Privacy & Cookies

What we collect, why, and how to control it.

The short version: we count visits without cookies and store nothing on your device unless you accept, we never sell personal data, and our research publishes measurements, never exploit code.

Who we are

Vulnerability Research Labs (VRL) is a research unit of Quantro Security, in partnership with Loginsoft. This policy covers vulnerabilityresearchlabs.ai. Questions: privacy@vulnerabilityresearchlabs.ai.

Cookies & analytics

We do not place cookies unless you accept them. Before you accept — and if you decline — Google Analytics runs in cookieless mode: it counts a page view and records which campaign or link referred you, without storing anything on your device and without an identifier that follows you between visits. Accepting turns on analytics cookies and the organization-level tools below. You can decline and the site works the same.

What we measure before you accept

  • Aggregate traffic in Google Analytics 4 (GA4) in cookieless mode: pages viewed, approximate location, device and browser, and the campaign, search or referring site that sent you. No cookie is written and no persistent identifier is set, so visits cannot be linked to each other or to you.

What loads only after you accept

  • GA4 analytics cookies, which let us recognize a returning browser and measure a session across pages.
  • Leadfeeder (Dealfront), which identifies the organizations (not individuals) that visit, from IP-based company data, so we can understand which sectors engage with the research.
  • The LinkedIn Insight Tag, which measures how our LinkedIn campaigns perform.

Your choices

Accept or Decline via the cookie banner on your first visit; your choice is remembered in your browser. To change it, clear this site's cookies/local storage in your browser and reload. You can also use browser controls or extensions to block analytics at any time.

Forms you submit

If you submit a CVE (ai-xi), request a scan (ai-recon), or contact us, we process the details you provide (e.g. a CVE id, a domain, an email address) to fulfil that request. We do not sell personal data.

Subscribing to updates

If you subscribe, we store your email address (and name, if given) to send you research and product updates. You consent to this when you subscribe, and can unsubscribe at any time via the link in any email or by contacting us. We record your subscription in our backend and in HubSpot, our CRM, which processes it under its own terms. We do not sell personal data.

Data we publish

Our research is released TLP:CLEAR and concerns already-public CVEs. We publish measurements and findings, never working exploit code or proof-of-concepts.

Third parties

Analytics data is processed by Google (GA4) and, once you accept, Dealfront (Leadfeeder) and LinkedIn, each under their own terms. Submissions are processed by our backend (Quantro/VRL infrastructure); ai-recon scans are handled via the Quantro free-scan service.

Changes

We may update this policy as the site evolves; material changes will be reflected here.

Last updated · July 2026

Get research & product updates

No spam. Unsubscribe anytime. See our privacy policy.

Vulnerability Research Labs
Vulnerability Research Labs (VRL) is a research unit of Quantro Security, in partnership with Loginsoft.
Updated 17 Jul 2026 · n=3,029 · vulnerabilityresearchlabs.ai
© 2026 Vulnerability Research Labs (VRL). All rights reserved.