HuntGrid
Browser Extension Privacy Policy
For the “HuntGrid IOC Enrichment” Chrome/Edge extension · Last updated 15 August 2026
Summary
The HuntGrid IOC Enrichment extension enriches indicators of compromise (IP addresses, domains, file hashes, and URLs) against your own HuntGrid cyber operations platform. It communicates only with your configured HuntGrid server. It does not use analytics, does not track your browsing, and does not sell or share your data with any third party.
Information the extension handles
- HuntGrid credentials. When you sign in, your username, password, and two-factor code are sent directly to your HuntGrid server to authenticate. They are never stored by the extension and never sent anywhere else. On success the server returns a time-limited session token.
- Session token. The returned token is stored locally in your browser (
chrome.storage.local) so you don’t re-authenticate on every lookup. It is cleared automatically on expiry and when you sign out. - Indicators you choose to enrich. The specific IP, domain, hash, or URL you select, paste, or pick from a page scan is sent to your HuntGrid server to retrieve its enrichment result.
- Page text (only on request). When — and only when — you click “Scan this page for IOCs,” the extension reads the current tab’s visible text to extract candidate indicators. This happens locally in your browser; the full page text is never transmitted. Only an indicator you then choose to enrich is sent to your HuntGrid server.
How information is used
Information is used solely to authenticate you to your HuntGrid server and to return enrichment results for the indicators you request. There is no other processing.
Where information goes
The extension contacts exactly one network host: your configured HuntGrid deployment (by default
https://www.huntgrid.io). No data is sent to the extension’s authors, to Google, or to any third-party service. Any third-party threat- intelligence lookups (e.g. VirusTotal, AbuseIPDB) are performed server-side by your HuntGrid deployment, not by the extension.Data sharing and sale
We do not sell, rent, or share any user data. Your data stays between your browser and your own HuntGrid server.
Data retention and control
The only data the extension persists is the local session token, which you can remove at any time by signing out in the extension or by removing the extension. Records created by enriching an indicator live in your own HuntGrid database, under your organization’s control and retention policy.
Permissions
storage— stores your session token locally.contextMenus— adds the right-click “Enrich in HuntGrid” action.activeTabandscripting— read the current tab’s visible text, only when you click “Scan this page for IOCs.”- Host access to your HuntGrid server — the only host the extension contacts.
Contact
Questions about this policy or the extension can be directed to your HuntGrid administrator, or to the address on your HuntGrid deployment’s security contact page (
/.well-known/security.txt).