Policy
Privacy
The MVP stores scan targets, events, reports, findings, and operator-created API keys when persistence is configured.
API key secrets are hashed and only displayed once.
Threat ingestion hashes IP addresses when provided.
External scanners can send target URLs to third-party services only when explicitly enabled.