Secure Code LLC, located at 417 Staunton Dr, Leander, Texas 78641 (“Secure Code,” “we,” “us,” or “our”), operates Zyloch, a business-to-business Software-as-a-Service platform providing automated security and compliance scanning for software source-code repositories.
Zyloch includes its website, web application, API, GitHub App, scanning engine, dashboards, reports, Software Bills of Materials, and related services collectively referred to as the “Services.”
The Cookie Policy governs the use of cookies and similar technologies when individuals visit or use the Services. It forms part of the Secure Code Privacy Policy and should be read together with the Terms and Conditions.
1. Cookies and Similar Technologies
1.1A cookie is a small text file stored on a device when a website or web application is accessed. Cookies may allow the Services to recognize a browser, maintain an authenticated session, remember selected settings, prevent unauthorized activity, or support technical operations.
1.2Some cookies exist only while a browser remains open and are deleted when the browser session ends. Other cookies remain on the device until they expire, are replaced, or are deleted through browser settings.
1.3Similar technologies may perform comparable functions without using a traditional browser cookie. Such technologies may include:
- (a) local storage;
- (b) session storage;
- (c) software-development kits;
- (d) application programming interfaces;
- (e) authentication tokens;
- (f) device or browser identifiers;
- (g) server logs;
- (h) pixels or tags; and
- (i) security and fraud-prevention technologies.
1.4References to “cookies” in the Cookie Policy include comparable technologies where the context permits.
2. Scope
2.1The Cookie Policy applies when a person:
- (a) visits a Secure Code or Zyloch website;
- (b) creates or accesses a Zyloch account;
- (c) uses the Zyloch web dashboard;
- (d) joins a customer organization or workspace;
- (e) authenticates through GitHub;
- (f) installs or authorizes the Zyloch GitHub App;
- (g) manages a Subscription;
- (h) uses support or account-management features; or
- (i) otherwise interacts with a browser-based part of the Services.
2.2Cookies placed on websites, applications, payment pages, or services operated independently by third parties are governed by the privacy and cookie practices of those third parties.
3. How Secure Code Uses Cookies
3.1Secure Code uses cookies where reasonably necessary to provide, protect, maintain, and administer the Services.
3.2Cookies may be used to:
- (a) authenticate Users;
- (b) maintain signed sessions;
- (c) recognize an authorized account during navigation;
- (d) support JSON Web Token session management;
- (e) prevent unauthorized access;
- (f) protect against Cross-Site Request Forgery;
- (g) detect unusual, abusive, or fraudulent activity;
- (h) preserve essential account or security settings;
- (i) distribute traffic across infrastructure;
- (j) maintain Service continuity;
- (k) diagnose technical failures;
- (l) enforce account and Subscription permissions;
- (m) support region-specific routing;
- (n) record cookie choices where applicable; and
- (o) understand Service performance through permitted first-party technical measurements.
3.3Secure Code does not currently use advertising cookies or third-party marketing cookies within Zyloch.
3.4Secure Code does not currently use cookies to create advertising profiles, follow Users across unrelated websites, or deliver third-party behavioral advertising.
4. Strictly Necessary Cookies
4.1Strictly necessary cookies enable functions required for the Services to operate securely. Disabling them may prevent account access, authentication, repository management, Subscription administration, or other core functions.
4.2Strictly necessary cookies may support:
- (a) User login and logout;
- (b) signed session management;
- (c) account and workspace identification;
- (d) authentication through GitHub;
- (e) protection against Cross-Site Request Forgery;
- (f) security-event detection;
- (g) load balancing;
- (h) infrastructure routing;
- (i) fraud and abuse prevention;
- (j) enforcement of account permissions;
- (k) preservation of cookie or privacy choices; and
- (l) recovery from temporary technical interruptions.
4.3Secure Code may use a signed session or JSON Web Token cookie to confirm that a User has authenticated successfully and remains entitled to access the relevant organization or workspace.
4.4Security cookies may contain a random or encrypted identifier. Secure Code does not intentionally place repository source code, complete payment-card details, or readable passwords inside browser cookies.
4.5Strictly necessary cookies are generally used without consent where applicable law permits because the requested Services cannot be delivered securely without them.
5. Authentication and Session Cookies
5.1Authentication cookies allow Zyloch to recognize a signed-in User and associate the browser session with the correct account, tenant, organization, role, and permissions.
5.2Session cookies may be created after a User:
- (a) enters account credentials;
- (b) authenticates through GitHub;
- (c) accepts an invitation to a workspace;
- (d) completes a security verification; or
- (e) accesses an authenticated Service page.
5.3Session cookies may be configured with security attributes designed to reduce unauthorized access, including secure transmission, restricted script access, expiration controls, and cross-site restrictions.
5.4A session may end when the User signs out, closes the browser, remains inactive for a defined period, resets credentials, revokes authorization, or is logged out for security reasons.
5.5Secure Code may invalidate active sessions after suspected account compromise, material account changes, administrative action, or updates affecting authentication security.
6. Security Cookies
6.1Security cookies and related technologies may help identify suspicious login attempts, repeated authentication failures, unauthorized requests, automated abuse, or unusual account activity.
6.2Security systems may consider information such as:
- (a) IP address;
- (b) browser type;
- (c) device characteristics;
- (d) approximate region;
- (e) session identifier;
- (f) request timing;
- (g) authentication history;
- (h) security tokens; and
- (i) patterns indicating abuse or account compromise.
6.3Security-related information may be retained beyond the immediate browser session where reasonably necessary to investigate incidents, enforce access controls, protect Users, and maintain evidence of unlawful or unauthorized conduct.
7. Preference and Functional Technologies
7.1Secure Code may use limited preference technologies to remember selections required for efficient use of the Services.
7.2Such selections may include:
- (a) language;
- (b) time zone;
- (c) region;
- (d) dashboard display settings;
- (e) workspace selection;
- (f) accessibility preferences;
- (g) dismissed notifications; and
- (h) security or privacy choices.
7.3Preference technologies may be treated as strictly necessary where they preserve a choice specifically requested by the User. Optional preference cookies will be subject to consent where applicable law requires it.
7.4Deleting preference cookies may return the Services to default settings without deleting the underlying Zyloch account.
8. Analytics and Performance Technologies
8.1Secure Code may use custom, first-party product analytics or technical monitoring to understand whether the Services operate correctly.
8.2Permitted analytics may measure:
- (a) page and feature usage;
- (b) errors and failed requests;
- (c) application performance;
- (d) response times;
- (e) device or browser compatibility;
- (f) navigation within the Services;
- (g) aggregate Subscription or plan usage;
- (h) scan initiation and completion events; and
- (i) adoption of product features.
8.3Analytics information may be collected through server logs or other technologies that do not require a browser cookie.
8.4Where an analytics cookie is not strictly necessary, Secure Code will obtain consent before placing or accessing it where applicable law requires consent.
8.5Analytics information is not used by Secure Code for third-party advertising.
9. Error Tracking and Infrastructure Monitoring
9.1Secure Code may use service providers or internal systems for diagnostics, infrastructure monitoring, reliability, crash reporting, and error tracking.
9.2Such systems may process:
- (a) technical identifiers;
- (b) timestamps;
- (c) error messages;
- (d) application state;
- (e) browser and operating-system information;
- (f) IP address;
- (g) request paths;
- (h) performance measurements; and
- (i) limited account or workspace identifiers needed to investigate the error.
9.3Error-monitoring tools are configured to support Service reliability and security. Secure Code does not intend to transmit complete repository source code or unnecessary personal data to diagnostic providers.
9.4Certain technical identifiers may be stored through cookies, local storage, or server-side logs. Optional diagnostic cookies will be managed according to applicable consent requirements.
10. GitHub Authentication and Integration
10.1Zyloch allows Users to authenticate through GitHub and authorize the Zyloch GitHub App.
10.2During the authentication or authorization process, the browser may be redirected to a GitHub-controlled page. GitHub may place or access its own cookies according to its policies and account settings.
10.3Secure Code does not control cookies placed directly by GitHub on GitHub-operated domains.
10.4After authentication, Zyloch may use its own session cookie to maintain the User’s signed-in session. Removal of GitHub cookies does not necessarily remove the Zyloch session, and removal of the Zyloch session does not necessarily sign the User out of GitHub.
10.5Users may revoke the Zyloch GitHub App through the relevant GitHub account or organization settings. Revocation may prevent future repository access and scanning.
11. Payment Provider Cookies
11.1Subscription payments are processed through a third-party payment provider selected by Secure Code.
11.2A payment provider may use cookies and similar technologies for:
- (a) checkout operation;
- (b) fraud prevention;
- (c) payment authentication;
- (d) transaction security;
- (e) regulatory compliance;
- (f) remembering checkout details; and
- (g) processing refunds or recurring charges.
11.3Payment-provider cookies placed on a provider-controlled page or embedded payment interface are governed by that provider’s policies.
11.4Secure Code does not use payment-provider cookies for third-party advertising and does not store complete payment-card numbers or security codes in Zyloch cookies.
12. Cookie Duration
12.1Cookie duration depends on the function performed.
12.2Session Cookies: Session cookies generally expire when the User signs out, closes the browser, or reaches the applicable inactivity limit.
12.3Authentication Cookies: Authentication cookies may remain for the period required to maintain a secure login, subject to expiration, logout, revocation, or security invalidation.
12.4Security Cookies: Security cookies may remain for a limited period required to detect fraud, repeated abuse, or unauthorized access.
12.5Preference Cookies: Preference cookies may remain until the preference changes, the cookie expires, or the User deletes it.
12.6Consent Cookies: Cookies recording privacy choices may remain for a reasonable period so Secure Code does not repeatedly request the same selection.
12.7Secure Code may update cookie duration as security, authentication, infrastructure, or legal requirements change.
13. First-Party and Third-Party Cookies
13.1First-party cookies are placed through a Secure Code or Zyloch domain and are generally controlled by Secure Code.
13.2Third-party cookies are placed by another organization through a domain, interface, integration, or service controlled by that organization.
13.3Third-party services connected with the Services may include:
- (a) GitHub;
- (b) cloud-hosting and infrastructure providers;
- (c) database-hosting providers;
- (d) payment providers;
- (e) error-monitoring providers; and
- (f) vulnerability or SBOM intelligence services.
13.4Not every service provider uses browser cookies. Some providers process data only through servers, APIs, infrastructure logs, or other technical mechanisms.
13.5Secure Code may replace, add, or remove service providers as the Services develop. Any resulting material change to cookie practices will be reflected in an updated Cookie Policy or consent interface where required.
14. Cookie Choices
14.1Where optional cookies or similar technologies are used, Users may accept, reject, or withdraw consent at any time through the cookie banner or preference center provided by Secure Code. A persistent “Cookie Settings” link, or another equally accessible control, will remain available through the website or web application after the initial choice is made.
14.2Withdrawing consent does not affect the lawfulness of processing completed before withdrawal.
14.3Strictly necessary cookies cannot ordinarily be disabled through a Secure Code preference tool because doing so would prevent secure delivery of the requested Services.
14.4A User who does not wish to accept strictly necessary cookies should stop using the browser-based Services.
14.5Cookie choices may apply only to the browser and device on which they were made. A User may need to repeat the selection after:
- (a) changing browsers;
- (b) changing devices;
- (c) deleting cookies;
- (d) using private-browsing mode; or
- (e) resetting browser settings.
15. Opt-Out and Browser Controls
15.1Users may reject or withdraw consent for optional cookies through the Secure Code cookie banner or preference center. Browser controls provide an additional method for blocking or deleting cookies, but may apply only to the browser and device on which the settings are changed.
15.2Official instructions for major browsers are available at:
15.3Blocking or deleting cookies may remove saved preferences, end active sessions, or prevent login, GitHub authentication, workspace access, security verification, and Subscription management.
15.4Browser controls do not disable strictly necessary server-side processing, logs, APIs, or security systems that do not rely on browser cookies.
16. Do Not Track and Similar Signals
16.1Some browsers transmit “Do Not Track” signals. No uniform legal or technical standard currently requires websites to interpret every such signal in the same way.
16.2Secure Code does not use Zyloch cookies for cross-site behavioral advertising.
16.3Where applicable law requires recognition of a supported opt-out preference signal, Secure Code will process that signal for the browser or device from which it is received.
16.4An opt-out signal does not disable strictly necessary cookies required for authentication, security, fraud prevention, or delivery of the Services.
17. International Users
17.1Secure Code operates from the United States and provides the Services to customers in the Americas, Asia, and other supported markets.
17.2Cookie identifiers and related technical data may be processed in countries where Secure Code or its service providers operate.
17.3Secure Code will apply consent and transparency requirements required by applicable law, including requirements relating to non-essential cookies in the European Economic Area and the United Kingdom when the Services are offered in those markets.
17.4Regional cookie behavior may vary to comply with local requirements or reflect available infrastructure.
18. Data Associated with Cookies
18.1Cookie identifiers may be associated with:
- (a) account details;
- (b) organization or workspace membership;
- (c) User role;
- (d) IP address;
- (e) browser and device data;
- (f) timestamps;
- (g) authentication events;
- (h) Service activity;
- (i) security events; and
- (j) privacy choices.
18.2Secure Code processes cookie-related personal data according to its Privacy Policy.
18.3Customers may control personal data contained in their workspaces, repositories, and scan results. Cookie data used directly by Secure Code for account administration, billing, security, and Service operation is controlled by Secure Code subject to applicable law.
19. Security
19.1Secure Code uses reasonable administrative, technical, and organizational safeguards designed to protect cookie identifiers and related personal data.
19.2Safeguards may include encrypted communications, signed tokens, access restrictions, expiration controls, secure cookie attributes, monitoring, session invalidation, and incident-response procedures.
19.3Users must protect their devices, accounts, passwords, GitHub credentials, and active browser sessions.
19.4A User should sign out after using a shared device and promptly notify Secure Code after suspected unauthorized account access.
20. Changes to the Cookie Policy
20.1Secure Code may update the Cookie Policy to reflect changes in the Services, cookies, integrations, infrastructure, service providers, legal requirements, or security practices.
20.2Material changes will be communicated through the Services, by email, through a cookie interface, or by another reasonable method where required by law.
20.3The date stated at the beginning identifies the latest revision.
20.4Continued use of strictly necessary cookies after an update is governed by the revised Cookie Policy. New optional cookies will not be activated without consent where applicable law requires consent.
21. Contact
Questions, requests, or complaints concerning cookies and similar technologies may be directed to:
Secure Code LLC
417 Staunton Dr
Leander, Texas 78641
United States
Email: privacy@secure-code.dev