SECURITY & DATA HANDLING

Know how your testing data is handled.

Clear information about source imports, encrypted scan configuration, access checks and AI processing — so you can choose the right data and environment for your tests.

Transient import tokens
Encrypted scan configuration
Owner checks on report routes

Safe testing and authorization

Scan only applications you own or have authorization to test. Default exploration blocks state-changing HTTP requests; recognized payment and destructive actions are skipped. No brute force, denial of service, intentional data destruction or validation of exposed credentials is performed.

Passive checks inspect response protections and bounded, already-loaded same-origin frontend scripts. Only recognized private-key/token formats are flagged, with values redacted. Public API identifiers are not automatically treated as secrets. A key-like pattern is potential exposure, not proof of usable credentials.

Explicit journeys and API contracts can write synthetic data and require authorization for an isolated staging environment. Dedicated-account access checks inspect only declared private markers. Screenshots can capture visible data: use synthetic fixtures.

BreakYourApp is not a full penetration-testing replacement. No issues detected within a scan’s coverage does not mean your application is completely secure. No compliance certification is claimed.

Credentials and imported sources

Jira and GitHub API tokens are used to fetch the source you select. The import feature does not save those tokens to the database, scan configuration, report or AI prompt. The form clears the token after each import attempt.

Application login credentials and imported Jira/GitHub source snapshots saved in scan configuration are encrypted with AES-256-GCM. The scanner decrypts the configuration when it needs to run your test. Imported content is also visible in your browser preview and its signed import snapshot; selected evidence can appear in reports and exports.

Source imports are read-only. They do not modify tickets, repositories or PRs. Private GitHub imports need only Pull requests: read; restrict the token to the repository you intend to test.

Access to your results

Your saved scan results require sign-in. Report, bug and screenshot routes check the signed-in account against the scan owner. Private screenshot storage can issue short-lived links after that check. Treat downloaded reports and temporary screenshot links as confidential.

Reports, account information and other scan records are stored separately from the encrypted scan configuration. Encryption of scan configuration is not a claim that every stored field or screenshot is encrypted by the application. Infrastructure and service operations may require access to service data.

What may be stored

Depending on the checks you run, stored data can include your account email, application URL, testing instructions, scan settings, imported source snapshots, actions, issue evidence, console and network diagnostics, screenshots and reports. Screenshots may capture anything visible in the tested application.

Known credential patterns are redacted from supported text evidence. Redaction is a best-effort safeguard; it does not automatically remove all personal data, business-sensitive content or secrets from screenshots. Use isolated staging, dedicated test accounts and synthetic data.

AI and service providers

Sending imported Jira or GitHub content to the configured AI provider for test proposals requires a separate opt-in in the import or combined-plan form. Without that consent, source imports offer manual mapping.

During ordinary scanning, a configured AI provider may receive page URLs, titles, short visible-text excerpts, testing instructions, candidate actions and issue-summary information to guide testing and prepare the summary. The import opt-in controls imported-source planning; it is not a switch that disables all scan-time AI processing.

Hosting, authentication, database and storage services process data needed to operate the product. If you request an emailed PDF and delivery is configured, the email provider receives your account email and report attachment. Provider retention, processing locations and training terms depend on the deployed service and its account settings; contact us for current details before importing sensitive organizational content.

Retention and deletion requests

The application currently does not implement a fixed automatic expiry schedule for scan records and stored screenshots, or an in-product account/data deletion control. Saved source snapshots allow you to rerun earlier tests.

To request deletion or ask how long your data is kept, contact us using the account email you signed in with and identify the affected scans. We will review the request and account ownership. Exact scope, timing and any infrastructure backup retention need confirmation; deletion is not completed merely by sending an email.

Report a security concern

Email guymeir1604@gmail.com with a short description, affected URL and safe reproduction steps. Start with a sanitized summary; ask us how to share sensitive evidence securely.

For access, retention or deletion questions, use the same address or our support page.

This page describes current application controls. It is not an independent security audit or certification. Last updated: October 4, 2026.