Skip to content

Security and privacy ​

The full statement is on dagsec.net/security and dagsec.net/privacy. In short:

  • Your code. The GitHub Action, GitLab CI, CLI and AI agent integrations never send it to dagsec. The GitHub App and dashboard clone a repository only for the scan and delete it afterwards.
  • Secrets. Reports show masked values only. The full value exists in memory during the scan and is never stored or logged.
  • Credential checks. Only in your own CI and the GitHub App, with read-only calls to the credential's provider. Never in dashboard scans.
  • Where data lives. On a dedicated server at Hetzner in Germany (EU), reachable only through Cloudflare over HTTPS.
  • What leaves for public services. Package names and versions, sent to OSV.dev and package registries. Never code or personal data.
  • Retention. Sign-in records and team audit logs 90 days; sessions 30 days; CI run records 400 days; accounts and scans until you ask for deletion; backups 14 days.
  • Compliance. GDPR, Qatar's PDPPL (Law No. 13 of 2016) and Türkiye's KVKK (Law No. 6698). No SOC 2 or ISO 27001 certification yet. A data processing agreement is available for business customers.

Report a vulnerability to hello@dagsec.net. See security.txt.