Security
We apply what we sell
A security tool that gets hacked loses everything. Here’s how we protect your code, and how to tell us if you find a problem.
We scan ourselves
ScanMyApp, scanned by ScanMyApp
SCANMYAPP.DEV SCOREFirst report coming soon
How we protect your code
- The public website holds no secrets and no access to your data
- Each analysis runs in an isolated, disposable environment with no inbound access
- Your code is analysed statically, never executed, and deleted afterwards
- Read-only repository access, revocable at any time
- Keys stay server-side and are rotated regularly
- Strict access rules on every database table
Report a vulnerability
Found a security issue in ScanMyApp? Email security@scanmyapp.dev with a description, the steps to reproduce it and its impact. We acknowledge every report within 72 hours.
Please
- Only test against your own account and data.
- Don’t access, change or delete other people’s data, and stop as soon as you have shown the issue.
- Don’t run denial-of-service tests, spam or social engineering.
- Give us reasonable time to fix the issue before talking about it publicly.
In return
- We won’t take legal action against good-faith research that follows these rules.
- We’ll keep you informed and credit you if you wish.
- Valid reports receive a small reward as a thank-you.
Our security.txt file lists these details in a standard format. Questions about how we handle your data? See our privacy policy.
