legal

Privacy Policy

Last updated: August 25, 2026 · Hexasentra

1. What we collect

Account data (work email, hashed password), billing metadata handled by our payment processor, product telemetry (scan job status, error logs), and scan metadata about the repositories we monitor on your behalf (repo names, commit hashes, finding classifications).

2. Secrets handling

Credential values detected during scans are processed to verify liveness and then stored MASKED by default. Unmasking requires authenticated action and is audit-logged. We never sell, share, or use detected credentials for any purpose other than serving your account.

3. Verification calls

Liveness verification performs read-only requests to third-party providers (e.g., AWS, Stripe). These requests contain the candidate credential only. No repository content is transmitted to providers.

4. What we do NOT collect

5. Retention & deletion

Scan metadata is retained while your subscription is active. Findings follow your configured retention policy (default 180 days). On account closure, all scan artifacts and findings are deleted within 30 days.

6. Your rights

GDPR/CCPA: access, correction, export, deletion via dashboard or privacy@hexasentra.com. We respond within 30 days.

7. Contact

privacy@hexasentra.com · Hexasentra