Privacy policy
Privacy, short and concrete.
We run a behavioral analysis engine. Here is exactly what we collect, why, and what we don't.
Effective 2026-05-06 · v1.2
01 What we collect
When you use the Manticore GitHub Action or our hosted application, we collect:
- Your work email. Used only to sign you in via magic link.
- The lockfile changes in the pull requests you point us at. Package names, versions, hashes.
- Organization and repository identifiers. So reports land in the right place.
- Aggregate usage metrics. Job count, duration and verdict distribution, scoped to your organization.
02 Why we collect it
To analyze the packages you pointed us at, write the verdict back to the right pull request, and bill the right organization. That is the whole list.
03 What we don't do
- We don't read your source code. We only analyze the third-party packages referenced by your lockfiles.
- We don't run trackers or analytics on this website. No Google Analytics, no Segment, no session replay. The demo film loads from YouTube only after you press play.
- We don't sell customer data. We sell behavioral analysis software, and that is the only thing we sell.
04 Sandbox data
The packages we analyze are public by definition. The behavioral traces we produce (process trees, network endpoints, file accesses) describe the package, not your code. We may aggregate and publish those traces to warn the ecosystem; your organization is never identified in that publication.
05 Retention
Pull request reports are retained for 90 days by default, or until you delete them. Sign-in logs are retained for 30 days. Aggregate usage metrics are retained indefinitely in anonymized form. Your organization's raw lockfiles are not stored after the analysis completes.
06 Your rights
You can request export or deletion of all data associated with your organization at any time, in writing. We confirm within 30 days under GDPR and within the timelines mandated by your jurisdiction. Data subject requests from EU residents go to the address below.
07 Contact
Data controller: TazarSec, Jyväskylä, Central Finland.
Questions, requests, concerns and security disclosures: hello@tazarsec.dev
