Security

You give us access to your code, so you should know what happens to it. This page covers what we do with your code and data, what we keep, and how we protect our own systems.

Your code

  • The GitHub Action uploads only the files changed in a commit, never your repository history.
  • Uploads are encrypted (AES-256-GCM) before they enter our queue, and bound to one scan so they cannot be replayed.
  • Each scan runs in its own throwaway sandbox: gVisor kernel isolation, no network access, a non-root user, no privileges, memory and CPU caps.
  • Code is streamed into the sandbox’s memory and never written to disk. The sandbox is destroyed when the scan ends.
  • We keep findings only: rule, file, line and a short masked excerpt. Secrets are masked before anything is stored or logged.

AI review

  • Only the riskiest findings are reviewed (at most 8 per scan), with about 25 lines of context and secrets masked.
  • The AI can only add an explanation and a suggested fix to a finding. It cannot hide or delete findings, and never sees secrets.

Scanning other people’s sites safely

  • The free scan is passive: ordinary GET requests to the exact address submitted, from an identifiable bot, with strict rate limits.
  • It refuses private and internal networks (including cloud metadata addresses), checks every redirect, and never follows one to another site.
  • Database checks run only on sites whose owner proved control (DNS or a file), with public keys only, and count rows without reading them.

Your account

  • You sign in with GitHub. We never see a password, and we throw away the GitHub token right after sign-in.
  • Sessions are random tokens; we store only their hash. Payments are handled by Stripe: we never see card details.
  • You can export your data or delete your account at any time. Deletion cancels billing and erases your data immediately.

Our platform

  • Strict Content-Security-Policy with nonces, HSTS, and no third-party scripts on our pages.
  • Services are isolated on separate networks. Third-party APIs are reachable only through an allowlisting proxy.
  • We don’t store client IP addresses. Secrets, cookies and request bodies are removed from our logs.

Report a vulnerability

Found a security issue in Afterprompt? Email security@afterprompt.io. We read every report and will get back to you. Details in our security.txt.