Operating the platform
Your data
What is stored, for how long, and what leaves Webcuris.
What is stored
Scan history, findings and their evidence, account data, and — from repository scans — commit author names, which are data about people who never signed up. That last one is stated plainly here because it is the one most easily overlooked.
Encryption
Sensitive fields are encrypted at the field level with envelope encryption and key rotation, on both supported databases. Session cookies lent for an authenticated scan are encrypted while queued and deleted when the scan ends.
Retention
Scan history and findings are kept until you delete them, unless a retention window is switched on — in which case the Data Retention page states the period and a scheduled sweep removes anything past it.
Nothing is written to a visitor's browser
The marketing site sets no cookies and writes nothing to local storage, identifying or not. That is why there is no consent banner: there is nothing to consent to.