Skip to content

Trust

Trust & security

A security tool has to earn access to your systems. Here's how Hivexly handles your code, your secrets and the apps you ask it to test.

Your code

  • For each repository scan, code is cloned into a temporary workspace and deleted when the scan ends.
  • Your code is never used to train anything.

Your secrets

When a scan detects a secret, it is redacted before the finding is stored.

Testing only what you own

  • Dynamic tests start only after you prove ownership of a target with a DNS record or a well-known file.
  • Every target has an agreed scope: allowed hosts, a request-rate cap and a testing window.
  • Organizations use role-based access, and an audit log records who did what.

Placeholder

Compliance status, sub-processors, data-residency details and a security contact are to be published by Hivexly. Until then, email [email protected].