Privacy
A scanner that reads your whole git history owes you an exact account of what it keeps. This is that account, written against the code rather than from a template.
Last updated 4 September 2026
What we read
A scan clones your repository and reads the working tree and the full commit history. If you supply a deployed URL we make ordinary HTTP requests to it, the way any visitor would. If you supply a Supabase anon key we use it read-only, to test what a stranger could read from your database. Nothing is ever written back to your repository unless you separately ask for a pull request.
What we store
- The scan record: the repository URL, timings, which checks ran, and which could not.
- Findings, with the code excerpt that triggered them. Any secret inside that excerpt is reduced to its last four characters before the finding is created, so raw secret material never reaches our database, our logs, or your report.
- Your email address, if you give us one at the paywall or the waitlist.
- Payment records held by Stripe. We never see or store your card number.
What we never store
- Raw secrets found in your code. Only the masked last four characters, which is enough for you to identify the key and useless to anyone else.
- The write token for a pull request. That path is deliberately synchronous rather than queued, because a queued job would have to write the credential down. It is used in memory for that one request and discarded.
- A copy of your source code after the scan finishes.
The read token for private repositories
If your repository is private you may give us a read-only GitHub token. It is encrypted with AES-256-GCM before it is stored, decrypted once inside the clone step, and never written to a log — error messages are passed through a redactor before they are saved. Ask us and we delete it.
Your report link is the key
A scan runs without an account, so the unguessable link to your report is the permission to read it. Anyone you send that link to can see the report. Treat it the way you would treat a share link to a private document.
Who else sees any of this
- Vercel — hosting and the request logs that come with it.
- Supabase — the database and the sign-in email link.
- Anthropic — the review pass that turns raw findings into plain English receives the findings and surrounding code context, masked the same way.
- Stripe — payment processing.
- Resend — the emails we send you.
We do not sell anything to anyone, and we do not run advertising trackers on this site.
Cookies
The only cookies we set are the session cookies that keep you signed in after you follow an email sign-in link. There is no analytics or advertising cookie on this site.
Deleting your data
Write to us and we will delete your scans, your findings and your email address. [[REAL PROOF NEEDED: contact address for privacy requests]]
The parts a code review cannot answer
These are open, and are marked rather than guessed: [[REAL PROOF NEEDED: the legal entity and registered address]] · [[REAL PROOF NEEDED: how long scan records are retained before deletion]] · [[REAL PROOF NEEDED: governing law and, if applicable, the UK/EU representative]].
Questions about anything on this page: start a scan or write to the address in the footer.