Data Handling
How ScanDrix processes code diffs — zero retention, secret redaction, BYOK, and audit logs.
Security posture for teams evaluating ScanDrix.
Zero code retention
- Diffs are processed in ephemeral, isolated environments that exist only for the duration of a review.
- Code is never used to train models — not ours, not any provider's (contractually enforced where providers allow it).
- Findings metadata (rule IDs, file paths, severities) is retained for dashboard history and audit logs; source code content is not persisted.
Secret redaction
Before any content reaches a model:
- Entropy scanning and token-pattern detection run over the prompt payload.
- Matches (cloud keys, PATs, private keys, high-entropy strings) are replaced with stable placeholders.
- Findings about the secret itself are still reported — as a comment telling the developer to move it to a secret store.
Model prompts never need the literal credential to flag it.
Bring Your Own Key (BYOK)
Point ScanDrix at your own LLM provider keys under Settings → Providers. Requests then go directly to your provider account under your commercial relationship; ScanDrix never sees the provider key beyond the encrypted storage boundary.
BYOK is available on every plan. For fully air-gapped setups, use internal endpoints (vLLM, Ollama) in a self-hosted deployment.
Self-hosted / VPC deployment
Enterprise deployments run entirely inside your AWS, GCP, or Azure VPC — or on-prem — with no code leaving your network. See Self-Hosted Deployment.
Access control & audit
- Role-based access for workspace members (admin, member, viewer).
- Audit logs record rule changes, suppressions, key creation/rotation, and integration changes — exportable for SOC 2 reviews.
- Team keys are scoped to a team and rotatable at any time; rotation is immediate.
Compliance
- SOC 2 Aligned Controls documentation available under NDA — request via security@scandrix.dev.
- Mutual NDAs supported for enterprise evaluations.
- Subprocessor list and DPA provided on request.
Reporting a vulnerability
Email security@scandrix.dev with reproduction steps. We acknowledge within 2 business days and coordinate disclosure.