Security
Privacy and secrets
What data leaves the browser, where it goes, and where keys live.
| Data | Where it goes |
|---|---|
| Advisory text | Sent to SERV Reasoning to compile a checklist |
| Checklist and one verdict | Sent to SERV Reasoning when you write a client note |
| Repository link | Used by the server to read public files from GitHub |
| SERV_API_KEY | Server environment only, never sent to the browser |
Pich has no accounts and no database. It does not store advisories, results, or notes; repository files are cached in memory for up to 5 minutes.
Warning
Do not paste confidential material into the advisory box. It is sent to SERV Reasoning.
Reporting a vulnerability
Report privately through GitHub Security Advisories on the repository. See SECURITY.md.