Pre-Beta Pre-beta signups are open now. The full audytx engine is live for pre-beta. Everything free today stays free — paid tiers arrive Sep 01, 2026 from $20/month for unlimited repositories.
Legal

Data Processing Addendum

Version 1.0 · Effective: 13 July 2026 · Operator: Rexstart Labs Pvt Ltd · Questions: open a support ticket

Scan metadata only Source never stored Read-only GitHub access GDPR Article 28 EU SCCs · Module Two 90-day metadata retention

1. Parties and how this DPA applies

This Data Processing Addendum ("DPA") is between the customer that installs the audytx GitHub App, holds an audytx account, or uses the audytx MCP server (the "Controller") and Rexstart Labs Pvt Ltd, the operator of audytx (the "Processor").

This is a click-through addendum: it forms part of the audytx Terms of Service and takes effect automatically when you install the GitHub App, create an account, or call the MCP server. No signature is required.

2. Subject matter, duration, nature and purpose

The processing is the automated static analysis of the Controller's Terraform configurations: audytx fetches .tf and .tfvars files (or receives them in an MCP request or an optional plan upload), analyzes them in memory, and returns findings. No source file content is written to any database or log.

Processing lasts for as long as the GitHub App remains installed or the account remains active, plus the retention period in section 9.

3. Categories of personal data and data subjects

Processed transiently, never persisted: the contents of the Terraform files audytx scans, which may incidentally contain personal data.

Persisted: scan metadata and installation records only — GitHub identifiers such as the account login, repository name, pull-request number and commit SHA, plus scan timings and outcome counts. The complete column list, straight from the database migrations, is published at /trust#storage.

Data subjects: the Controller's personnel, contractors and repository contributors whose GitHub identifiers appear in the processed data.

Account registration data (email, name, password hash), contact-form submissions and cost-sampler reports are processed by Rexstart Labs Pvt Ltd as an independent controller under the Privacy Policy, not under this DPA. audytx neither requests nor is designed to process special categories of personal data.

4. Documented instructions

The Processor processes personal data only on documented instructions from the Controller. The documented instructions are: installing the GitHub App on chosen repositories (scan pull requests there), each MCP tool call (scan the submitted content), each optional plan upload, and any .audytx-baseline.yaml suppression file the Controller commits. If applicable law requires processing contrary to those instructions, the Processor will inform the Controller before processing, unless that law prohibits it.

5. Confidentiality

Access to production data is limited to the two founders of Rexstart Labs Pvt Ltd, who are committed to confidentiality. There are no other personnel with access.

6. Security measures

The technical and organisational measures are documented, claim by claim with source references, on the trust & data handling page. In summary:

7. Subprocessors

The Controller grants general written authorisation for the subprocessors listed at /subprocessors — currently Cloudflare (hosting, storage, queues, transactional email) and GitHub (source of scanned files and destination of results).

The Processor will give at least 30 days' advance notice of any intended addition or replacement by publishing a dated entry on that page. If the Controller objects, its remedy is to stop using the service before the change takes effect — removing the GitHub App immediately and permanently revokes audytx's access.

Each subprocessor is bound by its own data-processing terms, linked from the subprocessor list.

8. Assistance with data subject rights and incidents

Taking into account the nature of the processing (metadata-only storage), the Processor assists the Controller in responding to requests to exercise the rights of a data subject — access, rectification, erasure — for the scan metadata and installation records described in section 3, via a support ticket.

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably needed for the Controller's own notification obligations.

9. Deletion and return

10. Information and audit

The Processor makes available the information necessary to demonstrate compliance with this DPA: the trust page publishes the storage schema straight from the database migrations, and every factual claim on this page carries an in-repo source reference in the page markup. The Processor will additionally respond to reasonable written audit enquiries submitted via a support ticket.

11. International transfers — Standard Contractual Clauses

Processing runs on Cloudflare's global edge network; scan metadata is stored in an edge SQLite database in the US region, and the Processor is established in India.

Where personal data originating in the EEA, the United Kingdom, or Switzerland is transferred to the Processor, the transfer is governed by the EU Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), which are incorporated into this DPA by reference, with the Controller as data exporter and Rexstart Labs Pvt Ltd as data importer. Where the Controller acts as a processor for its own customers, Module Three (processor to processor) applies instead. For UK transfers the clauses are read with the ICO's International Data Transfer Addendum; for Swiss transfers, with the adaptations required by the FADP.

Annex I to the clauses is completed by sections 2 and 3 of this DPA; Annex II by section 6; the list of subprocessors by /subprocessors. Onward transfers to subprocessors are covered by each subprocessor's own transfer terms, linked from that page.

12. Term and precedence

This DPA applies for as long as the Processor processes personal data on behalf of the Controller and ends automatically when that processing ends (section 9). If this DPA conflicts with the Terms of Service, this DPA prevails with regard to the processing of personal data. Material changes to this DPA are announced the same way as Privacy Policy changes, at least 14 days before taking effect.

Open beta

Start free during the open beta

Install the GitHub App or point your coding agent at the MCP server — this DPA takes effect automatically, no signature required.