Last updated: August 25, 2026 · Hexasentra
Account data (work email, hashed password), billing metadata handled by our payment processor, product telemetry (scan job status, error logs), and scan metadata about the repositories we monitor on your behalf (repo names, commit hashes, finding classifications).
Credential values detected during scans are processed to verify liveness and then stored MASKED by default. Unmasking requires authenticated action and is audit-logged. We never sell, share, or use detected credentials for any purpose other than serving your account.
Liveness verification performs read-only requests to third-party providers (e.g., AWS, Stripe). These requests contain the candidate credential only. No repository content is transmitted to providers.
Scan metadata is retained while your subscription is active. Findings follow your configured retention policy (default 180 days). On account closure, all scan artifacts and findings are deleted within 30 days.
GDPR/CCPA: access, correction, export, deletion via dashboard or privacy@hexasentra.com. We respond within 30 days.
privacy@hexasentra.com · Hexasentra