Buyer-readable data handling
Where product data goes—and where it does not.
This page translates Guard's published data-processing artifact into plain language. The source artifact remains available as JSON.
Roles and service scope
The customer is the controller or primary data owner for repository, pull-request, reviewer, and approval data. The Guard operator acts as a processor or service provider for report support, subscription verification, and service operations.
Public repositories are free while available. Guard Pro covers up to five selected private repositories and 500 Guard runs per billing month under one GitHub account while its subscription is active.
Data categories
- Repository and pull-request URLs, numbers, titles, author metadata, and changed paths.
- Owner-routing metadata, test identifiers, scanner and dependency summaries, policy status, blockers, unknowns, and reviewer feedback.
- Business contact details submitted through intake, feedback, approval, scheduling, or payment handoff flows.
- Stripe subscription metadata needed to verify Guard Pro access.
Default storage boundary
| Data | Default location |
|---|---|
| Customer source code | Remains in the customer's repository by default. |
| Guard reports | Customer-controlled workflow artifacts or pull-request comments unless another sink is explicitly configured. |
| Operational ledgers | Optional private operator repositories or signed internal systems when configured. |
| Public samples | Must not include customer source, secrets, approval evidence, or live revenue evidence. |
External services
| Service | Purpose | Required |
|---|---|---|
| GitHub Actions | Run Guard in the customer repository. | Yes |
| Stripe | Checkout and payment webhook verification. | Only when card checkout is enabled |
| GitHub Contents API | Optional private operational ledgers. | No |
| Configured webhooks or CRM | Optional signed business handoff notifications. | No |
| Customer-selected scanners | Security and dependency evidence. | No |
Retention and deletion
Operator-controlled records are intended to be kept only as long as needed for service operation, accounting, fraud prevention, dispute handling, or a written legal obligation. Customers control deletion of artifacts and comments in their own repositories. On written request, operator-controlled lead, feedback, approval, and revenue artifacts may be deleted or redacted unless continued retention is required for those purposes.
Customer controls
- Disable pull-request comments and use workflow artifacts only.
- Omit optional operational ledgers and webhooks.
- Disable scanner integrations while preserving the resulting unknowns.
- Uninstall the workflow and revoke App access.
- Request deletion or redaction of operator-controlled service artifacts.
Next step for review
Review the trust center, security review source, and privacy notice. Use the support route shown in the GitHub App listing or your existing commercial correspondence for a data request.