Security & data
Your code never leaves your control.
We read your repository, we never keep it. Every scan takes a temporary clone, analyses it, stores the report, and deletes the working copy — including on a failed scan. No third-party AI ever sees your code, and nothing runs on someone else's cloud. Every claim on this page is written out in full, with its limits, in the security statement.
The short version
Four answers, before the paperwork.
Your source is never persisted
A temporary, isolated clone per scan. We store the report and the metrics; the working copy is deleted every time, including when the scan fails. We never train on your code.
No third-party AI, no cloud
The language model is self-hosted. Processing and storage run on hardware we own in Denmark — there is no cloud provider in the data path, and no analytics SaaS, error-tracking SaaS or CDN anywhere on it.
Read-only by doctrine
The GitHub App asks for read-only Contents and Metadata. No actions, no code in webhook payloads, and we never modify your source. One optional write exists and stays off until you turn it on.
Publication is yours to choose
On a paid plan every report is private by default; publishing is an explicit opt-in. A report that regressed below one you already published is never published.
The whole subprocessor list is two names
GitHub (source hosting and sign-in identity) and Stripe (payments, once billing activates). That is the entire list. Identity, the engine, the model, the database and report storage are all self-hosted. The full table — purpose, data and location for each — is in the security statement.
Leaving is self-service
You can take it all back without asking us.
Close the account yourself
A 14-day reversible grace period, then permanent deletion: personal data and the sign-in identity are erased, reports and source-derived artifacts purged. No ticket, no email thread, no waiting on us.
Disconnect a single repository
Reports and metrics are kept only while a repository is connected. Disconnect it and its stored reports and metrics are deleted — that retention rule is written into the DPA, not just into our habits.
The documents themselves
Everything above, written out with its limits.
Security & data statement
The full account: access scopes, scan lifecycle, where data lives, who can see a report, transport, subprocessors, and an honest note on what we are not certified for today. Read the statement →
Data Processing Agreement
GDPR Article 28 terms: roles, retention and deletion, technical measures, subprocessors, breach notification, audit and international transfers. Read the DPA →
Terms of Service
What the service does, what happens to your code, how plans and LoC-scan budgets work, when a report is published, and how to close your account. Read the terms →
Point it at a repo and see exactly what we read.
The first full report on any repo is €0. Nothing is installed, nothing is written, and the working copy is gone before you read the result.