Cookie Policy
Transparency by default. Learn how BROOT SECURITY utilizes minimal cookie structures to maintain session state and edge firewall security.
Essential Session Cookies
Used to manage active user sessions and portal authentication. These cookies contain encrypted JSON Web Tokens (JWT) to securely identify you as you navigate the assessment panel and switch tenants.
Preference Cookies
Retains user configuration selections, such as theme layout configurations (forcing our light white/orange gradient). These do not track personal identifying information.
Security & Shield Cookies
Prevent Cross-Site Request Forgery (CSRF) tokens and manage rate-limiting parameters at the Cloudflare edge layer to protect forms from automated scraping.
1. Zero-Tracking Commitment
Unlike standard marketing agencies, BROOT SECURITY does not deploy third-party advertising cookies, retargeting scripts, behavioral trackers, or analytics pixels (such as Google Analytics or Meta Pixels). We believe security platforms should collect the absolute minimum data required to protect operations.
2. Client Portal Sessions
When you authenticate into the BROOT VAPT portal, we generate a secure token cookie. This cookie utilizes the HttpOnly attribute, preventing client-side script queries (blocking XSS-based token extraction attempts), and enforces Secure and SameSite=Strict parameters.
3. Disabling Cookie Structures
You can choose to disable functional or preference cookies within your browser configuration tools. However, disabling strictly necessary authentication cookies will prevent the client assessment portal and active tenant switching from loading or verifying system actions.
4. Policy Contact
For further inquiries regarding compliance parameters, data caching schedules, or our cookie configuration practices, contact our security governance board at contact@brootsec.com.