Security
Trust model for vasdra — local scan, evidence-linked findings, minimal data retention.
Local-first scan
npx vasdra scan runs entirely on your machine. No network calls. No API keys sent to vasdra during a free scan.
GitHub App permissions
Watch mode uses the vasdra GitHub App with least-privilege scopes needed to read manifests, run checks, and open remediation PRs you approve.
Evidence integrity
Findings link to real files and detector ids. We do not generate impact via LLM guesswork. AI may explain or draft patches later — always from canonical evidence.
Reporting
Security issues: security@vasdra.com (placeholder). We aim to acknowledge reports within 48 hours.