Security and data handling
A security tool should be clear about its own data. Here is what Scanverra collects, what it never sees, and where your data goes.
Website scans
- We load only the public URL you enter, the way a visitor's browser would. We never log in to your site.
- Results (scores, issues, metrics, the detected stack) are stored with your account. Performance data also comes from Google PageSpeed Insights, which receives the URL.
- Audits run without an account are viewable by anyone with the report link and are deleted after 7 days unless you save them to an account.
CLI and VS Code extension
- Your code is scanned on your own machine or CI runner. File contents are never uploaded.
- The CLI uploads findings only: file path, line, rule, severity and fix suggestion. Secret values are never included; the matched line is sent only if you pass --include-code.
- Scanner rules are signed with Ed25519. The CLI verifies the signature and refuses to run anything Scanverra did not sign.
- --no-upload scans without sending anything, and --offline makes no network calls at all. The VS Code extension never uploads results.
Web Repo Scanner
- You connect GitHub or Bitbucket with OAuth, and we read the repository to scan it on our servers.
- GitHub's OAuth scope for private repositories (repo) allows read and write. Scanverra only reads code, and writes only when you open a fix pull request.
- We store findings, including the short code snippet around each one, not a copy of your repository.
AI analysis
- Explanations and fixes are written by third-party AI models (Anthropic, OpenAI or Google Gemini, depending on the task), called through their APIs.
- The AI receives scan results only: for websites, issues, metrics and the detected stack of a public page; for code, findings plus flagged snippets from the web Repo Scanner.
- When you open a fix pull request, the file being changed is sent so the fix can be applied. CLI uploads contain no code unless you pass --include-code.
Accounts and API keys
- Passwords are stored as bcrypt hashes. You can also sign in with Google or GitHub, and Enterprise teams can use SAML SSO.
- API keys are shown once and stored only as SHA-256 hashes. Revoke a key at any time from the API Keys page.
- The site is served over HTTPS only, with HSTS and strict browser security headers.
Payments
- Card payments are handled by Razorpay. Scanverra never sees or stores your card number.
- Cancel anytime from the billing page; refunds follow our refund policy.
Who processes data for us
These providers process data on Scanverra's behalf. Analytics only runs with your consent, except cookieless Vercel Analytics.
| Provider | Purpose |
|---|---|
| Vercel | Hosting and serverless compute |
| Neon | Database (accounts, reports, findings) |
| Google (PageSpeed Insights, Gemini) | Performance data for scanned URLs; AI analysis for some tasks |
| Anthropic | AI explanations and fixes |
| OpenAI | AI explanations and fixes |
| Razorpay | Subscription billing and payments |
| Cloudinary | Images for articles and guides |
| Vercel Analytics, Google Analytics, Microsoft Clarity | Site usage analytics (Google and Microsoft only with consent) |
Report a vulnerability
Found a security issue in Scanverra? Email us with the steps to reproduce it. Please give us a reasonable time to fix it before disclosing it publicly, and don't access other users' data while testing.
support@scanverra.com