Prasovi Privacy Policy
Last updated: September 5, 2026
1. Who We Are
Prasovi ("we", "us", "our") is a security scanning platform that helps you find vulnerabilities in your code repositories and audit your cloud infrastructure for misconfigurations.
2. Information We Collect
Account information: When you sign up, we collect your name, email address, and password (stored as a secure hash, never in plain text). You may optionally provide your mobile number, company name, and address.
Provider credentials: To scan your repositories and cloud accounts, you provide access tokens/credentials for GitLab, GitHub, Azure DevOps, Azure, and/or AWS. These are encrypted at rest using industry-standard encryption before being stored, and are only decrypted momentarily when actively performing a scan you requested.
Scan data: We store the results of scans you run — findings such as detected secrets, code vulnerabilities, dependency issues, and infrastructure misconfigurations — along with metadata like which repository/account was scanned and when.
Payment information: Payments are processed by Razorpay, our third-party payment processor. We do not store your full card or bank details — Razorpay handles this directly under their own security and compliance standards (PCI-DSS). We retain only subscription status, plan, and billing period information.
Usage data: We log login attempts (for security, e.g. detecting brute-force attempts), scan history, and basic technical information like IP address and browser type for operational and security purposes.
3. How We Use Your Information
- To provide the scanning service you've signed up for
- To authenticate you and secure your account
- To process payments and manage your subscription
- To send you transactional emails (password resets, billing confirmations) via our email provider, Resend
- To detect and prevent abuse (e.g. login lockouts after repeated failed attempts)
- To improve and maintain the platform
We do not sell your personal information to third parties. We do not use your code, scan results, or credentials for any purpose other than providing the service to you.
4. Third-Party Services We Use
- GitLab, GitHub, Azure DevOps, Azure, AWS — to access repositories and cloud resources you explicitly connect, using credentials you provide
- Razorpay — payment processing
- Resend — transactional email delivery
- Render — application hosting infrastructure
- PostgreSQL (hosted on Render) — database storage
Each of these providers has its own privacy policy governing how they handle data on their end.
5. Data Retention
We retain your account and scan data for as long as your account is active. If you delete your account, we permanently delete your profile, connected provider credentials, scan history, and findings from our systems. This action cannot be undone.
6. Your Rights
You can access, update, or delete your account information at any time through your account settings. You can disconnect any provider integration (GitLab, GitHub, etc.) at any time, which removes the stored credential. You can request a copy of your data or ask questions about our data practices by contacting us at [email protected].
7. Security
We use encryption for sensitive data at rest (including provider credentials), secure password hashing, brute-force login protection, and access controls to protect your information. However, no system is completely secure, and we cannot guarantee absolute security.
8. Cookies
We use a session cookie to keep you logged in. We do not use advertising or tracking cookies.
9. Children's Privacy
Prasovi is not directed at individuals under 18. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this policy from time to time. We'll update the "Last updated" date above when we do. Continued use of Prasovi after changes means you accept the updated policy.
11. Contact Us
Questions about this policy? Contact us at [email protected].
← Back to home