Privacy Policy
1. Introduction & Scope
Welcome to iotascan. We value your privacy and security above all else. This Privacy Policy explains how we collect, process, secure, and store data when you utilize our automated repository scans, compliance assessments, and vulnerability tracking features.
By using our platform, you consent to the data collection and usage practices outlined in this policy.
2. Information We Collect
To provide security scanning and compliance reporting services, we process the following categories of information:
- Authentication Credentials: User account details (name, email address, password hashes) and organization details.
- Repository Integration Metadata: GitHub API access tokens, repository names, commit IDs, and basic structure configurations needed to carry out remote analysis.
- Scan Targets & Findings: Vulnerability insights, hardcoded secrets identified (which are masked in reports), dependency files (e.g.
package.json,requirements.txt), infrastructure configurations (Terraform, Dockerfiles), and attack path configurations.
3. How We Process & Secure Code Scans
The security of your codebase is our primary mission:
- In-Memory Scanning: Our scanner retrieves and parses codebase files dynamically. Scanned code files are processed in-memory and are never written to permanent storage, except for high-level audit findings, metadata, and reporting metrics.
- PII Separated Storage: Personally Identifiable Information (such as names and emails) is stored in a dedicated, isolated database (the PII DB) separate from the primary system database (Main DB). Connections between user activity and profile details are heavily restricted.
- Encryption Standards: All database records are encrypted at rest using industry-standard AES-256 algorithms. Data in transit is protected using TLS 1.3 secure protocols.
4. How We Use the Information
We use the processed information solely to deliver and improve our application features, including:
- Performing vulnerability, secret leak, and compliance readiness analysis.
- Generating compliance and health scores (SOC 2, ISO 27001, GDPR, etc.).
- Sending critical security alerts and system updates.
- Diagnosing performance issues and improving the scanner regex matching heuristics.
We **never** sell, rent, or share your source code, configuration profiles, or scan results with third parties.
5. Data Retention & Deletion
We retain scan summaries and compliance reports for as long as your account is active. Users and organization administrators have the ability to delete projects and repositories from our index at any time. Doing so permanently purges all historical scan details and finding metrics associated with that project.
6. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the security of your data on iotascan, please contact our Security Operations Team at:
Email: [email protected]