HomePrivacy notice
Privacy notice

Know what stays local and what optional services process.

BoundaryCI is local-first. Network processing occurs only when a customer enables an optional integration, uses BoundaryCI Cloud, authenticates, requests support, or purchases a subscription.

Local deterministic scans

Deterministic scans run on the customer machine or GitHub Actions runner and make no BoundaryCI network request. Merely running the scanner does not send repositories, migrations, findings, credentials, or workflow metadata to the Developer.

BoundaryCI has no product analytics, behavioral advertising, or scanner telemetry. Information reaches BoundaryCI Cloud only when upload is explicitly enabled.

Optional Cloud upload

The Cloud history upload can include repository and commit context, scan timestamps, summary counts, finding classifications, relative paths, line numbers, short evidence, remediation, disposition, and waiver metadata.

That history payload excludes complete migration files, database credentials, absolute scan targets, and migration inventories. Common secret patterns are redacted, but redaction cannot guarantee removal of every confidential value. Managed AI review, when separately authorized, has the transient processing described below.

Accounts, authentication, and abuse protection

Supabase processes authentication records and hosts organization, repository, usage, finding, finding-visibility preferences, and subscription state. Repository ingestion tokens are stored as SHA-256 hashes rather than plaintext.

Cloudflare Turnstile processes browser and request signals needed to challenge automated authentication attempts. Its public site key is browser-visible; its verification secret remains server-side in Supabase.

Billing

Stripe processes paid subscriptions, payment methods, invoices, tax identifiers, and billing addresses. BoundaryCI stores customer, subscription, price, status, event, and billing-period identifiers needed to synchronize plan access.

The Developer does not receive or store complete payment-card numbers. Stripe retains payment and invoice information under its own policies.

Optional AI review and information customers submit

For managed review, an owner or administrator of an eligible paid organization must first accept the dashboard disclosure. The runner sends only repository identity to check eligibility. If enabled, it redacts common secret patterns locally and sends up to 80,000 characters of migration text through BoundaryCI to Fireworks under the Developer's managed account. BoundaryCI does not store that migration input; it can store the normalized findings, model, status, input hash, and operational metadata needed for history, limits, retries, and abuse prevention.

Managed review can be disabled for an organization, repository, or workflow. Existing organizations remain off until authorization. Direct bring-your-own-key review remains available; in that mode, migration text is sent from the customer environment directly to Fireworks under the customer's account and BoundaryCI does not receive that direct request or response.

Fireworks processes managed and direct inference under its own terms and privacy practices. Customers are responsible for ensuring they are authorized to submit the selected code. Secret redaction is defense in depth and cannot guarantee removal of every confidential value.

Information voluntarily submitted through GitHub issues, pull requests, discussions, or vulnerability reports is processed to respond and maintain the product. Customers should remove credentials, personal data, and proprietary material before submission.

Retention, sharing, and requests

The Developer does not sell personal information. Information is shared only as needed to provide the selected services, respond through support channels, comply with law, or protect rights and security.

Cloud records may be deleted when an organization or repository is removed, while billing and event identifiers can be retained when reasonably needed for accounting, fraud prevention, disputes, and legal compliance. Use the support page for access, correction, export, or deletion requests without posting confidential information publicly.