← Back

How we handle your code

You are about to let a stranger read your product. Every commitment below is one the system actually enforces, not one we intend to keep.

Last updated 6 August 2026

The commitments

Why the certificate shows so little

The certificate is public and your app is live. Publishing vulnerability specifics, file names, or dependency names would hand an attacker a map of where to start. So the certificate carries grades, counts, and fingerprints only. The detail lives in the report, which is yours to share selectively.

Personal information we hold

Separately from your code, we hold the small amount of personal information the service needs to work:

We use it to deliver the service, to answer your support requests, and to meet our tax and accounting obligations. We do not sell it, and we do not use it for advertising.

Who else processes it

Five companies, each doing one job. This is the whole list. The last column says exactly what each one can see, because a tick in a box would not tell you the thing you actually want to know.

CompanyWhat it doesWhat it can see
VercelHosts this websiteNothing. No code, no findings.
SupabaseDatabase, sign-in, and file storageYour account, your findings, and the short evidence excerpts inside them. Never your source.
StripePaymentsYour email and payment details. Card numbers go to Stripe and never reach us.
AnthropicThe AI analysis passesFindings and the specific lines each one cites, under commercial terms that do not train on your data.
ResendSends the report-ready and payment emailsYour email address and the contents of those emails. They link your report and never quote it.

We will tell account holders before adding a subprocessor that touches code or personal information. When the analysis sandbox moves off our own hardware, the host running it will appear here before it runs anything.

How long we keep it

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Deleting your account withdraws any published certificate, because we will not keep verifying a claim for someone who has left. Email hello@struckcode.com and we will respond within 30 days.

If you are in the EU or UK, the lawful basis for processing your code and account data is performance of our contract with you, and for our security logging it is our legitimate interest in running the service safely. You can complain to your local data protection authority. If you are in Australia, you can complain to the Office of the Australian Information Commissioner.

Where the detail lives

The commitments above are shaped by how the system is built rather than the other way around. The methodology says what we look at, and the terms say what we promise about it.