Secure Code LLC, located at 417 Staunton Dr, Leander, Texas 78641 (“Secure Code,” “we,” “us,” or “our”), operates Zyloch, a business-to-business Software-as-a-Service platform providing automated security and compliance scanning for software source-code repositories.
Zyloch includes its web application, API, GitHub App, scanning engine, dashboards, reports, Software Bills of Materials (“SBOMs”), and related services collectively referred to as the “Services.”
Secure Code processes personal data as a controller or business for account administration, billing, communications, security, and operation of the Services. Where Secure Code processes repository information or other personal data solely on behalf of a business customer, Secure Code ordinarily acts as that customer’s processor, service provider, or equivalent regulated entity.
1. Scope
1.1This Privacy Policy applies to personal data processed when an individual:
- (a) visits a Secure Code or Zyloch website;
- (b) creates or uses a Zyloch account;
- (c) joins a customer workspace or organization;
- (d) installs, authorizes, or interacts with the Zyloch GitHub App;
- (e) connects a repository or initiates a scan;
- (f) purchases or manages a Subscription;
- (g) uses the dashboard, API, support channels, or related features; or
- (h) otherwise communicates with Secure Code.
1.2A customer organization controls the personal data contained in repositories, workspace content, policy settings, and other information submitted for processing on its behalf. Requests concerning customer-controlled data may need to be directed to the relevant organization.
1.3Third-party websites, platforms, and services remain governed by their own privacy policies.
2. Personal Data We Collect
2.1Account and Identity Data
Secure Code may collect:
- (a) first name and last name;
- (b) username;
- (c) business email address;
- (d) authentication credentials;
- (e) GitHub identity and OAuth information;
- (f) organization, workspace, team, or employer details;
- (g) assigned role and permissions; and
- (h) account preferences and settings.
Passwords created directly through Zyloch are stored in hashed form. Secure Code does not retain readable copies of account passwords.
2.2Repository and Source-Control Data
When a customer connects GitHub or another supported source-control service, Secure Code may process:
- (a) repository and branch names;
- (b) repository identifiers and access permissions;
- (c) supported configuration files;
- (d) Docker, Kubernetes, and GitHub Actions configurations;
- (e) infrastructure-as-code and pipeline information;
- (f) commit identifiers;
- (g) commit messages;
- (h) commit author names, usernames, and email addresses;
- (i) webhook events;
- (j) repository installation and authorization information; and
- (k) scan status and processing records.
Zyloch temporarily clones supported repository content when required to perform a scan. Temporary clones are deleted after the applicable scan has completed. Findings, SBOMs, policy results, and limited repository or commit metadata may remain available to the customer according to its account settings and applicable retention periods.
2.3Scan and Security Data
Secure Code may process or generate:
- (a) security Findings;
- (b) policy violations;
- (c) configuration issues;
- (d) vulnerability references;
- (e) compliance-related results;
- (f) SBOMs;
- (g) risk classifications and remediation information;
- (h) scan histories and timestamps;
- (i) customer-created policies; and
- (j) comments or annotations relating to Findings.
Automated results may be linked to repository content, commits, or individual contributors where that information is available through the connected source-control service.
2.4Subscription and Transaction Data
Secure Code may collect:
- (a) selected plan and billing interval;
- (b) Subscription status;
- (c) trial, renewal, cancellation, and payment dates;
- (d) billing contact information;
- (e) transaction identifiers;
- (f) invoices and payment status; and
- (g) limited payment-method details supplied by the payment processor, such as card type and final digits.
Payments are handled by a third-party payment processor identified during checkout. Secure Code does not store complete payment-card numbers or card-security codes.
2.5Device, Usage, and Technical Data
Secure Code may collect:
- (a) IP address;
- (b) browser and device type;
- (c) operating system;
- (d) language and time-zone settings;
- (e) session identifiers;
- (f) authentication and security events;
- (g) API requests;
- (h) pages, features, and controls used;
- (i) scan frequency and Service activity;
- (j) timestamps and referring pages;
- (k) diagnostic, crash, and error information; and
- (l) network, infrastructure, and performance logs.
2.6Communications
Secure Code may retain support requests, feedback, workspace names, comments, annotations, emails, and other communications submitted through the Services.
2.7Sensitive Personal Data
Zyloch is not designed to collect health information, government identification numbers, complete payment-card data, biometric information, or other sensitive personal data unrelated to developer-security operations.
Customers must not submit sensitive personal data unless the Services expressly support it and Secure Code has agreed to the processing in writing.
3. Sources of Personal Data
3.1Secure Code may obtain personal data:
- (a) directly from Users;
- (b) from a customer organization or workspace administrator;
- (c) from GitHub and other authorized integrations;
- (d) from repositories and configuration files submitted for scanning;
- (e) automatically through devices, cookies, logs, APIs, and security systems;
- (f) from payment and infrastructure providers; and
- (g) from Users who invite colleagues or configure team access.
3.2Customer organizations are responsible for ensuring that they have authority to provide personal data to Secure Code and that required notices have been given to affected individuals.
4. Purposes of Processing
Secure Code may process personal data to:
- 4.1 create, authenticate, and administer accounts;
- 4.2 establish organizations, workspaces, roles, and permissions;
- 4.3 connect repositories and process authorized webhooks;
- 4.4 perform scans and generate Findings, reports, and SBOMs;
- 4.5 operate, maintain, troubleshoot, and secure the Services;
- 4.6 enforce plan entitlements, repository limits, and usage limits;
- 4.7 process Subscriptions, payments, renewals, and cancellations;
- 4.8 provide customer support and respond to inquiries;
- 4.9 detect fraud, abuse, account compromise, and unauthorized activity;
- 4.10 analyze performance and understand product usage;
- 4.11 develop, test, and improve Service features using account, technical, usage, aggregated, or de-identified information, but not use customer repository content for independent product-development purposes except on documented customer instructions or with the customer’s express written authorization;
- 4.12 send operational, security, billing, and account communications;
- 4.13 send marketing communications where permitted by law or consented to by the recipient;
- 4.14 comply with legal obligations and lawful requests;
- 4.15 establish, exercise, or defend legal claims; and
- 4.16 protect Secure Code, its customers, Users, systems, and third parties.
Secure Code does not use customer repository content to advertise third-party products to Users.
5. Legal Bases for EEA and UK Processing
Where the General Data Protection Regulation or UK data-protection law applies, Secure Code relies on one or more of the following legal bases:
5.1Contract: Processing required to create an account, provide the Services, perform scans, administer a Subscription, or respond to Service requests.
5.2Legitimate Interests: Processing required to secure, administer, analyze, support, and improve the Services; prevent misuse; communicate with business Users; and protect legal rights, provided those interests are not overridden by the individual’s rights.
5.3Legal Obligation: Processing required for taxation, accounting, compliance, law-enforcement cooperation, dispute management, or another binding legal duty.
5.4Consent: Processing based on consent where required, including certain optional cookies or marketing communications. Consent may be withdrawn at any time without affecting processing completed before withdrawal.
6. Customer-Controlled Processing
6.1Secure Code acts on a customer’s instructions when processing repository data, contributor information, configuration files, policy settings, scan content, and related personal data submitted through that customer’s workspace.
6.2The customer determines which repositories are connected, who may access the workspace, which scans are performed, and how generated results are used.
6.3Secure Code may process customer-controlled data beyond documented instructions where required by applicable law. Where legally permitted, the affected customer will be notified before such processing.
6.4Additional data-processing terms may apply where required by law or agreed through an order form or Data Processing Agreement.
7. Disclosure of Personal Data
Secure Code may disclose personal data to:
7.1Customer Organizations
Workspace administrators and other authorized Users may access account details, repository information, scan results, roles, activity, comments, and related workspace data according to assigned permissions.
7.2Service Providers
Personal data may be processed by providers supporting:
- (a) Microsoft Azure cloud hosting and infrastructure;
- (b) Google Cloud Platform hosting and infrastructure;
- (c) MongoDB Atlas database hosting;
- (d) GitHub integration, authentication, and repository access;
- (e) payment processing;
- (f) error tracking, diagnostics, and infrastructure monitoring;
- (g) email delivery and customer support; and
- (h) vulnerability or SBOM intelligence.
Service providers receive only the access reasonably required for their assigned functions and are subject to contractual or legal obligations governing their processing.
7.3Professional Advisers
Secure Code may disclose information to lawyers, accountants, auditors, insurers, consultants, and financial institutions where reasonably necessary.
7.4Legal and Safety Disclosures
Secure Code may disclose personal data where reasonably believed necessary to comply with law, legal process, court orders, regulatory requests, or enforceable governmental demands, or to protect rights, safety, systems, and property.
7.5Corporate Transactions
Personal data may be disclosed in connection with financing, due diligence, merger, acquisition, restructuring, insolvency, or sale of all or part of Secure Code’s business or assets. Recipients must use the information consistently with applicable law.
8. Sale and Targeted Advertising
8.1Secure Code does not sell personal data or personal information for monetary or other valuable consideration, as “sell” is defined by applicable privacy law.
8.2Secure Code does not use personal data for third-party cross-context behavioral advertising or targeted advertising.
8.3Secure Code does not use advertising or third-party marketing cookies within Zyloch.
8.4Where future practices constitute a sale, sharing, or targeted advertising under applicable law, Secure Code will provide required disclosures and opt-out methods before beginning that processing.
9. Cookies and Similar Technologies
9.1Zyloch uses cookies and similar technologies required for:
- (a) authentication and signed sessions;
- (b) JSON Web Token session management;
- (c) security and fraud prevention;
- (d) Cross-Site Request Forgery protection;
- (e) load balancing and infrastructure operation; and
- (f) User preferences and essential functionality.
9.2Secure Code may collect product-usage information through its own analytics systems.
9.3Non-essential cookies will be subject to consent where required by law. Additional information appears in Secure Code’s Cookie Policy.
10. Data Retention
10.1Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, including Service delivery, security, legal compliance, dispute resolution, and enforcement of agreements.
10.2Temporary repository clones are deleted after the applicable scan has completed.
10.3Customers may export available data using Zyloch’s download functionality.
10.4If the customer selected post-cancellation retention during installation or account configuration, account data, repository metadata, scan results, support communications, and related customer data may remain available for up to 15 days after cancellation and will then be deleted from active systems, subject to clauses 10.6 and 10.7. If the customer did not select post-cancellation retention, Secure Code will begin deleting such data from active systems promptly after cancellation, subject to clauses 10.6 and 10.7.
10.5Data may be deleted sooner at the customer’s request where no legal, security, or contractual reason requires continued retention.
10.6Transaction, tax, accounting, security, fraud-prevention, and dispute records may be retained for the period required or permitted by law.
10.7Residual copies may remain in protected backups for no longer than 15 days after account cancellation, after which they will be deleted or overwritten, unless a longer period is required by applicable law. Backup data is not used for ordinary business purposes and will not be restored after the applicable deletion deadline except where required by law.
11. International and Regional Processing
11.1Secure Code is established in the United States and provides Services to customers in the Americas, Asia, and other supported regions.
11.2Customer data is maintained according to available regional storage arrangements and the customer’s selected configuration, plan, or written order.
11.3Personal data may be accessed or processed in countries other than the individual’s country of residence where Secure Code, its personnel, or its service providers operate.
11.4Where EEA, Swiss, or UK personal data is transferred to a country without an applicable adequacy decision, Secure Code will use a recognized transfer mechanism where required, including approved standard contractual clauses or another lawful safeguard.
12. Security
12.1Secure Code maintains administrative, technical, and organizational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, or access.
12.2Safeguards may include tenant-level data separation, role-based access, encrypted communications, hashed passwords, authentication controls, logging, monitoring, restricted administrative access, and incident-response procedures.
12.3No system can provide absolute security. Users must protect passwords, access tokens, API credentials, GitHub permissions, devices, and administrator accounts and must promptly report suspected unauthorized access.
13. Privacy Rights
13.1Depending on applicable law, an individual may have the right to:
- (a) confirm whether personal data is being processed;
- (b) access personal data;
- (c) correct inaccurate personal data;
- (d) request deletion;
- (e) obtain a portable copy;
- (f) restrict or object to certain processing;
- (g) withdraw consent;
- (h) opt out of qualifying sale, targeted advertising, or profiling;
- (i) appeal the denial of a privacy request; and
- (j) complain to a competent supervisory or regulatory authority.
13.2Rights are subject to legal conditions, exceptions, identity-verification requirements, and Secure Code’s role in the processing.
13.3Where data is controlled by a customer organization, Secure Code may refer the request to that organization or assist it in responding.
13.4Requests may be sent to privacy@secure-code.dev. Secure Code may request information reasonably necessary to confirm identity, authority, account ownership, or the data concerned. 13.5Authorized agents may submit requests where permitted by law. Secure Code may require proof of authorization and may verify the individual’s identity directly.
13.6Secure Code will not unlawfully discriminate against an individual for exercising a privacy right.
14. United States Privacy Rights
14.1Residents of a U.S. state with an applicable comprehensive privacy law may exercise the rights granted under that law.
14.2Texas law may provide eligible consumers with rights to access, correct, delete, and obtain portable copies of personal data, opt out of certain processing, and appeal a denied request. Statutory exclusions may apply to individuals acting in a commercial or employment context.
14.3Where the California Consumer Privacy Act applies to Secure Code, California residents may request information about applicable categories of personal information, sources, purposes, recipients, and disclosures, and may exercise access, correction, deletion, and opt-out rights subject to statutory exceptions.
14.4If the California Consumer Privacy Act applies to Secure Code, the categories of personal information collected during the preceding 12 months are described in Sections 2 and 3, the applicable business or commercial purposes are described in Section 4, and the categories of recipients are described in Section 7. Secure Code does not sell or share personal information as those terms are defined by the California Consumer Privacy Act.
15. EEA, Swiss, and UK Rights
15.1Where applicable, individuals may exercise rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
15.2An individual has the right to object at any time to personal-data processing based on legitimate interests, including profiling based on those interests. Secure Code will stop the processing unless compelling legitimate grounds or legal claims justify its continuation.
15.3An individual may object at any time to processing for direct-marketing purposes. Personal data will no longer be processed for that purpose after a valid objection.
15.4Complaints may be submitted to the data-protection authority in the individual’s place of residence, place of work, or location of the alleged infringement. GDPR and UK GDPR rights remain subject to applicable conditions and exceptions.
15.5Where legally required because Secure Code offers Services to individuals in the EEA or UK, the identity and contact information of any appointed representative will be published in an updated version of this Privacy Policy.
16. Automated Processing
16.1Zyloch automatically evaluates supported configurations and repository materials to identify potential security, compliance, vulnerability, and policy issues.
16.2Findings may be ranked or categorized using automated rules. Customers decide whether to rely on, investigate, remediate, or otherwise act upon a Finding.
16.3Secure Code does not use automated processing to make decisions producing legal or similarly significant effects concerning individual Users.
17. Children
17.1The Services are intended exclusively for individuals aged 18 or older and for business use.
17.2Secure Code does not knowingly collect personal data directly from children. Suspected collection involving a child may be reported to privacy@secure-code.dev. 18. Communications
18.1Secure Code may send account, billing, security, maintenance, support, and Subscription communications required to provide the Services.
18.2Marketing communications may be discontinued through the unsubscribe method included in the message or by contacting Secure Code.
18.3Opting out of marketing does not prevent delivery of essential Service communications.
19. Changes to the Privacy Policy
19.1Secure Code may update the Privacy Policy to reflect changes in the Services, processing activities, service providers, legal requirements, or security practices.
19.2Material changes will be communicated through the Services, by email, or through another reasonable method before taking effect where required by law.
19.3The date displayed at the beginning identifies the latest revision.
20. Contact
Privacy requests, questions, and complaints may be directed to:
Secure Code LLC
417 Staunton Dr
Leander, Texas 78641
United States
Email: privacy@secure-code.dev