Legal
Privacy Policy
Last updated: July 12, 2026
What CapitalGuard collects
CapitalGuard collects the work email, company name, license purchase and fulfillment records, authorized scope metadata, scan intake answers, redacted finding data, affiliate attribution, and support communications needed to provide the service. Stripe handles payment credentials on its hosted checkout.
Customer code and secrets
The included local scanner runs in the customer's repository and does not upload source code. It reports paths, categories, and policy gaps while redacting secret-like values. Any separately authorized managed review requires a written scope and retention plan before CapitalGuard receives repository material.
GitHub Signed Preview
When Signed Preview is enabled, the Action sends a fixed aggregate evidence object and a short-lived GitHub OIDC identity token to CapitalGuard. CapitalGuard verifies the token, discards the raw token and identity claims, and stores only irreversible workflow proof digests, aggregate counts, control states, the community Guardprint, and the signed receipt. The registry has no repository name, actor, source path, source content, secret value, or customer identity field. Public receipts are excluded from proprietary benchmark calculations by default; only internally quality-reviewed, non-identifying aggregates may be used to improve versioned security benchmarks and threat intelligence.
Model training
CapitalGuard does not use customer source code or private scan evidence to train models. Any separately agreed AI-assisted managed analysis must identify its provider, processing scope, and retention terms before transfer.
Service providers
CapitalGuard uses Stripe for hosted payment, a private Postgres service for entitlement and operational records, and transactional email for customer delivery. The local scanner does not send repository contents to these providers. Provider access is limited to the data needed for its stated function.
Referral attribution
Approved partner links carry an explicit partner code in the destination URL. CapitalGuard records a privacy-minimized click and keeps that code with its unique click ID in session storage while the visitor moves through the current browser session. If a purchase follows, CapitalGuard uses the verified pair to calculate qualified commission and prevent abuse. CapitalGuard does not give partners access to customer names, email addresses, payment credentials, license keys, or repository data.
Partner accounts and payouts
CapitalGuard stores an approved partner's account status, referral code, assigned package rates, click and conversion aggregates, commission ledger, refund-hold dates, payout threshold, and payout history. Partners can access only their own account through passwordless authentication. Account and payout terms are controlled by CapitalGuard and cannot be changed from the partner dashboard.
Contact
Privacy and security questions can be sent to support@capitalguard.io.
