Security
We inspect a read-only copy. We do not run the target's code.
You are about to let someone read the repository behind a company you may buy. This is what that access actually is.
Access
We work from a read-only git clone or from an escrow or VDR archive the seller already controls. Cloud cost is taken from exported billing files, not from console credentials. We do not take production access, deploy keys, or live customer data.
If you would rather not sit in the middle, we sign an NDA with the seller directly. If the seller refuses any form of technical review, that refusal is itself a finding.
What we do with it
Scanners parse artifacts: manifests, lockfiles, commit history, configuration, and the exports you gave us. The analysis pipeline runs locally. Target source is not sent to third-party model APIs as part of that pipeline. Engagement material is not used to train models.
We never execute the target's tests, build scripts, or application code. A party with a motive to influence the outcome does not get a shell on our side, and we do not give their code a shell on ours.
What the report will not contain
Secrets are reported by location and type, never by value. A live credential quoted in a report that then circulates to a buyer, their counsel, and a lender is a liability event, so it does not appear.
When the engagement ends
Repository access is revoked. Engagement material is held under NDA and is not used for any purpose beyond the engagement it belongs to. It is not reused as a sample, a case study, or training data.
This website
The marketing site and the forms worker run on Cloudflare. Sample and contact submissions go to [email protected]. They are not engagement source.
The privacy policy for personal data collected on this site is being finalized with counsel. Until it is published, ask.