Pich logoPichdocs
Docs menu: Privacy and secrets

Security

Privacy and secrets

What data leaves the browser, where it goes, and where keys live.

DataWhere it goes
Advisory textSent to SERV Reasoning to compile a checklist
Checklist and one verdictSent to SERV Reasoning when you write a client note
Repository linkUsed by the server to read public files from GitHub
SERV_API_KEYServer environment only, never sent to the browser

Pich has no accounts and no database. It does not store advisories, results, or notes; repository files are cached in memory for up to 5 minutes.

Warning

Do not paste confidential material into the advisory box. It is sent to SERV Reasoning.

Reporting a vulnerability

Report privately through GitHub Security Advisories on the repository. See SECURITY.md.

Edit this page on GitHub