01. Data Collection
We collect only what an engagement requires: information to reach and work with your team. The audit scan itself runs on your own infrastructure with zero network connections. Your source code never leaves your premises: we receive only one sanitised file, a findings summary with no code, no secrets, and no real names.
Client & Contact Details
Names, roles, company information, and correspondence needed to scope and deliver an audit engagement.
Sanitised Audit Findings
A single summary file of rule matches from your codebase scan, with all secret values, code snippets, and individual developer identities stripped out. No developer is ever named or identifiable in what we receive, or in anything we produce from it. We never see your source code, pull requests, or AI tool logs.
02. Processing Protocols
Processing is kept deliberately narrow to the audit at hand. Material from one engagement is never mixed into another client's audit. Sensitive content found during review gets redacted before it ever reaches a report.
Data Arrives Pre-Sanitised
The scanner your team runs strips secrets, code, and real names before anything leaves your infrastructure. We receive only the sanitised findings file, sent either through our optional one-click, consent-gated send or by your team emailing it themselves. No raw source material ever reaches us.
Findings Validation
Audit findings are cross-checked against the sanitised evidence before they are written up. The report reflects what the team actually does, not what someone guesses.
Engagement Logging
Activity during an engagement is logged so we can account for what was accessed and when, for as long as the engagement is active.
Cloudflare Turnstile
Our contact and audit-request forms use Cloudflare Turnstile, a privacy-friendly CAPTCHA alternative, to protect against spam and automated abuse. Turnstile runs invisibly in most cases and may process technical and usage data as part of that verification. For details, see Cloudflare's Turnstile Privacy Policy.
Vercel Web Analytics
We use Vercel Web Analytics to understand aggregate site traffic. Pages viewed, referrer, and general device/location data. It does not use cookies, does not track you across other sites, and does not store your IP address. No individual visitor is identifiable from this data. For details, see Vercel's Privacy Policy.
03. User Rights
You keep control over the data we hold about you and your organisation for the duration of an audit and beyond.
Right of access
Request a copy of the personal and engagement data we hold about you or your organisation.
Right to erasure
Ask us to delete non-essential data once it's no longer needed for an active audit or legal obligation.
Right to transparency
Ask how your data was handled during an audit, including what was reviewed and what was redacted from reports.
04. Retention Logic
We retain data only for as long as it is required to service an active audit or satisfy a legal obligation. Retention windows are tied to the engagement: your underlying material is retained only as long as needed to finalize the report and support any follow-up. Where no active obligation applies, clients may request early deletion at any time through the Right to Erasure process outlined in Section 03.
- Retained only for the duration of the active audit or a legal obligation
- Windows scoped to the one-off audit engagement, not held indefinitely
- Early deletion available on request via Right to Erasure