PRIVACY MODEL

Private by design.

This page describes the service behavior implemented by StoreReady. Review it with qualified counsel before a production commercial launch.

Source inputsSource ZIPs, GitHub repository snapshots and Human QA session files are temporary audit inputs. They are deleted after audit completion by default unless the operator explicitly enables upload retention.
GitHub accessStoreReady stores non-secret GitHub App installation metadata and audit provenance such as repository, requested ref and resolved commit SHA. GitHub user access tokens and installation tokens are not persisted. The temporary user token used to verify an installation is explicitly revoked after verification.
ReportsAudit reports, source provenance, billing/entitlement records and account metadata persist so customers can retrieve their results and history.
API keysStoreReady API keys are random credentials. The service stores their cryptographic hashes rather than plaintext keys and shows a new key only when it is issued.
Third-party scannersSecurity tools execute behind the private StoreReady service. Operators must disclose any scanner configuration that sends vulnerability metadata to an external service; source is not intentionally sent to third-party AI.
DeletionTemporary source is deleted automatically by default. Operators must define production retention/deletion procedures for accounts, audit reports and GitHub connection metadata, along with support contacts and legally required retention.