This section supplements the CTM360 Privacy Policy above and applies specifically to the CTM360 browser extension. It explains how the extension handles browser-related information when an authenticated user chooses to use the extension.
Key privacy principle
CTM360 browser extension does not continuously monitor browsing activity and does not automatically collect, scan, or transmit every URL a user visits. For non-CTM360 webpages, access is temporary and user-initiated. URL, domain, page, or screenshot information is sent to CTM360 only when an authenticated user chooses an extension feature that requires that information.
1. Authentication and CTM360 Service Access
CTM360 extension is intended for authenticated CTM360 users. It may use an existing CTM360 session to identify the user, associate actions with the appropriate organization, and authorize access to CTM360 services. This may include a session or access token, account identity, organization identifiers, and related organization or brand information. Persistent host access is limited to CTM360-operated service domains used by Platform, CyberBlindspot, HackerView, Webhunt, and the Webhunt API.
2. User-Initiated URL and Page Access
CTM360 extension does not use the browser-history permission, does not run continuous background monitoring of visited websites, and does not request blanket access to all HTTP or HTTPS websites. For a non-CTM360 webpage, temporary access becomes available only after the user intentionally invokes the extension, such as by clicking the toolbar icon or using the extension shortcut.
When invoked, the extension may temporarily read limited page context such as the current URL, page title, canonical URL, and hostname so the requested feature can be prepared. CTM360 does not receive URLs from unrelated browsing activity. A full Webhunt scan occurs only when the user chooses to submit a URL through Scan a Link or selects the CTM360 extension context-menu scan action. Likewise, a link displayed on a webpage is not submitted unless the user specifically chooses that link for scanning.
3. Incident Reporting and Organizational Asset Checks
When the extension is intentionally activated, it may temporarily capture the visible portion of the active tab, so screenshot evidence is available if the user chooses to report an incident. The screenshot is not sent to CTM360 merely because the extension is opened. If the user submits an incident, the extension may send the submitted URL, screenshot, incident classification, organization information, and any notes voluntarily provided by the user. Authorized CTM360 security personnel may review this submitted information as necessary to investigate the reported cybersecurity issue.
If the user chooses an asset-related feature, the extension may submit the relevant hostname or domain to CTM360 HackerView to perform the requested asset check or action. The extension does not automatically inventory every website the user visits.
4. Extension Storage, Scan Status, and Notifications
CTM360 extension may use browser storage for operational information such as CTM360 platform authentication or session state, organization selection, pending or recent user-requested scans, and extension preferences. After a user submits a URL, the extension may check CTM360 for the status of that specific scan. Browser notifications may be used for user-initiated scan status, completion, errors, or report availability. These functions do not monitor general browsing activity, advertise to users, or build behavioral profiles.
5. Browser Permissions and Their Purpose
CTM360 extension uses the following browser permissions only for its disclosed cybersecurity functions:
| Permission |
Purpose |
| ActiveTab |
Provides temporary access to the current page only after the user invokes the extension. |
| Scripting |
Runs packaged extension code needed for user-initiated page access and CTM360 session connectivity. |
| Storage |
Stores operational session state, organization selection, user-requested scan information, and limited preferences. |
| Alarms |
Checks the status of scans already submitted by the user. |
| ContextMenus |
Provides the user-controlled "Scan this link with CTM360 extension" action. |
| Notifications |
Shows status, completion, error, or report notifications for user actions. |
| SidePanel |
Displays the CTM360 extension interface and user controls. |
| CTM360 host access |
Allows authentication and communication only with applicable CTM360-operated service domains. |
6. Use, Sharing, and Limited Use
Information processed through the CTM360 extension is used only to provide, secure, support, or improve the extension's disclosed cybersecurity functionality. CTM360 does not sell extension user data, use it for personalized or interest-based advertising, transfer it to data brokers or information resellers, use it to determine creditworthiness or for lending purposes, or use it to monitor a user's general browsing behavior. Where service providers process information on CTM360's behalf, their access is limited to what is necessary to provide authorized infrastructure, security, support, or related services and is subject to applicable confidentiality and data-protection obligations.
Chrome Web Store Limited Use statement
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Human access to submitted extension information is restricted except where the user has authorized review, where access is necessary for security or abuse investigation, where required by law, or where appropriately aggregated or anonymized information is used for permitted internal operations.
7. Retention, User Control, and Contact
Temporary extension state may remain in browser session storage while the CTM360 extension is in use, and limited preferences may remain locally until changed or removed. Information intentionally submitted to CTM360, including URL scans, asset-related actions, and incident reports, may be retained in accordance with applicable customer agreements, security requirements, legal obligations, and CTM360 retention practices.
Users control when the extension is used on a non-CTM360 webpage and whether to submit a URL, selected link, domain, incident report, or screenshot evidence. CTM360 browser extension does not automatically scan every website a user visits.