Privacy
Selected artifacts are processed locally in your browser. Source code, archive contents, filenames, paths, snippets, local evidence, credentials, and settlement transaction rows are not designed to leave your browser.
This screening stage uses privacy-first website analytics to measure public exposure. If you explicitly submit an anonymous screening signal after a completed scan and SP-API maintainer attestation, the browser briefly records a coarse route representing only the result category: affected-code, affected-parser, or not-detected. No email, company identity, source material, artifact hash, filename, or evidence is submitted.
A browser-local duplicate guard limits screening submission to one per browser profile for 30 days. This is not organization-level identity or deduplication.