Trust

Data handling

See Security for how access and tenancy are protected. This page is about what data exists and how to remove it.

What Wirecheck reads

When you connect a repository, Wirecheck fetches supported file contents (source files, configs, lockfiles, READMEs, not binaries or build output) into worker memory for a single scan pass. It reads to find credentials, MCP/integration configuration, agent and SDK usage, webhooks, scheduled jobs, and other dependency signals described in Supported detections.

What Wirecheck stores

  • Repository identity and file paths
  • File blob hashes and line numbers (so evidence can point to a specific line)
  • Detected nodes and edges (agents, credentials, MCP servers, integrations) and their confidence
  • Evidence labels: e.g. a masked credential identifier or a matched import, never a secret value
  • Saved impact analyses, reports, scan history, and feedback you submit
  • Optional AI-generated summaries of evidence the deterministic scan already found

What Wirecheck does not store

  • Credential or secret values: only variable names and masked identifiers
  • Full repository source, by default; structured evidence is extracted, then the raw fetched content is discarded rather than persisted indefinitely
  • GitHub installation tokens as repository content; they are requested from GitHub when needed, not stored in the product database

Why this data is required

Answering “what breaks if I revoke this?” requires knowing which file, line, and confidence level a relationship came from; that is the entire trust model (see provenance over confidence). Without storing evidence locations, Wirecheck could only show a claim, not a reason to believe it.

How to disconnect a repository

Disconnect a single repository from its own page in the dashboard. This deletes that repository, its scans, and its graph evidence. A node or credential still referenced by another connected repository is kept, scoped to that other repository, rather than deleted out from under it.

How to delete your organization's scanned data

Settings → Delete scanned data permanently deletes repositories, scans, graph findings, impact analyses, reports, and feedback for your organization. Your account and billing settings stay intact; this is a data wipe, not an account deletion.