet legal obligations. We do not sell personal data, we do not share it for advertising, and we do not use it for marketing profiles.
Intake assistant
The intake assistant turns your plain-language description into a structured triage summary. This processing runs within our service infrastructure, and we do not use your submissions for any other purpose. The assistant provides preliminary, defensive triage guidance only.
Cookies and analytics
We use no advertising or cross-site tracking cookies. Traffic measurement is cookieless. Bot protection on our forms may set a strictly functional token.
Service providers
We rely on a small set of processors for hosting, security, analytics, payments, and transactional email, each bound by their own security and data protection commitments.
Retention and deletion
We keep intake and engagement records for as long as needed to deliver the engagement and to meet legal, accounting, and professional obligations. Clients can request access, correction, or deletion of their personal data through their engagement channel; we honor requests unless a legal obligation requires retention.
International operation
Response Red serves organizations worldwide, so data may be processed in multiple regions under the safeguards of our service providers.
Security
All traffic is encrypted in transit, the site enforces a strict content security policy and hardened headers, access follows least privilege, and, because incident response is our profession, we treat your data with the same discipline we bring to client engagements.
Changes
We update this page when our practices change and revise the effective date above. This site is not directed to individuals under 18.