Privacy Policy
Last updated: September 8, 2026
This policy explains what information Iron Ridge Cyber Inc. collects through QuickChain, why we collect it, who we share it with, and the choices you have including how QuickChain handles the source code you connect for scanning, which is the question we get asked first.
Iron Ridge Cyber Inc. (“Iron Ridge Cyber,” “QuickChain,” “we,” “us,” or “our”) is a West Virginia C-Corporation that builds QuickChain, a hosted software supply-chain evidence platform. This policy applies to quickchain.dev, our application dashboard, and related services (together, the “Service”). It does not apply to third-party sites we link to.
1. Information we collect
Account and profile information
When you create an account, we collect your name, email address, and authentication credentials through Supabase, our authentication and database provider. If you sign in with GitHub, Bitbucket, or Azure DevOps, we receive the basic profile information those providers share as part of that sign-in.
Repository and organization information
To scan a repository, you authorize QuickChain to access it through GitHub, Bitbucket, or Azure DevOps OAuth or a personal access token you provide. We store the minimum connection metadata needed to run scans (repository name, URL, default branch, and the access token or installation reference itself, which is never shown back to you in full). You control this access and can revoke it at any time, from your Settings page or directly from the provider’s own application-permissions page.
Scan, vulnerability, and compliance data
Running a scan produces a Software Bill of Materials (SBOM), vulnerability findings, reachability and exploitability analysis, VEX statements, and compliance-mapping documents. This data describes your dependencies and code structure (for example, package names, versions, and the file and line number where a package is imported or called) rather than reproducing your source code itself. It is stored in your account so you can review scan history and trends over time.
Billing information
Paid plans are billed through Stripe. We do not receive or store your full payment card number; Stripe collects and processes that information directly under its own privacy policy. We retain records of your subscription status, plan, and billing history.
Communications and scheduling
If you book time with us through the “Book a pilot call” scheduler on our site, that scheduler is provided by HubSpot and the meeting details you enter (name, email, and your selected time) are collected by HubSpot on our behalf. If you email us or fill out a contact form, we keep that correspondence to respond to you and for our own business records.
Usage and log data
Like most hosted services, our servers automatically log technical information such as IP address, browser type, pages visited, and timestamps, which we use for security, debugging, and abuse prevention.
2. How we handle your source code
This is the section most teams evaluating QuickChain care about most, so we are stating it plainly. When you run a scan, QuickChain clones your repository into an isolated, temporary sandbox environment for the duration of that scan. We do not retain a copy of your source code after the scan completes; the sandbox is discarded. What we keep is the derived evidence described above (dependency lists, vulnerability findings, and file-path/line-number references), not the code itself. Our scan and VEX-suppression logic is deterministic, static analysis, meaning the same inputs produce the same output; it does not send your source code to a third-party AI model (see Section 5 below).
3. How we use information
- Provide, operate, and maintain the Service, including running scans and generating compliance artifacts you request.
- Authenticate you and enforce access controls within your organization.
- Process payments and manage subscriptions.
- Respond to support requests and communicate about your account or scans.
- Monitor, secure, and improve the Service, including diagnosing technical issues.
- Communicate about product updates, and, if you opt in, marketing about QuickChain.
- Comply with legal obligations and enforce our agreements.
4. How we share information
We do not sell your personal information, and we do not share your source code or scan data with third parties for their own advertising or marketing purposes. We share information only in these circumstances:
- Service providers that host or operate parts of the Service on our behalf, currently including Supabase (database and authentication), Stripe (payment processing), HubSpot (meeting scheduling and, if you opt in, marketing email), and our cloud infrastructure and hosting providers. Each is authorized to use your information only to provide services to us.
- Source-control providers (GitHub, Bitbucket, Azure DevOps) that you connect, solely to access the repositories you authorize.
- Within your organization, where the Service is designed for shared visibility across developers, compliance leads, and other teammates or auditors you invite.
- Legal and safety reasons, if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Iron Ridge Cyber, our users, or others.
- Business transfers, if we are involved in a merger, acquisition, financing, or sale of assets, in which case information may be transferred as part of that transaction, subject to this policy or a successor policy.
5. AI and automated processing
QuickChain’s core scanning, reachability, and VEX-suppression logic is deterministic and rule-based; it does not send your source code to OpenAI, Anthropic, or any other third-party AI provider. Some in-product summaries are generated by local, non-AI text processing over your own scan results (for example, turning a list of findings into a short prioritized summary) and never leave our infrastructure to reach a third-party model. If we introduce a feature that sends your data to a third-party AI provider, we will update this policy and provide notice before that feature processes your data.
6. Cookies and tracking
We use a small number of first-party, functional cookies, for example to keep you signed in and remember the repository you last selected. We do not currently use third-party advertising or cross-site tracking cookies on the Service. If that changes, we will update this section.
On a small number of single-purpose landing pages we send directly to prospects (not linked from elsewhere on the Service), we also record first-party interaction analytics, for example whether the “Book a pilot call” link was clicked, time on page, and scroll depth, and we may use Microsoft Clarity, a session-replay and heatmap analytics tool, on those same pages. This data is tied to a randomly generated identifier scoped to that browser tab, not to your name, email, or account, and we do not use it to identify you personally.
7. Data retention
We retain account, scan, and vulnerability data for as long as your account is active, so you can review historical scans and trends. If you delete a repository, we remove the associated scan artifacts. If you delete your account, we delete your account data and stored scan artifacts, other than information we are required to retain for legal, tax, or accounting reasons (for example, billing records).
8. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encrypting data in transit, isolating each scan in its own temporary sandbox, and scoping source-control access tokens to the minimum permissions needed. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. As an early-stage company, we have not yet completed a formal third-party security certification (such as SOC 2); building toward one is on our roadmap, and we will update this policy when that changes.
9. Your choices and rights
- Access and correction: you can review and update your account information from within the Service.
- Revoking repository access: you can disconnect a source-control provider from Settings, or revoke QuickChain’s access directly from that provider’s application settings, at any time.
- Deletion: you can delete individual repositories or your entire account from Settings, or by emailing us.
- Marketing communications: you can unsubscribe from marketing emails using the link in those emails; we may still send you transactional or account-related emails.
If you are located in a jurisdiction that grants additional data protection rights, contact us using the details below and we will address your request under applicable law.
10. Children’s privacy
The Service is a business tool intended for software teams and is not directed to, and should not be used by, children under 16. We do not knowingly collect personal information from children.
11. International users
Iron Ridge Cyber is based in the United States, and the Service is hosted and operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country.
12. Changes to this policy
We may update this policy as the Service evolves. If we make material changes, we will update the “Last updated” date above and, where appropriate, notify you directly (for example, by email or an in-product notice).
13. Contact us
Questions about this policy or requests regarding your data can be sent to evan@ironridgecyber.com, or to Iron Ridge Cyber Inc., a West Virginia corporation.