This policy describes the cookies and similar technologies used by the Borealis Security marketing site, our consent controls, and how we honor browser-based privacy signals. We keep this policy aligned with the live consent banner, our active vendor list, and the controls available on the privacy-choices page.
What are cookies and similar technologies?
Cookies are small text files that websites place on a browser or device. We may also use similar technologies such as pixels, tags, SDKs, local storage, and session identifiers. For convenience, this policy refers to all of these technologies as “cookies.” These technologies can help us operate the website, maintain security, remember settings, understand performance, and, where permitted, support analytics or marketing measurement.
How we use these technologies
Borealis uses strictly necessary cookies or similar technologies to support security, fraud prevention, network management, consent-state storage, and core request-flow functionality. We may use optional analytics technologies to understand traffic, performance, and content usefulness. We may use optional marketing or attribution technologies to measure which channels drive interest or requests and to improve outreach efficiency, subject to your choices and applicable law.
Categories of cookies
- Strictly necessary. These support security, session state, consent-state storage, accessibility, and core form or scheduling functionality. They remain enabled because the site cannot operate properly without them.
- Analytics / performance. These help us understand how visitors interact with the site and may include tools such as Google Analytics 4 or Microsoft Clarity where enabled.
- Functional / preference. These remember preferences such as consent state or display choices.
- Marketing / attribution. These may be used for campaign measurement, company-level visitor identification, or related B2B attribution where enabled and allowed by your settings.
First-party and third-party technologies
Some cookies are set directly by Borealis. Others may be set by service providers or third parties that help us host, secure, analyze, or operate the site. Current vendor inventory (last reviewed: July 30, 2026):
- Analytics (loaded only after analytics consent): Google Analytics 4, Microsoft Clarity.
- Session recording, heatmaps, and product analytics (loaded only after analytics consent): PostHog. PostHog is materially more invasive than standard traffic analytics — it can capture session replay of on-page activity (form field inputs are masked by default), generate heatmaps of visitor interaction, and automatically record clicks and other on-page events (autocapture).
- Marketing and attribution (loaded only after marketing consent): Reb2B for company-level visitor identification.
- Security and infrastructure: providers that support network delivery, fraud prevention, and site availability. These technologies are necessary and run regardless of consent state.
Cookie and storage inventory
This inventory lists the specific cookie and browser-storage key names that Borealis’s own site code sets directly, and the vendor-set key patterns that our consent-cleanup code is written to detect and remove when you decline or withdraw a consent category. Where a duration is set by a third-party vendor’s own script rather than by Borealis, this policy says so instead of stating a duration Borealis does not control.
- cookie_consent (browser local storage key, set directly by Borealis): stores your saved cookie-preference choices (necessary, analytics, marketing, and the time you last saved them). Local storage has no built-in expiration; this key persists until you clear your browser storage or Borealis changes the consent mechanism.
- analytics_consent and marketing_consent (first-party cookies, set directly by Borealis): record your analytics and marketing consent choices for use across page loads. Duration: 1 year (SameSite=Lax; Secure).
- _ga, _gid, and _ga_ followed by a Google-assigned suffix (Google Analytics 4; third-party; loaded only after you grant analytics consent): visitor and session identifiers used for traffic analytics. Duration: set by Google; not fixed by Borealis.
- _clck, _clsk, CLID, ANONCHK, MR, MUID, and SM (Microsoft Clarity; third-party; loaded only after you grant analytics consent): session and analytics identifiers used for heatmap and session-replay analytics. Duration: set by Microsoft; not fixed by Borealis.
- Keys containing “posthog” or starting with “ph_” (for example, a key in the form ph_<project key>_posthog), stored in both local storage and as a cookie (PostHog; third-party; loaded only after you grant analytics consent): session-recording, heatmap, and product-analytics identifiers for the PostHog capabilities described above. Duration: set by PostHog; not fixed by Borealis.
- Cookies named “reb2b” or starting with “reb2b” (Reb2B; third-party; loaded only after you grant marketing consent): company-level visitor identification used for marketing attribution. Duration: set by Reb2B; not fixed by Borealis.
- Security, network, and hosting-infrastructure cookies: our hosting, content-delivery, and fraud-prevention providers may set additional cookies to operate and protect the site regardless of consent state. Borealis has not independently catalogued the specific names, first-party or third-party status, or durations of every such cookie in this policy. Contact us using Section 9 if you have a question about a specific cookie you observe.
The Cookie Preferences control and the privacy-choices page reflect this configuration. If we add, remove, or change vendors, we update this list, the banner copy, and the privacy-choices page together.
Managing your choices
Optional analytics and marketing technologies remain off until you affirmatively enable them through the cookie banner or related controls. You can revisit your choices using the “Cookie Preferences” link or equivalent controls made available on the site. Blocking or disabling certain technologies may affect saved preferences, scheduling flows, or certain convenience features, but the site should continue to function without optional analytics or marketing technologies.
Global Privacy Control and browser settings
Borealis honors supported Global Privacy Control signals by keeping optional analytics and marketing technologies off on the Borealis marketing site and related request flows. Legacy “Do Not Track” signals are not treated as the controlling opt-out mechanism because they are not a standardized consent or opt-out signal. You may also manage cookies through your browser settings.
Relationship to privacy rights
Depending on the live configuration and applicable law, certain optional analytics or marketing technologies may involve disclosures that are treated as sale, sharing, or targeted advertising under some state privacy laws. For more information about those choices, see our Privacy Policy and Privacy Choices page.
Changes to this policy
We may update this Cookie Policy from time to time to reflect changes in our practices, vendors, technologies, or legal requirements. When we do, we will update the last-updated date and publish the revised policy.
Contact
Questions about cookies, consent choices, or this policy may be sent to privacy@borealissecurity.com or by mail to Borealis Security, Inc., Attn: Privacy Officer, 3300 Arctic Blvd, Suite 201 PMB 1085, Anchorage, AK 99503.