This Privacy Policy explains how Solvion Solutions ("we") collects, uses, and protects information when you use GuardLayer. We aim to collect as little as possible, and we never sell your data.
1. Information We Collect
- Account data. If you sign in, we receive your name, email, and avatar from your chosen provider (GitHub or Google), or just your email address if you use a one-time email link. We keep the provider sign-in tokens needed to maintain your session.
- GitHub App data. When you install our GitHub App, we store the installation, your GitHub account or organization name, the repositories you choose to watch, and your settings for that account (your merge-gate policy and, if you add one, a Slack webhook URL).
- Code you scan. File contents from the repositories you connect (fetched at scan time) or files and code you submit to the one-off scanner. This may incidentally contain secrets or personal data present in your code. See section 3 — we do not store your raw source code.
- Scan reports. The results we save: a score, issue counts, and findings — each with a file path, line number, and a short snippet of the specific line flagged.
- Billing data. If you subscribe, your plan, status, and Stripe customer and subscription identifiers. We never see or store full card details — Stripe handles payment.
- Team data. If you invite teammates, the email addresses you invite and, once they accept, their account.
- Feedback & waitlist. Anything you send via the feedback form (your message, a category, and an optional email), and the email you submit if you join the waitlist.
- Technical data. Your IP address (used transiently, in memory, for rate limiting and abuse prevention) and basic server logs.
- Cookies.Only essential cookies — your sign-in session, a short-lived security token during GitHub connection, and your cookie-consent choice. No advertising or tracking cookies. See "Cookies" below.
2. How We Use Information
- To run security scans and generate your reports, pull-request checks, and PDF exports.
- To authenticate you and operate your account, team, and subscription.
- To send transactional email (sign-in links and team invitations) and, if you configure it, to post finding alerts to your Slack channel.
- To prevent abuse, secure the Service, and debug issues.
- To respond to your feedback and waitlist requests.
3. How Your Code Is Handled & Retained
When a scan runs on a connected repository, we fetch the relevant file contents from GitHub over a short-lived, repository-scoped access token, analyze them in memory, and then discard the source. We do not store your raw source code. What we keep is the scan report: the findings, each with a file path, line number, and a short snippet (capped at roughly 200 characters) of the specific line flagged — just enough to show you the issue.
Reports created from a connected GitHub account are private to that account and the team members it has invited; we enforce this access control in our application. Files you submit to the public one-off scanner are analyzed immediately and discarded — only the report is saved, and it is reachable solely through its unguessable link, so just the people you share that link with can open it.
You can delete any report, or clear them all, from your dashboard at any time. If you disconnect a GitHub account, we stop scanning it and forget which repositories you watched; existing reports become inaccessible from your dashboard. To have your data fully erased, contact us.
GuardLayer's analysis is performed by our own static engine. It can also use an AI provider, Anthropic, to add a plain-language explanation and suggested fix for individual findings. When it does, we send only the finding itself — its title, the short snippet, the file name and language, and the severity — never your full source code. Anthropic does not use it to train models, and we do not use your code to train any model.
4. Service Providers (Sub-processors)
We share data only with providers that help us run the Service:
- Supabase — our database (accounts, scan reports, settings, subscriptions, audit logs, team, and waitlist).
- Vercel — hosting, delivery, and cookieless, aggregate visitor analytics (page counts and referrers only — no cookies, no cross-site tracking, no personal profiles).
- GitHub — sign-in and, if you install our GitHub App, repository access to scan your code and post checks and pull-request comments.
- Google — sign-in, if you choose to sign in with Google.
- Stripe — payment processing for paid plans (we never see full card details).
- Amazon SES (AWS) — delivery of transactional email (sign-in links and team invitations).
- Anthropic — AI-assisted explanations of individual findings. When used, we send only the finding (its title, snippet, file name, language, and severity), never your full source code.
- Slack — if you connect it, we post finding alerts to the incoming-webhook URL you provide. We send only the summary, never your code, and you can remove it anytime.
5. Cookies
We use only strictly necessary cookies required for the site to function — your session, a short-lived security token during GitHub connection, and your cookie-consent choice. We do not use analytics or advertising cookies. You can manage cookies in your browser settings.
6. Data Sharing
We do not sell your personal data. We share it only with the providers above, with the Slack workspace you specify (if you connect one), when required by law, or to protect our rights and our users.
7. Security
We use industry-standard measures to protect your data: encryption in transit, application-enforced access controls (our database is reachable only by our backend, which scopes every request to your own account), short-lived repository-scoped tokens for GitHub access, and signed, verified webhooks. No method is 100% secure, but we work to protect your data and to limit what we store.
8. Your Rights
Depending on your location (e.g. GDPR/UK GDPR/CCPA), you may have rights to access, correct, delete, or export your data, and to object to certain processing. To exercise these, contact hello@guardlayer.io.
9. International Transfers
Your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We may update this Policy; material changes will be posted here with an updated date.
12. Contact
Privacy questions: hello@guardlayer.io.