Core principle: scan locally, share minimally
ZenVeil is designed so that the most sensitive operation — scanning your source code — happens entirely on your machine. Your code never touches our servers during a local scan.What we collect
When you use the CLI locally
When you use the dashboard or API
When you use AI features
When you callexplain, fix, or triage:
Anthropic’s and Google’s data retention policies apply to these requests. See:
Data storage
All ZenVeil data is stored in:- MongoDB Atlas — hosted in AWS US-East-1, encrypted at rest and in transit (TLS 1.2+)
- Stripe — for billing data. ZenVeil stores only
customerIdandsubscriptionId, not card details
Data deletion
Deleting your account removes:- Your user record
- All API keys
- All scan history stored on our servers
- Your subscription (effective at period end)
privacy@zenveil.dev.
Deleting local data:
GDPR / CCPA compliance
ZenVeil complies with GDPR and CCPA:- Right to access: request a copy of your data at
privacy@zenveil.dev - Right to deletion: request deletion at
privacy@zenveil.dev - Right to portability: your scan history can be exported as JSON from the dashboard
- Data minimization: we collect only what’s necessary to operate the service