SECURITY & PRIVACY
Keep the input close.
Use the CLI or run the demo on your own machine. The hosted portfolio mode accepts no scan input. No credential is tested against a provider.
What happens to your input.
The local demo sends source directly from your browser to 127.0.0.1:8000. Input clears on submission. The API processes it in a disposable worker and returns fully redacted values with a fixed filename. Source is not routed through the Next.js server or written to disk by the scanner.
Redacted results stay in React memory across in-site navigation. Reloading, leaving the site, clearing results, or starting another scan clears them. There is no application analytics, browser storage, cookie tracking, or remote asset loading. Browser extensions, developer tools, swap, and crash dumps can still expose memory; secure erasure is not guaranteed.
Bounds before work.
The request deadline is ten seconds. Reports are capped at 1,000 findings and 2 MiB. Limits fail explicitly; incomplete work never becomes a clean result. These are application limits, not an operating-system sandbox.
Reports still need care.
CLI reports mask values but include paths, locations, and partial value characters. API reports fully redact values and filenames. Both can reveal service names and finding counts. Treat reports as sensitive and review any upload destination. Scanned content is never executed.
Found an exposed credential?
Revoke or rotate it, update consumers, and review provider access logs. Deleting a line does not remove Git history. Follow the finding’s service-specific response guidance.
Report a vulnerability privately.
Do not post credentials, private code, or exploit details in a public issue. Use GitHub’s private reporting flow if enabled. Otherwise open a minimal issue asking for a private contact channel. Only the latest development version is maintained; no response-time guarantee is offered.
Repository security page →