How we handle your code
You are about to let a stranger read your product. Every commitment below is one the system actually enforces, not one we intend to keep.
Last updated 6 August 2026
The commitments
- Read-only access to one repository. We use a GitHub App with read-only contents permission on exactly the repository you choose. We cannot write to it, and we never see your other repositories. This is why we do not use GitHub's older sign-in method, which would ask for access to all of them at once.
- Pinned and ephemeral. Your analysis runs against one commit inside an isolated, single-use virtual machine with restricted network access. The machine is created for your job and destroyed when it finishes.
- We do not keep your source code. After analysis we keep the report: findings, short evidence excerpts of a few lines each, measurements, and cryptographic hashes. Every copy of your source is destroyed with the analysis machine. An uploaded archive is deleted within seven days.
- No training, ever. AI analysis runs under commercial API terms that do not train on your data. Region-pinned processing is available on request.
- If we find live credentials, we protect you first. Secrets are always redacted in reports and never stored or displayed in full. If we detect an apparently live credential we notify you immediately with rotation guidance. Any verification we do is read-only and side-effect free.
- Buyers never touch your code. Buyers see the report and the certificate. Sharing is yours to control: links expire, carry the viewer's identity as a watermark, can be revoked, and every view is logged. The public certificate carries grades and hashes, never code.
- Confidential by default. Our terms include a mutual confidentiality clause covering your code and your report. We never aggregate or resell anything derived from your codebase.
Why the certificate shows so little
The certificate is public and your app is live. Publishing vulnerability specifics, file names, or dependency names would hand an attacker a map of where to start. So the certificate carries grades, counts, and fingerprints only. The detail lives in the report, which is yours to share selectively.
Personal information we hold
Separately from your code, we hold the small amount of personal information the service needs to work:
- Your email address and, if you sign in with GitHub, your GitHub account name and installation id.
- Payment records. Card details are handled by Stripe and never reach our servers. We store the fact of a payment, not the instrument.
- An append-only log of actions taken on your account, such as an analysis starting or a certificate being published. This is what lets us answer questions about what happened and when.
- If you share a report, the identity you attach to the link and a record of each view, so you can see who looked.
We use it to deliver the service, to answer your support requests, and to meet our tax and accounting obligations. We do not sell it, and we do not use it for advertising.
Who else processes it
Five companies, each doing one job. This is the whole list. The last column says exactly what each one can see, because a tick in a box would not tell you the thing you actually want to know.
| Company | What it does | What it can see |
|---|---|---|
| Vercel | Hosts this website | Nothing. No code, no findings. |
| Supabase | Database, sign-in, and file storage | Your account, your findings, and the short evidence excerpts inside them. Never your source. |
| Stripe | Payments | Your email and payment details. Card numbers go to Stripe and never reach us. |
| Anthropic | The AI analysis passes | Findings and the specific lines each one cites, under commercial terms that do not train on your data. |
| Resend | Sends the report-ready and payment emails | Your email address and the contents of those emails. They link your report and never quote it. |
We will tell account holders before adding a subprocessor that touches code or personal information. When the analysis sandbox moves off our own hardware, the host running it will appear here before it runs anything.
How long we keep it
- Source code: destroyed with the analysis machine when the analysis finishes. Uploaded archives within seven days.
- Reports, findings, and certificates: for as long as your account is open, because a published certificate has to keep verifying.
- Account and payment records: for as long as the law requires us to keep them after your account closes, typically seven years for financial records.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Deleting your account withdraws any published certificate, because we will not keep verifying a claim for someone who has left. Email hello@struckcode.com and we will respond within 30 days.
If you are in the EU or UK, the lawful basis for processing your code and account data is performance of our contract with you, and for our security logging it is our legitimate interest in running the service safely. You can complain to your local data protection authority. If you are in Australia, you can complain to the Office of the Australian Information Commissioner.
Where the detail lives
The commitments above are shaped by how the system is built rather than the other way around. The methodology says what we look at, and the terms say what we promise about it.