Draft, not yet in force. Each statement below describes what the service actually stores, and where it sends it, as of 5 October 2026. Fill every highlighted blank and have a lawyer review it before this page is linked.
Last updated date of publication
In short. We collect only what we need to sign you in and analyse your SBOMs. There are no advertising or analytics cookies and no tracking scripts. No AI model reads your files. We sell nothing. To check your components, we send their names and versions to public vulnerability databases, but never who you are.
legal entity name, registered address, is the controller of
the personal data described here. Questions and requests: [email protected].
Our representative in the EU under Article 27 of the GDPR is EU representative's name and address. You can contact them instead of us.
When you upload an SBOM that contains personal data, for example an author's name in its metadata, we process that data for you, as your processor, and only to provide the service. Data processing terms are available on request.
| When | What | Why, and our legal basis | How long |
|---|---|---|---|
| You write to us through the form on this website | Your email address and message; the page you sent it from; your country, as your connection reports it; your browser's user-agent string; a salted hash of your IP address (not the address itself) | To reply to you, and to keep the early-access list you asked to join. To block floods of automated submissions. Legitimate interest, and your request. | proposed: 24 months after we were last in touch, or sooner if you ask |
| You sign in or sign up | Your email address. The one-time code, stored only as a keyed hash and never in readable form. A keyed hash of your IP address, used to limit attempts | To prove you control the address, and to stop guessing and abuse. Contract. | Deleted within 24 hours. A code expires after 10 minutes, or as soon as it is used |
| You have an account | Email address, an optional display name, your role and workspace, when the account was created, and when it was last used (to the nearest hour) | To run your account and decide what you may see. Contract. | Until the account is closed, then deleted within 30 days |
| You upload an SBOM | The file, its name, who uploaded it and when, the product it belongs to, and the analysis we produce | To provide the service. Contract. | Until you delete it or close the account, then deleted within 30 days |
| You act in the service | An audit record of significant actions, such as signing up, plan changes and confirmed decisions about findings, with the email address of the person who acted | Accountability: vulnerability handling under the CRA needs a record of who decided what, and when. Legitimate interest. | For the life of the account. confirm with your lawyer |
| You buy Pro | From our reseller: your name or company name, email address, country, VAT number if you give one, and your subscription status. Never card details, which only the reseller sees | To give you the plan you paid for. Contract, and legal obligations for tax records. | As long as tax law requires |
| Any request to our servers | Your IP address and request details, processed by Cloudflare, which hosts the service and protects it from attacks | To deliver and secure the service. Legitimate interest. | Under Cloudflare's own retention |
The app sets two cookies, both strictly necessary for signing in:
__Host-session: keeps you signed in. It lasts 12 hours.__Host-signin: protects the sign-in step. It lasts 10 minutes.Neither can be read by scripts or sent to another site. There are no analytics, advertising or third-party cookies. When the anti-spam check on our contact form is switched on, Cloudflare Turnstile runs a check in your browser to tell people from bots. It is not used for advertising.
We use a small number of providers. Each sees only what its job needs.
| Provider | What for | What they see | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, DNS, email forwarding, anti-spam check | Everything stored in the service, encrypted at rest | Global network; storage location region |
| Resend | Sending sign-in codes | Your email address and the code | United States |
| Paddle / Lemon Squeezy | Selling Pro as merchant of record | What you give them at checkout | country |
| mailbox provider for [email protected] | Receiving your emails to us | Your messages | country |
Public vulnerability databases. To find what affects a component, we look it up by name and version in public sources: OSV.dev (run by Google), the U.S. National Vulnerability Database, and GitHub, for public repositories named in your SBOM. Those lookups carry only component names, versions and public repository references. They never carry your name, your company, your product names or your file.
Where analysis runs. SBOMs are analysed on Cloudflare's container platform, the same provider that hosts the service, and on a machine we operate in country. No AI model reads your SBOMs. We use a language model only on vendors' public advisories. It runs on our own hardware, and nothing is sent to a third-party AI service.
Some providers above are in the United States. Where personal data from the EU or UK goes to a country without an adequacy decision, it is protected by the European Commission's Standard Contractual Clauses, or by the provider's certification under the EU–US Data Privacy Framework. confirm the mechanism for each provider
You can ask us to give you a copy of your personal data, correct it, delete it, or send it to you in a portable
format. You can also object to, or ask us to restrict, how we use it. Email [email protected] from the
address on your account. We answer within one month. If you think we have handled your data wrongly, you can complain
to the data protection authority where you live or work. We would be glad to hear from you first.
Data is encrypted in transit and at rest. Every request is checked against your workspace, so one customer's data is never served to another. Sign-in codes and IP addresses are stored only as keyed hashes. Card data never reaches us.
Firmpath is a service for businesses and is not meant for anyone under 16.
If we change this policy in a way that matters to you, we will email account holders before the change takes effect. The date at the top shows when it last changed.