Trust and security

Last reviewed: 28 September 2026. Written for whoever does vendor review. The binding texts are the privacy policy and the terms; where this page and they differ, they win.

1. Where your code goes

QuestionAnswer
Where is my code read?On one dedicated server run by Hetzner Online GmbH in Finland (European Union). Nowhere else.
Does any AI model see it?No. The checks are deterministic. Your code is never sent to an AI model, and an automated test blocks our deployment if any part of the service is wired to one.
What leaves the server?Package names — and, for the advisory check, the pinned version — to pypi.org and registry.npmjs.org; to their download counters, api.npmjs.org and, only for Python packages under 90 days old, pypistats.org; and to api.github.com. That list is the whole list.
What do you write to disk?Installation ID, organisation, repository name, pull request number, risk level, counts and billing data. Never your source code and never the value of a secret we detect.
And the report linked from the pull request?Held in memory only, for up to seven days, and lost if the service restarts. It includes the flagged lines so the person reading it can see them.
What happens when I uninstall?Access ends immediately, and the stored data about your organisation is deleted automatically. If you were on a paid plan we keep only the link to your Stripe customer, anonymised, so a subscription can be cancelled or refunded cleanly.

The complete list of organisations that process data for us — hosting, payments, email, this website — and exactly what each one receives is in section 3 of the privacy policy.

2. What we do not have

If your vendor review requires any of these, we are not the right vendor for you yet, and we would rather you knew now than after a trial. We will start a certification when a paying customer's review requires one, and we will say so on this page when we do.

3. How the service is run

4. How often we are wrong

Every false positive we have fixed is pinned by a regression test built from the exact line we got wrong, in a real public repository, with the pull request cited. The record is public →

5. If something goes wrong

If a personal data breach occurs we notify the supervisory authority within 72 hours, as Article 33 GDPR requires, and affected organisations without undue delay. If you find a vulnerability in our service, write to contact@magsolutionsai.com with the subject “Security” and please do not open a public issue.

6. Who is behind it

MagSolutionsAI is built and run by one person in Spain, under Spanish law. The service went live in July 2026 and has no paying customers yet; we will not show logos or testimonials until there are real ones.

Install on GitHub →