Resources

Data & security

Riscly handles sensitive material — source code, cloud configuration and secrets. Here is how that data is accessed, stored and controlled.

Read-only by default

Access to connected systems is read-only wherever possible. The one exception is applying a fix, which writes only the file you explicitly approve — and always returns a link to the resulting commit so you can review exactly what changed.

Secrets are masked

When a scan detects a secret, the value is masked before it is stored. Riscly records that a secret exists and where, not the secret itself.

Subprocessors

Riscly relies on a small set of infrastructure and service providers. The full, current list — with their roles and locations — is maintained in the Privacy Policy, alongside the legal bases for processing.

  • Hosting & database — Supabase, Render, Vercel
  • Payments — Stripe
  • Email — Resend
  • AI analysis & fixes (when enabled) — Anthropic
  • Vulnerability data — OSV.dev

International transfers

Riscly is offered worldwide. Where data is transferred outside the EU, transfers rely on the EU Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework, with appropriate supplementary measures.

Your control

  • Disconnect any provider at any time — access stops immediately.
  • Deleting a project removes its scan and analysis data.
  • Request a Data Processing Agreement (DPA) for business use.
  • Exercise your data-subject rights via the contact in the Privacy Policy.

Riscly is an assistive tool

Automated analysis cannot find every vulnerability and fixes are suggestions you must review. Riscly provides no guarantee of security — responsibility for your systems stays with you. See the Terms.

Related