Before you connect anything

You're about to give us
read access to your code.

Here is exactly what happens to it, what we keep, and what you get back — so you can decide before you grant anything rather than after.

1

You connect one repository

Through GitHub’s own App install, so you choose the repositories and you can revoke it in one click without talking to us. Read access to code and metadata. Nothing else — not issues, not actions, no write access to anything.

Free about a minute · revocable at any time
2

We ask you about the application

What it does, who maintains it, when you launch, and what is already worrying you. A scanner does not know that the database holding your customer records is the one you spun up in an afternoon. The person reading your results needs to.

Free six questions · two minutes
3

The scan runs in a sealed container

Your repository is cloned into a container with no outbound network access, scanned against 28 production-readiness checks, and the container is destroyed. The clone goes with it.

Free minutes, not hours
4

A senior engineer reads the results

The part you are actually paying for. A machine can tell you a key is exposed; it cannot tell you which three of nineteen findings matter before Thursday. Free, you see your top three findings and your score — enough to know whether the rest is worth having.

Top 3 free Full read $750 within 48 hours

What we keep

The short answer is nothing, unless you ask us to.

Kept after delivery

  • The findings — which checks passed and failed
  • Your report, so you can open it again
  • What you told us about the application

Destroyed with the container

  • Your repository, in full
  • The code behind every finding
  • Any credential the scan happened to read

Retention is opt-in. If you want a re-scan later, or a remediation sprint that carries the findings forward, you tell us and we keep them. Otherwise the source is purged after your report is delivered — that is a command we run, not a habit we rely on.

One thing we would rather say than bury

A model drafts a first pass at each finding, from that finding's metadata only — rule identifier, category, severity, file path, line numbers. Your source is never sent, and that boundary is an allow-list of what we send rather than a list of things we strip out.

That drafting runs outside Canada. Your code does not go with it. We write both sentences because only one of them is the reassuring one.

How we handle your code, in full →

What this costs

The X-ray is free. One repository, your top three findings, and a readiness score. No card, no call.

The full read is $750 — all 28 checks, a senior engineer's priority list, stack risk, a skills assessment, an enterprise readiness track, and a 30-minute call. Delivered within 48 hours.

You see the free result before you decide anything.

Who is asking

Company
Deop Inc., Vaughan, Ontario, Canada — deop.ca
Partner
Microsoft Solutions Partner for Cloud & AI Platforms and Security
Who reads it
A senior engineer at Deop, named in your report. The judgement is the product, and it is not anonymous.
Where it runs
Microsoft Azure, Canada Central. The qualifications to that sentence are on the security page rather than buried here.
Connect a repository See a sample report first
Read-only · revocable in one click · we don't keep your repository
What we promise and what we do with your data: Terms · Privacy