Operating the platform

Your data

What is stored, for how long, and what leaves Webcuris.

What is stored

Scan history, findings and their evidence, account data, and — from repository scans — commit author names, which are data about people who never signed up. That last one is stated plainly here because it is the one most easily overlooked.

Encryption

Sensitive fields are encrypted at the field level with envelope encryption and key rotation, on both supported databases. Session cookies lent for an authenticated scan are encrypted while queued and deleted when the scan ends.

Retention

Scan history and findings are kept until you delete them, unless a retention window is switched on — in which case the Data Retention page states the period and a scheduled sweep removes anything past it.

Nothing is written to a visitor's browser

The marketing site sets no cookies and writes nothing to local storage, identifying or not. That is why there is no consent banner: there is nothing to consent to.