Skip to content
SEO Optimizer is live, Audit on page SEO and AI-search readiness. Try it free
Sign in

Security and data handling

A security tool should be clear about its own data. Here is what Scanverra collects, what it never sees, and where your data goes.

Website scans

  • We load only the public URL you enter, the way a visitor's browser would. We never log in to your site.
  • Results (scores, issues, metrics, the detected stack) are stored with your account. Performance data also comes from Google PageSpeed Insights, which receives the URL.
  • Audits run without an account are viewable by anyone with the report link and are deleted after 7 days unless you save them to an account.

CLI and VS Code extension

  • Your code is scanned on your own machine or CI runner. File contents are never uploaded.
  • The CLI uploads findings only: file path, line, rule, severity and fix suggestion. Secret values are never included; the matched line is sent only if you pass --include-code.
  • Scanner rules are signed with Ed25519. The CLI verifies the signature and refuses to run anything Scanverra did not sign.
  • --no-upload scans without sending anything, and --offline makes no network calls at all. The VS Code extension never uploads results.

Web Repo Scanner

  • You connect GitHub or Bitbucket with OAuth, and we read the repository to scan it on our servers.
  • GitHub's OAuth scope for private repositories (repo) allows read and write. Scanverra only reads code, and writes only when you open a fix pull request.
  • We store findings, including the short code snippet around each one, not a copy of your repository.

AI analysis

  • Explanations and fixes are written by third-party AI models (Anthropic, OpenAI or Google Gemini, depending on the task), called through their APIs.
  • The AI receives scan results only: for websites, issues, metrics and the detected stack of a public page; for code, findings plus flagged snippets from the web Repo Scanner.
  • When you open a fix pull request, the file being changed is sent so the fix can be applied. CLI uploads contain no code unless you pass --include-code.

Accounts and API keys

  • Passwords are stored as bcrypt hashes. You can also sign in with Google or GitHub, and Enterprise teams can use SAML SSO.
  • API keys are shown once and stored only as SHA-256 hashes. Revoke a key at any time from the API Keys page.
  • The site is served over HTTPS only, with HSTS and strict browser security headers.

Payments

  • Card payments are handled by Razorpay. Scanverra never sees or stores your card number.
  • Cancel anytime from the billing page; refunds follow our refund policy.

Who processes data for us

These providers process data on Scanverra's behalf. Analytics only runs with your consent, except cookieless Vercel Analytics.

ProviderPurpose
VercelHosting and serverless compute
NeonDatabase (accounts, reports, findings)
Google (PageSpeed Insights, Gemini)Performance data for scanned URLs; AI analysis for some tasks
AnthropicAI explanations and fixes
OpenAIAI explanations and fixes
RazorpaySubscription billing and payments
CloudinaryImages for articles and guides
Vercel Analytics, Google Analytics, Microsoft ClaritySite usage analytics (Google and Microsoft only with consent)

Report a vulnerability

Found a security issue in Scanverra? Email us with the steps to reproduce it. Please give us a reasonable time to fix it before disclosing it publicly, and don't access other users' data while testing.

support@scanverra.com