Operating policy

Privacy and retention

Anonymous package discovery and report viewing require no email or account. Package reports, artifact identities and recorded observations are public. Do not put secrets or personal data in public package contents or output.

Request handling

The ingress uses your network address to limit abuse. Admission stores a keyed identifier that rotates daily, groups IPv6 addresses by /64, and is removed after seven days. Raw addresses are not stored in the catalog. The default deployment disables access logs and filters request details from proxy errors. There is no advertising or browser analytics integration.

Retention

Maintainer accounts

Maintainer tools are coming soon. GitHub sign-in, repository linking, release monitoring and email alerts are not available on the public website. We will explain their data handling and account controls before they become available.

Service providers

Discovery requests public npm registry metadata. The control service may send fixed operational error names to an operator-configured Sentry endpoint. It does not send package contents, request bodies, credentials, network addresses or user profiles to error tracking.

Corrections and removal

For an incorrect report or public content removal request, open a repository issue with the report URL and reason. Send sensitive security details through the private disclosure process. Removal does not rewrite the original compatibility classification. Log removal retains the report's structured observations and provenance; invalidation marks the report as unsuitable for reuse. The operator audits the reason. Do not include sensitive content in a public issue.

Retained behavioral evidence

A report may include historical named assertions from public GitHub commits. Their source, fixture hashes, approved capabilities and results remain part of the public evidence. Registering new maintainer assertions through the website is not available yet.