Security and privacy
The full statement is on dagsec.net/security and dagsec.net/privacy. In short:
- Your code. The GitHub Action, GitLab CI, CLI and AI agent integrations never send it to dagsec. The GitHub App and dashboard clone a repository only for the scan and delete it afterwards.
- Secrets. Reports show masked values only. The full value exists in memory during the scan and is never stored or logged.
- Credential checks. Only in your own CI and the GitHub App, with read-only calls to the credential's provider. Never in dashboard scans.
- Where data lives. On a dedicated server at Hetzner in Germany (EU), reachable only through Cloudflare over HTTPS.
- What leaves for public services. Package names and versions, sent to OSV.dev and package registries. Never code or personal data.
- Retention. Sign-in records and team audit logs 90 days; sessions 30 days; CI run records 400 days; accounts and scans until you ask for deletion; backups 14 days.
- Compliance. GDPR, Qatar's PDPPL (Law No. 13 of 2016) and Türkiye's KVKK (Law No. 6698). No SOC 2 or ISO 27001 certification yet. A data processing agreement is available for business customers.
Report a vulnerability to [email protected]. See security.txt.