Data Handling

How ScanDrix processes code diffs — zero retention, secret redaction, BYOK, and audit logs.

Security posture for teams evaluating ScanDrix.

Zero code retention

  • Diffs are processed in ephemeral, isolated environments that exist only for the duration of a review.
  • Code is never used to train models — not ours, not any provider's (contractually enforced where providers allow it).
  • Findings metadata (rule IDs, file paths, severities) is retained for dashboard history and audit logs; source code content is not persisted.

Secret redaction

Before any content reaches a model:

  1. Entropy scanning and token-pattern detection run over the prompt payload.
  2. Matches (cloud keys, PATs, private keys, high-entropy strings) are replaced with stable placeholders.
  3. Findings about the secret itself are still reported — as a comment telling the developer to move it to a secret store.

Model prompts never need the literal credential to flag it.

Bring Your Own Key (BYOK)

Point ScanDrix at your own LLM provider keys under Settings → Providers. Requests then go directly to your provider account under your commercial relationship; ScanDrix never sees the provider key beyond the encrypted storage boundary.

BYOK is available on every plan. For fully air-gapped setups, use internal endpoints (vLLM, Ollama) in a self-hosted deployment.

Self-hosted / VPC deployment

Enterprise deployments run entirely inside your AWS, GCP, or Azure VPC — or on-prem — with no code leaving your network. See Self-Hosted Deployment.

Access control & audit

  • Role-based access for workspace members (admin, member, viewer).
  • Audit logs record rule changes, suppressions, key creation/rotation, and integration changes — exportable for SOC 2 reviews.
  • Team keys are scoped to a team and rotatable at any time; rotation is immediate.

Compliance

  • SOC 2 Aligned Controls documentation available under NDA — request via security@scandrix.dev.
  • Mutual NDAs supported for enterprise evaluations.
  • Subprocessor list and DPA provided on request.

Reporting a vulnerability

Email security@scandrix.dev with reproduction steps. We acknowledge within 2 business days and coordinate disclosure.