Keelix — Official Document
Privacy Policy
Last updated: June 1, 2026
Draft — pending legal review.
What we collect
For the hosted dashboard we store: your email and authentication identifiers, your organization and team membership, the hosts you register, and the structured results of each scan (scores, findings, control mappings, target hostnames, and timestamps). We also keep billing metadata via our payment processor and an audit trail of account actions.
What we do NOT collect
Your raw docker-compose.yml and .env file contents are NOT stored by Keelix Cloud. Scanning runs on your own machine (the CLI or your self-hosted worker); only the resulting structured findings, scores, target hostnames, and metadata are uploaded to the dashboard. Secret values detected by a check are reported by location/name, never by uploading the secret value itself.
How scoring works (and the role of AI)
Scoring and pass/fail are produced by deterministic checks. The optional AI layer only rewrites explanations and drafts remediations — it never changes a score or a check result.
AI enrichment is opt-in. When enabled, the text of individual findings (and a stack summary) is sent to Anthropic to generate plain-English explanations and remediation drafts. With no AI key configured, no finding data is ever sent to Anthropic. The deterministic results are identical with or without AI.
Data retention by plan
- free: 30 days
- pro: 365 days
- team: 730 days (2 years)
- enterprise: Custom (set by contract)
Scan history older than your plan's retention window is automatically pruned.
Your GDPR rights (export & erasure)
You can export all of your organization's data as JSON from Settings, and an organization owner can request erasure (soft-delete with a 30-day hard-erase). These cover GDPR access, portability, and erasure rights.
Self-service export and deletion live in Settings → Danger Zone.
Subprocessors
We share data with the following processors strictly to operate the service:
- Supabase — Database, authentication, and storage for the hosted dashboard.
- Vercel — Application hosting, edge network, and serverless functions.
- Stripe — Payment processing and subscription billing.
- Resend — Transactional and alert email delivery.
- WorkOS — Enterprise SSO/SCIM (only when an org enables SSO — private preview).
- Anthropic — AI explanation/remediation enrichment (only when AI enrichment is enabled).
Security contact
Report a vulnerability or ask a security question: info@keelix.dev.