What we collect, what we deliberately do not, and how to have any of it removed. The security page explains the handling; this states the rights.
Your GitHub identity. The account id and login of whoever signs in, and the installations that account administers. Sign-in requests no OAuth scopes at all, so we cannot read your email address, your profile, or anything else GitHub would otherwise offer.
Repository metadata. Names, commit hashes, and which repositories an installation covers. Not contents.
Findings. Which of the 28 checks passed and failed, the file paths and line numbers involved, and what an engineer wrote about them.
What you told us. The contact address you gave, and the six answers about your application — what it does, its stage, what it holds, who maintains it, who is asking you security questions, and what worries you.
The address is asked for rather than read from GitHub. That is deliberate: reading it would mean requesting a permission we do not need, and it is the wrong address anyway — where you want a report sent is not necessarily the address on your GitHub account.
Your repository is cloned into a container with no outbound network access, scanned, and destroyed with the container. Retention of the source behind a finding is opt-in and off by default. If you do not ask for it, the source is purged after your report is delivered — a command that is run, not a habit that is relied on.
You would opt in for one reason: a re-scan or a remediation sprint that carries the findings forward. Ask and we keep it; say nothing and we do not.
We do not use your code to train anything, by us or by anyone else.
Microsoft Azure — everything runs in Canada Central. Deop is a Microsoft Solutions Partner and this is the platform the product is built on rather than a vendor chosen per component.
GitHub — the App that reads your repository, and the sign-in.
Stripe — payment. Card details go to Stripe and never reach us; we hold a session identifier and an amount.
Cloudflare — DNS and TLS for this website. TLS terminates at a Cloudflare point of presence that may sit outside Canada, so web traffic in transit may be handled elsewhere. Your repository does not travel that path.
Azure OpenAI — drafts a first pass at each finding from that finding's metadata only. Inference runs outside Canada; your code does not go with it. That boundary is an allow-list of the fields we send rather than a list of things we strip out.
Findings and reports are kept so you can open them again and so a remediation sprint has something to work from. Source is purged after delivery unless you opted in. What you told us about your application is kept while you have an application with us.
Ask and we delete any of it. Uninstalling the App stops us reading anything new immediately; it does not by itself erase what came before, because a report you paid for is a thing you may still want.
You can ask what we hold about you, ask for a copy, ask for it corrected, or ask for it deleted. Write to our contact form and a person answers.
Deop Inc. is Canadian and subject to PIPEDA. If you are in the EU or the UK the equivalent rights apply and we will honour them the same way.
Deop Inc., Vaughan, Ontario, Canada — our contact form. A person reads that address; it is the same one that answers questions about a report.