Version 2026-07-30 · applies to app.sudarshana.io
This policy explains the cookies and similar technologies used by the Sudarshana security platform at app.sudarshana.io, what each one is for, how long it lasts, and who sets it. It sits alongside our Privacy Policy.
We ask before storing anything that is not strictly necessary, and nothing optional is stored until you agree. Refusing is one click, in the same place and the same size as accepting. If you refuse, the product works exactly as it does if you accept, because we do not use cookies for advertising, personalisation, paywalls or A/B tests.
Your choice is recorded with the time you made it and the version of this policy you were shown. If this policy changes in a way that affects what is stored or why, the version is raised, your previous choice stops applying, every optional category is switched off, and you are asked again the next time you sign in.
These are required to deliver a service you have explicitly asked for: signing in, staying signed in, and remembering this cookie choice. They cannot be switched off, and under the ePrivacy rules they do not require consent. All of them are set by us on app.sudarshana.io and are first-party cookies.
| Name | Purpose | Duration |
|---|---|---|
sd_consent | Stores the choice you made about the cookies on this page, with the time you made it and the version of this policy you were shown. Without it we would have to ask you on every page. | 180 days |
active_org | Remembers which of your organizations the console is currently showing, if you belong to more than one. Checked against your real memberships on every request, so it cannot widen your access. | 1 year |
impersonate_org | Set only for Sudarshana staff accounts: which customer organization a staff member is currently viewing in order to support it. Never set for customer accounts. | 1 year |
view | Set only for Sudarshana administrator accounts: which view of the console is being rendered. Never set for customer accounts. | 1 year |
Authentication is operated for us by Clerk, who act as our processor. Clerk’s script runs on app.sudarshana.io and sets its own session cookies there, including __session, which carries the short-lived token our servers use to recognise you. These are strictly necessary: without them you cannot sign in.
The full set of names Clerk uses, and their durations, are determined by Clerk’s software rather than by us and can change when it is updated. Clerk documents them; we do not restate them here in order to avoid publishing a list that quietly goes out of date.
At the time of this version of the policy, no analytics or performance cookies are set, and no analytics software runs in this product at all. The optional category exists so that error and performance monitoring, if and when we introduce it, cannot start without your consent: the code that would load it is gated on your choice and does not download the software until you have opted in.
If you accept this category, we intend to use it only to record faults and slow requests in our own product so we can fix them. It is never used for advertising and is never shared for advertising.
We do not use advertising or cross-site tracking cookies, we do not embed advertising networks, we do not sell or share personal data for behavioural advertising, and we do not run social media tracking pixels. That is why this policy has no advertising category for you to switch off. If that ever changes, this policy will change first and your consent will be asked again.
The console keeps a few preferences in your browser’s local storage rather than in a cookie. These are set because you asked for the thing they remember, they never leave your device, and they contain no identifiers:
sudarshana-pentest-theme and sudarshana-pentest-density: your light or dark theme and your preferred information density.sudarshana-pentest-new-draft: an autosaved draft of a pentest request you have started but not yet submitted, so that navigating away does not lose your typing. It is removed when the request is submitted or discarded.You can change or withdraw your choice at any time, and it is no harder than giving it. Use the control at the top of this page, or, when signed in to the console, go to Settings and then Privacy. Withdrawing takes effect immediately and stops any optional software from running.
You can also delete cookies through your browser’s own settings. Deleting sd_consent means we no longer have a record of your choice, so nothing optional will run and you will be asked again. Deleting the strictly necessary cookies will sign you out.
Questions about this policy, or a request to exercise your rights? Contact privacy@sudarshana.io.