Last updated: September 10, 2026
ShipSafe CLI: Source-code pattern and secret analysis runs on your machine. Dependency advisory checks contact the npm registry and can send package names and versions. Optional monitoring, source-map uploads, and license activation use network services when configured.
@shipsafe/monitor: If you install the optional monitoring snippet, it sends error reports and performance metrics to our API. All data goes through automatic PII scrubbing before transmission — emails, credit card numbers, social security numbers, phone numbers, and IP addresses are stripped. You can add a beforeSend hook to filter or block any event.
shipsafe.org: This website uses Vercel hosting, Web Analytics, and Speed Insights to measure visits and performance. The web scanner receives pasted text or downloads a public GitHub repository for server-side analysis. It does not execute the submitted code. Use the local CLI for confidential source code or secrets.
Monitoring data is used solely to display error reports and performance metrics in your ShipSafe dashboard. We do not sell, share, or use your data for advertising. We do not train AI models on your data.
The monitoring API stores error reports and source maps for the configured deployment. Transport and storage protections depend on that deployment; use HTTPS for remote endpoints and restrict access to monitoring data and source maps.
Web scanner files are created in a temporary directory and removed after the request finishes, including when a scan fails. We do not intentionally log submitted source code or scan findings. Hosting infrastructure may retain ordinary operational request logs.
Error data is retained for 30 days by default. Performance metrics are retained for 7 days. Source maps are retained for 90 days. You can request deletion of all your data at any time by emailing privacy@shipsafe.org.
Vercel provides website hosting and site analytics. GitHub provides public repository downloads, and npm provides dependency advisory information. Optional monitoring data is sent to the configured API endpoint. These services process the data necessary to provide their features.
You can request access to, correction of, or deletion of your data at any time. Contact privacy@shipsafe.org. We respond within 30 days.
Questions? Email privacy@shipsafe.org.