Trust and security
Last reviewed: 28 September 2026. Written for whoever does vendor review. The binding texts are the privacy policy and the terms; where this page and they differ, they win.
1. Where your code goes
| Question | Answer |
|---|---|
| Where is my code read? | On one dedicated server run by Hetzner Online GmbH in Finland (European Union). Nowhere else. |
| Does any AI model see it? | No. The checks are deterministic. Your code is never sent to an AI model, and an automated test blocks our deployment if any part of the service is wired to one. |
| What leaves the server? | Package names — and, for the advisory check, the pinned
version — to pypi.org and registry.npmjs.org; to their download
counters, api.npmjs.org and, only for Python packages under 90 days old,
pypistats.org; and to api.github.com.
That list is the whole list. |
| What do you write to disk? | Installation ID, organisation, repository name, pull request number, risk level, counts and billing data. Never your source code and never the value of a secret we detect. |
| And the report linked from the pull request? | Held in memory only, for up to seven days, and lost if the service restarts. It includes the flagged lines so the person reading it can see them. |
| What happens when I uninstall? | Access ends immediately, and the stored data about your organisation is deleted automatically. If you were on a paid plan we keep only the link to your Stripe customer, anonymised, so a subscription can be cancelled or refunded cleanly. |
The complete list of organisations that process data for us — hosting, payments, email, this website — and exactly what each one receives is in section 3 of the privacy policy.
2. What we do not have
- No SOC 2 and no ISO 27001. We have not been audited against either.
- No uptime commitment. One server, one person. If the service is down, the check does not run. If you made it a required check, GitHub waits for it; repository admins can merge anyway or remove the requirement.
- No logic review. We match patterns. A reviewer that understands your code will find flaws we cannot — our own benchmark shows one.
If your vendor review requires any of these, we are not the right vendor for you yet, and we would rather you knew now than after a trial. We will start a certification when a paying customer's review requires one, and we will say so on this page when we do.
3. How the service is run
- Every webhook from GitHub is verified with HMAC-SHA256 before anything is processed.
- The server is reached by SSH key only — the administrator account refuses passwords and every other account is locked — behind a firewall that denies incoming traffic by default.
- Dependencies are pinned and watched by Dependabot; on 27 September 2026 there were no open alerts.
- A deployment is refused unless more than 1,200 automated tests pass, and unless every figure and promise we publish still matches what the code does.
- When we detect a credential we report where it is. We never test whether it works, and we never store or print its value.
4. How often we are wrong
Every false positive we have fixed is pinned by a regression test built from the exact line we got wrong, in a real public repository, with the pull request cited. The record is public →
5. If something goes wrong
If a personal data breach occurs we notify the supervisory authority within 72 hours, as Article 33 GDPR requires, and affected organisations without undue delay. If you find a vulnerability in our service, write to contact@magsolutionsai.com with the subject “Security” and please do not open a public issue.
6. Who is behind it
MagSolutionsAI is built and run by one person in Spain, under Spanish law. The service went live in July 2026 and has no paying customers yet; we will not show logos or testimonials until there are real ones.