← Back to Allowist

Privacy Policy

Effective date: July 12, 2026

Allowist ("Allowist," "we," "us") is operated by Default Deny LLC, an Oregon limited liability company. Allowist is a network access management service that keeps firewall IP allow lists current automatically. This policy explains what information we collect, why we collect it, how we protect it, and the choices you have.

Because Allowist's entire purpose is managing IP addresses, this policy is unusually specific about IP address handling. We believe a security product owes you that specificity.

1. Our roles

For information about your account, our website, and billing, Default Deny LLC acts as the data controller.

For the information your organization stores in the service — the IP addresses, device names, allow list entries, and recipient details your administrators manage — we act as a processor on your organization's behalf. Your organization's administrators control that data, decide who may access it, and can delete it.

2. Information we collect

Account information. Name, email address, and profile image (when you sign in with Google or Microsoft, provided by them); a password hash if you use email sign-in (we never store plaintext passwords); multi-factor authentication enrollment data; and single sign-on identifiers if your organization uses SAML.

Organization information. Organization name, plan tier, subscription status, and configuration such as feed settings, security policies, and email template customizations.

Service data — IP addresses by design. The core function of Allowist is recording public IP addresses so your firewalls can allow them. This includes: addresses reported by agents you install on your devices (with the device hostname and agent version); addresses your administrators enter manually; and addresses submitted by recipients of Allow Links, together with the recipient email address or reference label your administrator attached to the link. Allow Link pages display the detected address to the recipient and add it only after the recipient explicitly confirms.

Feed access logs. When a firewall or other client fetches one of your allow list feeds, we log the source IP address, requested format, result, timestamp, and user agent. These logs exist so your administrators can verify which systems consume their feeds and detect misuse of feed tokens.

Audit logs. Administrative actions in the service (adding or removing entries, revealing tokens, changing settings, redeeming Allow Links, and similar events) are recorded with the acting user, the affected resource, the change made, a timestamp, and the administrator's source IP address. Audit logging is a security feature and cannot be disabled by end users.

Payment information. Payments are processed by PayPal. We never receive or store card numbers or bank details. We store your subscription identifier, plan, and payment status as reported to us by PayPal.

Support communications. Messages you send through the in-app support form or the website contact form, including the email address you provide so we can respond.

Website analytics. Our public website uses a cookieless, aggregate page-view counter. It does not build visitor profiles, does not use advertising trackers, and does not follow you across other sites.

Cookies. The application uses an essential session cookie to keep you signed in. We do not use advertising cookies.

3. How we use information

We use the information above to operate the service (publishing your allow lists to your firewalls is the product); to authenticate users and enforce your organization's security policies such as required MFA; to maintain security through audit logs, rate limiting, and abuse detection; to process subscriptions and trials; to respond to support requests; to send transactional email such as verification links, invitations, Allow Links, and security notices; and to improve reliability. We do not sell personal information, and we do not use your data for advertising.

4. Third parties we rely on

We use a small set of infrastructure providers, each for a specific purpose:

  • Akamai Connected Cloud (Linode) — compute infrastructure and our managed PostgreSQL database, with encryption at rest. Our infrastructure benefits from Akamai's global network and its network-level DDoS mitigation.
  • Cloudflare — edge network in front of the service: TLS termination, caching, web application protections, and Turnstile bot verification on our public contact form.
  • PayPal — payment and subscription processing.
  • Google Workspace — delivery of transactional email.
  • Google and Microsoft — sign-in, if you choose OAuth authentication; your identity provider, if your organization configures SAML single sign-on.
  • ipify — an optional, client-side IP echo service. When an Allow Link confirmation page (or our IP lookup page) detects your IPv4 and IPv6 addresses, your browser may query ipify directly to determine each address family. Only your IP address reaches ipify; no account information, link details, or identity accompanies the request.
  • We share information with these providers only as needed for the purposes described, and with authorities only where required by law.

    5. Security

    Security is the product, and we hold our own infrastructure to the standard we help you enforce.

  • Hosting on Akamai Connected Cloud, with the protection of Akamai's global network, including network-level DDoS mitigation, and a managed database with encryption at rest.
  • All traffic encrypted in transit with TLS; strict transport security on the application.
  • Passwords hashed with bcrypt; multi-factor authentication available to every account and enforceable organization-wide by administrators.
  • Agent tokens, feed credentials, API keys, and integration secrets stored hashed or encrypted at rest — never in plaintext.
  • Strict tenant isolation with per-request membership verification, role-based access control, and session hardening.
  • Comprehensive, tamper-evident audit logging of administrative actions, including the acting administrator's source IP.
  • Rate limiting on public endpoints; single-use, automatically expiring Allow Links whose confirmation pages never modify anything until a human confirms; cryptographic verification of payment webhooks.
  • No system is impenetrable, and we do not promise perfect security. We do promise honest engineering: if an incident affects your data, we will notify affected organizations without undue delay.

    6. Data retention

    Account and organization data is retained while your account is active. Audit log retention follows your organization's plan tier. Feed access logs are retained on a rolling window for operational and security review. When an organization is deleted by its administrator, its allow lists, entries, agents, audit records, and Allow Links are deleted; residual copies in encrypted backups expire on the backup rotation schedule. Expired allow list entries and expired or used Allow Links become non-functional immediately upon expiry.

    7. Your rights and choices

    You can view and update your account information in the application. Organization administrators can export data, remove members, and permanently delete the organization from Organization Settings. Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of your personal information, or to object to certain processing; to exercise them, contact us at [email protected] and we will respond as required by applicable law (including, where applicable, the GDPR and the CCPA). If you interact with Allowist because an organization sent you an Allow Link, that organization controls the associated record; we will direct requests to them or assist as processor.

    8. Children

    Allowist is a business service and is not directed to anyone under 16. We do not knowingly collect personal information from children.

    9. International visitors

    Allowist is operated from the United States, and information is processed and stored in the United States.

    10. Changes to this policy

    If we make material changes, we will post the updated policy here, update the effective date, and notify signed-in administrators through the application. Continued use of the service after changes take effect constitutes acceptance.

    11. Contact

    Default Deny LLC — Allowist Portland, Oregon, United States [email protected]