Privacy notice · updated July 2026

Source stays local unless you deliberately choose otherwise.

Data processed by the hosted service

We process account identity, workspace membership, billing identifiers, managed integration identifiers, projects, CBOM records, fingerprints, paths, dependency identifiers, policy results, ownership, migration work, exceptions, and audit events you choose to upload or create.

Scanner boundary

The local scanner does not upload source code, private keys, certificate private material, tokens, or secrets by default. Evidence excerpts are redacted locally and included only as part of the selected scan metadata.

Purpose

We use hosted data to authenticate users, preserve version history, route migration work, evaluate drift, generate exports, prevent abuse, operate subscriptions, and support your workspace. Analytics must not include source code, secrets, private keys, or certificate private material.

Providers

The service may use configured authentication, billing, managed OAuth, infrastructure, backup, email, and error-monitoring providers. Managed OAuth providers hold third-party authorization while Qubrisk stores workspace-scoped connection identifiers.

Retention and deletion

Workspace owners choose retention within plan and safety limits and can delete hosted workspace data without support. Independently encrypted backups expire under the operational recovery policy.

Operator and contact

the operator identified at checkout operates the service. Privacy, access, correction, and deletion requests may be sent to the privacy contact shown at checkout.