Back to home

Privacy Policy

Version 1.0 · September 24, 2026

This policy explains what data VegaSec processes, why, with whom it is shared, how long it is kept and how you exercise your rights. It covers the site, the scans, the reports and the account area.

Who we are and what this policy covers

VegaSec is a Je4nDev product. We process data to run static analysis of contracts and repositories, produce risk reports and let anyone verify the integrity of those reports.

When a part of the product is not live yet, it is listed here as not existing instead of being promised. Example: the account area depends on sign in, and without sign in there is no account.

What we process

  • Account, when you sign in with Google: Google account identifier, name, email and public photo URL. Without sign in, no account is created and the public scan keeps working.
  • Scans and reports: the source code you submit, the derived findings, analyzer versions, report id, timestamp, canonical hash and digital signature.
  • Technical record: on authenticated flows the IP address is hashed with a secret salt before storage. We do not keep the IP in clear text.
  • Payment, when a paid plan exists: billing is processed by a specialized provider and card data never reaches our servers.

Why we use it

  • To run the analysis and build the report.
  • To keep your account and the history of reports you ran while signed in.
  • To sign the report and allow public integrity verification against the published key.
  • To prevent abuse, fraud and service overload.
  • We do not use personal data for advertising and we do not sell or rent personal data.

A report belongs to the link, not to the scanner

By design the public scan asks for no sign in and the report is reachable by anyone holding the link. Whoever holds the link holds the report.

When listing is on, the report appears in VegaSec public indexes. Turning listing off removes it from those indexes and does not invalidate the signature already issued.

Signing keys and the verification result are public by definition: that is what makes independent verification possible.

Cookies

  • A signed session cookie, when you sign in to your account.
  • Temporary cookies for the sign in flow, used to protect authentication state and cleared at the end of the flow.
  • No advertising cookies and no third party trackers. The product code loads no third party analytics.

Who we share with

  • Google, only as identity provider, when you choose to sign in with Google.
  • Payment provider, when a paid plan is charged.
  • Authorities, when there is a legal obligation or a valid order.
  • Outside those cases we do not share personal data with third parties.

Where the data lives

On servers contracted by Je4nDev, with a self hosted database. Report content is not stored on third party platforms.

How long we keep it

  • Reports and submitted code: while the report link exists.
  • Account and history: while the account exists.
  • You can ask for the report to be removed from public indexes at any time, and for permanent deletion of the records, through the contact below.

Your rights

Under LGPD (Brazilian Law 13.709/2018) and, where applicable, GDPR, you may request confirmation of processing, access, correction, portability, anonymization, deletion and information about sharing.

Requests go to the contact email and are answered within 15 days.

Security

  • Reports signed with Ed25519 and a published public key.
  • IP addresses stored only as salted hashes.
  • Restricted database access and fail closed checks: when in doubt the system denies instead of accepting.

Minors

The service is meant for people over 18 and for professional use. We do not intentionally process data from children or adolescents.

Changes to this policy

Every revision gets a version number and a date. Material changes are announced on the site before taking effect.