Security & Compliance

Your data, our posture

EnvLens processes the inputs you submit for analysis. This page states, plainly, what we handle and what we do not claim.

What we handle

config snippets (.env / yaml / toml) you paste for secret and insecure-setting scanning. Secrets should be rotated if real values are pasted.

Data handling commitments

  • Submissions run the product pipeline and are retained only as long as needed for your audit log (paid tiers) or until you delete the run.
  • We apply access controls consistent with GDPR Art. 32 (security of processing) where personal data is processed.
  • BYOK keys (Enterprise), when offered, are stored server-side only and never exposed to the browser.
Honesty rule: EnvLens helps find likely leaked secrets and bad settings. We do not guarantee finding every secret, 100% config safety, or that you will never miss a leak. Do not paste production secrets into untrusted tools. We do not claim guarantee / 100% / never miss.

Our compliance posture

  • EnvLens is decision-support, not a law firm, clinic, or certified auditor.
  • For binding advice, consult a qualified professional in the relevant domain.

Subprocessors & payments

  • Payments are processed by Waffo Pancake (merchant of record).
  • See Privacy and Terms for full terms.

refs: OWASP Secrets Management Cheat Sheet · CWE-798 Use of Hard-coded Credentials · OWASP Top 10 A07 Identification and Authentication Failures