Trust
Trust & security
A security tool has to earn access to your systems. Here's how Hivexly handles your code, your secrets and the apps you ask it to test.
Your code
- For each repository scan, code is cloned into a temporary workspace and deleted when the scan ends.
- Your code is never used to train anything.
Your secrets
When a scan detects a secret, it is redacted before the finding is stored.
Testing only what you own
- Dynamic tests start only after you prove ownership of a target with a DNS record or a well-known file.
- Every target has an agreed scope: allowed hosts, a request-rate cap and a testing window.
- Organizations use role-based access, and an audit log records who did what.
Placeholder
Compliance status, sub-processors, data-residency details and a security contact are to be published by Hivexly. Until then, email [email protected].