We take the protection of your data seriously and only process it as far as ZeroFlaw needs to. Here you can find out which data we process when, for what purpose and for how long, and which rights you have.
Controller
The controller for data processing on this website and in the ZeroFlaw application is:
[set legal.name in config.php]
[set legal.street in config.php]
[set legal.zip in config.php] [set legal.city in config.php]
Germany
E-mail: [set legal.email in config.php]
You can reach us at the same address with any data protection questions. We are not required to appoint a data protection officer under Art. 37 GDPR and § 38 BDSG.
Hosting and server log files
ZeroFlaw runs on servers of [set legal.hoster in config.php]. The hosting provider processes the data exclusively on our behalf and according to our instructions (Art. 28 GDPR). The scans themselves run on our own scan servers ("workers").
Whenever you open a page, your browser transmits technically necessary data that the web server stores in log files: IP address, date and time, requested address, HTTP status code, amount of data transferred, referrer and browser identifier (user agent). We use this data to deliver the page, fix faults and fend off attacks. The legal basis is our legitimate interest in secure and stable operation (Art. 6 (1) (f) GDPR). The log files are deleted after 14 days unless they are needed longer to investigate a specific security incident.
Cookies
We only set cookies that are technically necessary for operation (§ 25 (2) no. 2 TDDDG, Art. 6 (1) (b) and (f) GDPR). We therefore do not ask for consent and show no cookie banner. We use no tracking, no analytics or marketing services and no local browser storage (localStorage).
| Name | Purpose | Duration |
|---|---|---|
sid | Keeps you signed in. Contains only a random identifier; our database only stores its hash. HttpOnly, Secure, SameSite=Lax. | 14 days, shorter for admins |
zf_csrf | Protection against forged form requests (CSRF). | browser session |
zf_lang | Remembers the chosen language (German or English). | 1 year |
zf_oauth, zf_osu, zf_oc | Secure a sign-in with GitHub or Google that is in progress. | 10 minutes |
zf_flash | Shows a message once after a redirect. | until shown |
Account and sign-in
For an account we process your name, your e-mail address and your password. We never store the password in plain text, only as an Argon2id hash. We also store your language, your plan and, if enabled, the secret for two-factor sign-in (TOTP) in encrypted form.
For every active session we store the IP address, browser identifier and time of last use so that you can see and end your sessions under "Account & security". When you sign in from a new device, we send you a notification e-mail for your security; for this we remember known devices. We count failed sign-in attempts to prevent password guessing.
The legal basis is the performance of the user agreement (Art. 6 (1) (b) GDPR) and our legitimate interest in account security (Art. 6 (1) (f) GDPR). You can delete your account yourself at any time under "Account & security".
Sign-in with GitHub or Google
You can optionally sign in through an external provider. Only when you click the corresponding button do we forward you to the provider. With your consent, the provider tells us your e-mail address, your name and a user ID; we never learn your password at the provider. The legal basis is Art. 6 (1) (b) GDPR. You can remove the link at any time under "Account & security".
- GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
The providers also process data in the USA. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which the providers are certified (Art. 45 GDPR).
Scans and results
At the heart of ZeroFlaw is checking source code and websites that belong to you or for which you are authorized.
- Code scans: Uploaded ZIP files and repositories imported via Git are analyzed on our scan servers and deleted right after the scan is finished.
- Live scans: We store the domains you enter and the proof that you control the domain. During the scan we send requests to this domain. A login cookie you optionally provide for scans behind a login is stored encrypted.
- Results: For every finding we store the title, severity, location, description and, where available, a short code snippet. Descriptions, code snippets and your notes are stored encrypted with AES-256-GCM. Secrets that were found (e.g. passwords or API keys) are only shown masked.
- Schedules and notifications: your settings for recurring scans and notifications.
The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR). If your code or website contains personal data of third parties, we process it as your processor; business customers can find our data processing agreement for this.
Public data sources during scans
To classify findings, our scan servers query public security databases, for example OSV.dev (known vulnerabilities in packages), FIRST EPSS and CISA KEV (likelihood of exploitation), crt.sh and Cert Spotter (certificates of a domain) and WPVulnerability (WordPress extensions). We only transmit technical details such as package names, version numbers, CVE identifiers or domain names, never your account data, your source code or your IP address.
AI explanation
Only when you explicitly click "Explain (AI)" on a finding do we send the title, severity, location, description and code snippet of that single finding to Anthropic, PBC, 548 Market Street, San Francisco, CA 94104, USA, to generate an easy-to-understand explanation. We mask secrets in the code snippet beforehand. We do not transmit your name or e-mail address. Under its commercial terms, Anthropic does not use the data to train its models. We store the answer encrypted so that it does not have to be requested again.
The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR), as you actively request the feature. The transfer to the USA is based on EU standard contractual clauses (Art. 46 (2) (c) GDPR).
Payment
You pay for paid plans through the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. You enter your payment details (e.g. card number or IBAN) directly with Stripe; we do not receive them. We transmit your e-mail address, your name and the chosen plan to Stripe and receive the payment status, a customer ID and the subscription term from Stripe. Stripe is an independent controller for payment processing and also processes data in the USA; the transfer is safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses. Stripe's privacy notice: stripe.com/privacy.
The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR). We keep invoice data for up to ten years because of legal obligations (§ 147 AO, § 257 HGB; Art. 6 (1) (c) GDPR).
E-mails
We send you e-mails that are part of running your account: confirmations, password reset links, notices about sign-ins from new devices, team invitations and support replies. You only receive notifications about finished scans, new critical findings or expiring certificates if you have enabled them in the settings, where you can turn them off at any time. We do not send advertising newsletters. We delete sent e-mails from our outbox one day after sending. The legal basis is Art. 6 (1) (b) GDPR.
Support, teams and API
- Support: When you write to us in the support chat or report a bug, we store your messages, attachments and, for bug reports, the affected page and the browser identifier to handle your request.
- Teams: When you invite someone to your team, we process the invited person's e-mail address to send the invitation. Team members see the shared domains, scans and results.
- API tokens: For CI/CD integration we only store a hash of your tokens, never the token itself.
The legal basis in each case is Art. 6 (1) (b) GDPR.
Security log
We log security-relevant events such as sign-ins, password changes, changes to two-factor sign-in, role changes and admin actions with time, IP address and browser identifier. This protects your account and helps investigate abuse (Art. 6 (1) (f) GDPR). You can see your own events under "Account & security". If you delete your account, we remove all other entries and keep security-relevant entries only in pseudonymized form, i.e. without reference to your name or e-mail address.
Retention
| Data | Deleted |
|---|---|
| Uploaded source code (ZIP, Git import) | right after the scan is finished |
| Scans, findings, notes, schedules, domains | when you delete them, at the latest with your account |
| Account, team and support data | when your account is deleted |
| Sessions | when you sign out, at the latest after 14 days |
| Server log files | after 14 days |
| E-mails in the outbox | one day after sending |
| Abuse counters (sign-in attempts, limits) | automatically when the respective time window ends |
| Security log | with the account; security-relevant entries afterwards only pseudonymized |
| Invoice and payment data | after the statutory retention period of up to ten years |
Recipients and third countries
We do not sell data and do not pass it on for advertising purposes. Recipients are only the service providers named in this policy: our hosting provider, Stripe, Anthropic (only for the AI explanation) and the providers of sign-in with GitHub or Google. Where data is transferred to countries outside the EU, the respective section describes the legal basis. Authorities only receive data if we are legally obliged to provide it.
Data security
As the provider of a security tool, we hold ourselves to our own standards:
- Transmission only encrypted via TLS, with HSTS and a strict Content Security Policy.
- Encryption of sensitive content (finding descriptions, code snippets, notes, AI answers, login cookies for scans) with AES-256-GCM.
- Passwords as Argon2id hashes, session and API tokens stored only as hashes.
- Two-factor sign-in available for all accounts and mandatory for administrators.
- Protection against password guessing through lockouts and counters, logging of security-relevant events.
- Scans only for domains whose control you have proven.
Read more and find out how to report vulnerabilities to us on the Security page.
Your rights
You have the right at any time to:
- access the data we store about you (Art. 15 GDPR),
- rectification of incorrect data (Art. 16 GDPR),
- erasure of your data (Art. 17 GDPR), for example by deleting your account,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR); you can also export your scan reports as PDF or SARIF and the software bill of materials as JSON at any time,
- withdraw consent with effect for the future (Art. 7 (3) GDPR).
Just write to us at [set legal.email in config.php]. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
Other
Providing your data is necessary to create and use an account; without an e-mail address and password (or a sign-in through a provider) we cannot create an account. There is no automated decision-making including profiling within the meaning of Art. 22 GDPR.
We update this policy when ZeroFlaw or the legal situation changes. The version published here applies; the date of the last change is shown at the top of this page.