Skip to content

Security

Trust model for vasdra — local scan, evidence-linked findings, minimal data retention.

Local-first scan

npx vasdra scan runs entirely on your machine. No network calls. No API keys sent to vasdra during a free scan.

GitHub App permissions

Watch mode uses the vasdra GitHub App with least-privilege scopes needed to read manifests, run checks, and open remediation PRs you approve.

Evidence integrity

Findings link to real files and detector ids. We do not generate impact via LLM guesswork. AI may explain or draft patches later — always from canonical evidence.

Reporting

Security issues: security@vasdra.com (placeholder). We aim to acknowledge reports within 48 hours.