Skip to main content

Core principle: scan locally, share minimally

ZenVeil is designed so that the most sensitive operation — scanning your source code — happens entirely on your machine. Your code never touches our servers during a local scan.

What we collect

When you use the CLI locally

When you use the dashboard or API

When you use AI features

When you call explain, fix, or triage: Anthropic’s and Google’s data retention policies apply to these requests. See:

Data storage

All ZenVeil data is stored in:
  • MongoDB Atlas — hosted in AWS US-East-1, encrypted at rest and in transit (TLS 1.2+)
  • Stripe — for billing data. ZenVeil stores only customerId and subscriptionId, not card details

Data deletion

Deleting your account removes:
  • Your user record
  • All API keys
  • All scan history stored on our servers
  • Your subscription (effective at period end)
To request account deletion: email privacy@zenveil.dev. Deleting local data:

GDPR / CCPA compliance

ZenVeil complies with GDPR and CCPA:
  • Right to access: request a copy of your data at privacy@zenveil.dev
  • Right to deletion: request deletion at privacy@zenveil.dev
  • Right to portability: your scan history can be exported as JSON from the dashboard
  • Data minimization: we collect only what’s necessary to operate the service

Third-party services