Privacy Policy of the Security-Audit site
1. Data controller
The controller of the personal data collected on the Security Audit site is the company Code Rhapsodie, SARL with capital of €20,000, registered with the RCS of Lyon, SIREN 828 961 078, whose head office is located at 60 rue Jaboulay, 69007 Lyon, France.
2. Personal data processed
As part of the operation of the service, Security Audit processes the following categories of personal data:
- Account data: username, email address, password (stored as an irreversible hash), preferred language and last login date.
- Data related to authentication via GitHub: GitHub identifier, when the User chooses to log in with this provider.
- Data related to two-factor authentication (2FA): TOTP secret and backup codes, if the User enables this feature.
- Access tokens generated by the User to use the site's API.
- The composer.lock file provided by the User, as well as, where applicable, the access information to their Git repository (authentication keys or GitHub certificate) necessary to retrieve that file.
- Email notification preferences and the history of analysis reports sent.
This data is collected when creating the account and using the service, and is necessary for the proper functioning of Security Audit's features. The site does not use the content of the composer.lock file for any purpose other than the security analysis requested by the User.
3. Purposes of the processing
This data is processed in order to:
- create and manage the User's account and allow them to authenticate;
- perform security analyses of the composer.lock file and generate the associated reports;
- send the notifications and reports by email chosen by the User;
- allow projects to be shared within a team, when the User decides to do so;
- ensure account security (two-factor authentication, access tokens);
- administer the platform (account management, support).
4. Data retention period
Account data is kept for as long as the User uses the service.
In case of inactivity, an automatic account purge mechanism is implemented: after one year without logging in, a warning email is sent to the User; if no new login occurs, their account and the associated data are automatically deleted one month later, i.e. approximately thirteen months after the last login.
Unaccepted invitations to join a team are automatically deleted after six months, and teams that no longer have any members are also automatically deleted.
5. Data deletion
The User can delete their own account at any time from their personal settings area. This action results in the permanent deletion of their account as well as the data directly attached to it (projects, access tokens, team memberships).
Account deletion is irreversible. A User who wishes to exercise their right to erasure without using this feature may also contact the data controller (see section 8).
6. Who has access to the data
Access to personal data is limited to the following persons and services:
- the User themselves, from their personal space;
- the other members of a team to which the User has explicitly attached a project, only for the projects thus shared;
- the platform administrators, as part of the operation and support of the service (account list, access management);
- the following technical processors, to the extent necessary for the provision of the service: the host OVH (data hosting), the email delivery provider used for notifications and reports, and GitHub as an authentication provider when the User chooses to log in with that service.
The site also uses a technical error tracking service (Sentry) to detect and fix platform malfunctions. This service is not configured to receive identifying personal data.
No personal data is sold or transferred to third parties for commercial purposes.
7. Data security
The site implements appropriate technical measures to protect personal data, in particular the hashing of passwords and backup codes, as well as verifying the integrity of the analysis tools used (see the Terms of Use).
8. User rights
In accordance with applicable personal data protection regulations, the User has the right to access, rectify, delete and object to their personal data. They can exercise these rights directly from their personal space or by contacting the data controller at contact@code-rhapsodie.fr.