GitHub repository access
Stored data
PR review records
- Repository identifier (org/repo name)
- PR number and commit SHA
- Finding records: file path, line number, vulnerability type, severity, description, remediation
- Vector embedding of each finding description (used for regression detection)
- Risk score and plain-English summary
Live scan records
- Domain and scan configuration
- Discovered endpoints and their response metadata (status code, headers)
- Finding records: endpoint, vulnerability type, evidence, remediation
- Scan run timeline and status
Account data
- Email address
- GitHub OAuth identity (if GitHub sign-in used)
- Organisation membership and plan tier
- Settings and preferences
Encryption
Subprocessors
We reserve the right to change our subprocessors at any time. When we add or change one,
we email account holders to let you know, so you are always aware of who processes your
data. See our Privacy Policy for details.
Retention and deletion
- Finding records and scan results: retained for the lifetime of the account
- Repository disconnection: findings for that repository removed within 24 hours
- Account deletion: all associated data removed within 30 days
- Data export: available as JSON from the Dashboard at any time