Privacy Policy
Draft. Plain-language starting point, not yet reviewed by a lawyer. Bracketed items must be filled in before launch.
What we collect
- Email address — only if you sign in; used for the magic-link login and account-related mail. No passwords.
- Scan reports — the findings and score for a scan.
Public share links at
/r/<id>are scrubbed: the target host/IP is redacted and sensitive evidence is masked. - Abuse-prevention hashes — your IP address and the target you scan are stored only as salted (peppered) SHA-256 hashes for rate limiting, never in the clear and not reversible back to the original.
- Usage events — anonymous funnel events (e.g. page view, scan started) to understand how the product is used.
SSH keys are never persisted
For the managed (“we connect”) option, the read-only SSH key you paste is passed to the scan worker in memory, spilled to a private owner-only temporary file only for the moment the connection is established, and deleted immediately afterwards. The key is never written to our database, logs, or backups.
Retention
Anonymous and outside-in scan reports expire automatically (24 hours by default) unless you attach them to an account or make one permanent. Account data persists until you ask us to delete it. [[ REVIEW: confirm exact retention windows and a deletion-request path once support email exists. ]]
Sub-processors
We share the minimum necessary with:
- Postmark — sends login and notification email.
- Polar.sh — billing and payment (merchant of record).
- Cloudflare Turnstile — bot/abuse protection on scan submissions.
- Backblaze B2 — encrypted off-site database backups.
We do not sell personal data.
Contact
[[ REVIEW: data-controller entity and a privacy contact address, pending outbound-email setup. ]]
Last updated: [[ REVIEW: set on publish ]].