Security and data handling
Source code is the most sensitive thing a company owns. This is exactly what happens to it.
Two ways to run
Local (CLI or CI). The analyzer runs on your infrastructure. The dossier contains paths, hashes, commit metadata and short structured values (license identifiers, URLs, trailer text), never source code. You can drop even those with --omit-extracts. Uploading a dossier is optional.
Hosted. For GitHub, access is granted per repository through a GitHub App with read-only permissions (contents, metadata, pull requests). Each scan mints a token scoped to one repository that expires within an hour and is never stored. The repository is cloned into an isolated working directory, analysed in a separate process with memory and time limits, and deleted when the scan ends, successful or not. Uploaded archives are deleted after analysis. GitLab project tokens are encrypted at rest and decrypted only for the clone.
What we keep
- The dossier, encrypted with AES-256-GCM before it is written to storage, for your organisation's retention period (default 365 days, configurable 7–3650). After that the body is deleted; the digest and readiness remain as your snapshot ledger.
- Audit events for sign-ins, repository changes, scans, share-link views, declaration changes and deletions. The audit table rejects updates.
What we never do
- Send your code to a language model. There is no LLM in the analysis or in the report.
- Train anything on your repositories.
- Send private package names to public registries. Public package names and versions are sent to OSV.dev, npm and PyPI only when enrichment is enabled for your organisation.
- Reproduce secret values. Detected credentials are identified by a fingerprint and a four-character prefix.
- Log repository contents, tokens or cookies.
Isolation
Every organisation-scoped table is protected by PostgreSQL row-level security keyed on the organisation of the current transaction, forced for the table owner, and the application role cannot bypass it. A query that forgets a filter returns nothing rather than another customer's data.
Deletion
Deleting a repository removes its scans, dossiers, declarations, change history and share links. Deleting an organisation removes everything it owns. Both are immediate and irreversible.
Verification
Hosted dossiers are signed (DSSE over an in-toto statement, Ed25519). The platform public key is published at /.well-known/acquicode-signing-key.pem. Anyone can check a dossier at /verify without signing in.
Reporting a vulnerability
See SECURITY.md in the source repository for the disclosure process.