Legal

Privacy Policy

Last updated: July 12, 2026

What CapitalGuard collects

CapitalGuard collects the work email, company name, license purchase and fulfillment records, authorized scope metadata, scan intake answers, redacted finding data, affiliate attribution, and support communications needed to provide the service. Stripe handles payment credentials on its hosted checkout.

Customer code and secrets

The included local scanner runs in the customer's repository and does not upload source code. It reports paths, categories, and policy gaps while redacting secret-like values. Any separately authorized managed review requires a written scope and retention plan before CapitalGuard receives repository material.

GitHub Signed Preview

When Signed Preview is enabled, the Action sends a fixed aggregate evidence object and a short-lived GitHub OIDC identity token to CapitalGuard. CapitalGuard verifies the token, discards the raw token and identity claims, and stores only irreversible workflow proof digests, aggregate counts, control states, the community Guardprint, and the signed receipt. The registry has no repository name, actor, source path, source content, secret value, or customer identity field. Public receipts are excluded from proprietary benchmark calculations by default; only internally quality-reviewed, non-identifying aggregates may be used to improve versioned security benchmarks and threat intelligence.

Model training

CapitalGuard does not use customer source code or private scan evidence to train models. Any separately agreed AI-assisted managed analysis must identify its provider, processing scope, and retention terms before transfer.

Service providers

CapitalGuard uses Stripe for hosted payment, a private Postgres service for entitlement and operational records, and transactional email for customer delivery. The local scanner does not send repository contents to these providers. Provider access is limited to the data needed for its stated function.

Referral attribution

Approved partner links carry an explicit partner code in the destination URL. CapitalGuard records a privacy-minimized click and keeps that code with its unique click ID in session storage while the visitor moves through the current browser session. If a purchase follows, CapitalGuard uses the verified pair to calculate qualified commission and prevent abuse. CapitalGuard does not give partners access to customer names, email addresses, payment credentials, license keys, or repository data.

Cookies and local storage

CapitalGuard uses only the session, authentication, checkout, and abuse-prevention storage required to provide requested features. The current website does not write a referral cookie or run advertising analytics. Partner attribution begins with the explicit code in the referral URL and remains only for the active browser session.

Partner accounts and payouts

CapitalGuard stores an approved partner's account status, referral code, assigned package rates, click and conversion aggregates, commission ledger, refund-hold dates, payout threshold, and payout history. Partners can access only their own account through passwordless authentication. Account and payout terms are controlled by CapitalGuard and cannot be changed from the partner dashboard.

Contact

Privacy and security questions can be sent to support@capitalguard.io.