Trust · PrivacyBrowse
TrustPrivacy
What we collect, and what we don’t
The short version: the file you upload is never written to disk, and all we send to vulnerability databases is package names and versions, plus the CVE IDs they match. If you have an account, we hold your email and the profile you gave us, and you can delete all of it yourself at any time.
Who is responsible
This deployment hasn’t declared a controller or a contact address yet. Until it does, treat it as a pre-release instance and don’t send it personal data you wouldn’t be willing to lose. The operator sets SBOMTRIAGE_LEGAL_ENTITY and SBOMTRIAGE_LEGAL_CONTACT to fill this in.
What we hold, and why
| What | Why | Legal basis | How long |
|---|---|---|---|
| The file you upload, while it’s being read | To extract the list of components inside it. | Necessary to provide the service you asked for. | Never written to disk. It’s held in memory for the seconds the analysis takes, then discarded. |
| The component inventory and report from an anonymous scan | To show you the report at its address. | Necessary to provide the service you asked for. | 24 hours, or less if you delete it. The scan’s progress record and a fingerprint of the upload are kept for 60 minutes. |
| A saved project: its sources, inventory, current report and scan history | To show the project, re-check it and tell you what changed. | Necessary to perform the agreement between us. | The project and its inventory: until you delete the project or the account. Scans older than 90 days are deleted the next time the project is scanned (the newest always stays, and a project keeps at most 1,000). The app shows 90 days of history, or 7 days without early access. The current report expires if the project isn’t scanned for 400 days. |
| Package coordinates sent to OSV.dev | To ask which published advisories affect those versions. | Necessary to provide the service you asked for. | Not retained by us. OSV.dev receives names and versions, and nothing that identifies you. |
| Your email address and sign-in identity | To identify your account and let you sign back in. | Necessary to perform the agreement between us. | Until you delete the account. |
| Your company, role and what you’re scanning | To understand who’s using an early-access product, and to ask you what’s missing. | Necessary for the early-access agreement: these answers are its condition. You don’t have to give them, but without them the account stays on the free plan (1 project, a repository scan every 7 days, 7 days of history shown). | Until you delete the account, or 12 months after you last saved your profile or settings, whichever comes first. |
| Whether you agreed to be contacted, and when | To email you occasionally about early access, from a person. | Your consent. It’s optional and doesn’t affect your access. Withdraw it at any time in Settings or through the opt-out in any email we send. | Stored with your profile, for the same period. |
| Your settings: report branding (company name and logo) and alert choices | To apply the choices you made. | Necessary to perform the agreement between us. | Until you delete the account, or 12 months after you last saved them, whichever comes first. |
| IP addresses and request records | To rate-limit scanning and keep the service secure. | Our legitimate interest in protecting the service from abuse. You can object, as described under your rights. | For rate limiting, held only in memory and never stored by us. The hosting provider’s request log records each request, including the path, on its own schedule. |
What we never do
- Write your uploaded file to disk. It’s parsed in memory and discarded.
- Send the file, its name or your identity to any vulnerability database. OSV.dev receives package names and versions, FIRST receives the CVE IDs found so it can return EPSS scores, and for Debian packages the Debian archive receives a package name. Nothing else.
- Run analytics, advertising or third-party tracking of any kind. There are no such scripts on any page.
- Sell, rent or share your data with anyone beyond the processors listed below.
- Read repositories you didn’t select. The GitHub App can only see what you granted it, and it reads dependency manifests only.
Who else sees it
These services see only what’s listed. Those working for us as processors are bound by their data processing terms. When you sign in with GitHub or Google, they act as independent controllers of your account with them, under their own privacy terms. The same list, with when each one is used, is on the subprocessors page.
| Processor | Role | What they see | Where |
|---|---|---|---|
| Vercel | Hosting and delivery | Requests, IP addresses in transit, and the application itself. | Functions in the Dublin region; pages through Vercel’s global network |
| Supabase | Database and authentication | Your email address, your profile, your projects and their analysis results. | An EU region |
| GitHub | Sign-in, and reading repositories you connect | Your GitHub identity, and the dependency manifests of repositories you select. | United States |
| Sign-in, if you choose it | Your email address and basic profile. | United States | |
| Resend | Email alerts, only when they’re switched on and you turn them on | Your email address and the alert text, which names packages and findings in your projects. | Per Resend’s own terms |
Cookies
There’s no cookie banner because there’s nothing to consent to. Every store listed below is strictly necessary for something you asked for, and consent is only required for storage that isn’t.
| Name | Purpose | How long |
|---|---|---|
| sb-…-auth-token | Keeps you signed in. Set by Supabase as http-only, so page scripts can’t read it. | Until you sign out, or the session expires. |
| sbt_claim | Remembers which report you asked to keep while you’re away signing in with GitHub or Google. | 15 minutes, then deleted whether or not it was used. |
| sbt-side | Remembers whether you collapsed the sidebar in the app. | 1 year. |
| sbomtriage-theme (local storage) | Remembers whether you chose light or dark. | Until you clear your browser storage. |
| sbomtriage-runsheet (local storage) | Remembers which steps of a scan you’ve expanded. It never leaves your browser. | Until you clear your browser storage. |
Your rights
If you’re in the EEA or the UK, you have the rights below. They apply to everyone here regardless, because building two systems would be worse than building one.
- See it. Every project exports as JSON, and your account page shows the profile we hold.
- Take it. The JSON and CSV exports are the portable copy.
- Correct it. Your company name and profile are editable from your account.
- Delete it. Delete your account and everything goes: profile, projects, history and reports. It’s removed, not just marked as deleted.
- Withdraw consent. Agreeing to be contacted is optional. Switch it off in Settings, or use the opt-out in any email we send. Withdrawing doesn’t affect anything we did before, or your access.
- Object. Where we rely on our legitimate interest, such as security logs and rate limiting, you can object to that use. Write to us and we’ll stop unless we have compelling grounds to continue.
- Complain. You can complain to the data protection supervisory authority in the EU Member State where you live or work, or where you think the problem happened.
Anonymous use
A scan without an account creates no personal data we can connect to you. The report lives at an unguessable address for 24 hours, and then it’s removed automatically. You can delete it sooner from the report itself. Our application logs don’t record which report address you visited, though our hosting provider’s request log records the paths of all requests, report addresses included.
Questions about any of this are welcome, and so is being told something here is wrong. See also the terms.