Product policy
Privacy
Original workflow JSON is processed by the Auturance server for static analysis and is not persisted. It is not a browser-only scanner.
What we do not store from a scan
- The original workflow JSON.
- Node parameters, prompts, API request bodies, or detected secret values.
- Credential values.
What we may store
- An anonymous visitor identifier and product usage events.
- Scan summary metadata such as score, node count, rule IDs, severity, and affected-node counts.
- Waitlist email addresses that users submit voluntarily.
- Feedback text, feedback category, rule ID/scan ID when relevant, and an optional contact email supplied with feedback.
Anonymous product analytics
When analytics is enabled, Auturance uses Umami to measure anonymous page visits, referrer/UTM campaign information, and allow-listed product event names such as scan completion, report export, roadmap requests, or contact-page visits.
- We do not send workflow JSON, workflow names, node parameters, prompts, credential values, feedback text, Auturance visitor IDs, scan IDs, rule IDs, or affected-node details to Umami.
- Session replay is not enabled as part of this integration.
Security findings report parameter paths and rule IDs, not the secret-like values themselves. Do not intentionally upload data you are not authorized to process.