Company · Data processingBrowse
CompanyLegalData processing
Data processing terms
If you use sbomtriage for an organisation, these are the binding terms on which personal data in what you upload is processed for your organisation. They form part of the terms, and they’re short because the processing is narrow.
Parties and scope
These terms are between your organisation, as controller, and the operator of sbomtriage, as processor. They apply for as long as the service processes data for your organisation, and until that data has been deleted. If they conflict with the terms of service on how personal data is processed, these terms win.
The operator hasn’t published a legal entity for the service yet. It’s run by one individual. No contact address has been published yet either.
Roles
- Your uploads and projects. Your organisation decides what to upload and why, so it’s the controller. The service processes that data only to give you the analysis you asked for.
- Your account. Your email address, profile answers and sign-in identity are held by the operator as controller, as described on the privacy page.
What data, and whose
An SBOM or lockfile is mostly about software, not people. What’s kept from it is the component inventory: component names, versions, package URLs and licences, the names of the files they came from, and the document name and generating tool if the file declares them. Authors, suppliers and contact fields in the file’s metadata aren’t kept. If a file name or component name contains a person’s name, that’s kept as part of the inventory.
For an account, the data subjects are the account holder and, for a branded report, whatever company name and logo you add.
Purpose
To match the inventory against published vulnerability data, rank what is found, show and export the result, and, on a project, re-check it on the schedule you set. It isn’t used for anything else: not sold, not shared beyond the subprocessors, not used for advertising, and not used to train any model.
What the operator commits to
- Instructions. The operator processes the data only on your documented instructions, including with regard to transfers outside the EEA. Your instructions are these terms and what you do in the service: what you upload, the settings you choose, and what you delete. If the law requires other processing, the operator will tell you first, unless that law forbids it. If an instruction seems to break data protection law, the operator will tell you.
- Confidentiality. Anyone the operator allows to access the data is bound by an obligation of confidentiality.
- Security. The operator keeps the measures described below in place.
- Subprocessors. You authorise the subprocessors listed. Each is bound by data protection obligations that give the same protection as these terms. Before adding or replacing one, the operator updates that page and emails account holders, so you can object. If an objection can’t be resolved, you can stop using the service and delete your data. The operator stays responsible to you for its subprocessors.
- Your obligations to individuals. The operator helps you respond to requests from people exercising their data protection rights. The exports and deletion tools cover most of this, and anything else can be asked for by email.
- Security, breaches and assessments. Taking into account the nature of the processing and the information available to it, the operator helps you meet your obligations on security, breach notification and data protection impact assessments.
- End of processing. When you stop using the service, you can export your data and then delete it, as described under deletion and return. Nothing is kept afterwards except backups held by the database provider, which expire on its schedule.
- Audits. The operator makes available the information needed to show that it meets these terms, and allows for and contributes to reasonable audits, including inspections, by you or an auditor you appoint, on reasonable notice.
How long it’s kept
- The uploaded file: not kept. It’s parsed in memory and discarded.
- An anonymous report: 24 hours, or less if you delete it.
- A project’s sources and inventory: until you delete the project or the account.
- A project’s scan history: scans older than 90 days are deleted the next time the project is scanned. The newest always stays, as a baseline.
- A project’s current report: until the project is deleted, or 400 days after its last scan.
If the database provider keeps backups of its own, those copies expire on the provider’s schedule, not this service’s.
Deletion and return
- Every report and project exports as JSON, which is the portable copy.
- Deleting a project removes its sources, reports, history and decisions.
- Deleting your account removes every project, report and preference, the account itself, and the sign-in identity behind it. It’s removed, not just marked as deleted.
- Uninstalling the GitHub App removes the installation, every project that depended on it and their stored reports, as soon as GitHub sends its notice.
Security measures
The measures in place are listed on the security page: uploads never written to disk, a fixed list of outbound hosts, a database that the public key can’t read, ownership checks on every project request, read-only access to repositories, and logs that carry no component names or file names. There is no independent audit or certification.
If something goes wrong
If the operator becomes aware of a personal data breach affecting data processed under these terms, it notifies you, the customer, by email to the affected account holders without undue delay. The notice says what’s known at the time, the likely consequences, what’s being done and what you can do. Further details follow as they become known.
Transfers outside the EEA
The database is in an EU region and the application runs in Dublin. Some subprocessors are in the United States, though, and Vercel’s network delivers pages worldwide. Those transfers rely on the standard contractual clauses in each provider’s data processing terms, and on the EU-US Data Privacy Framework where the provider is certified under it.
See also all legal pages.