Privacy Policy
Last updated · June 13, 2026
Zolt Security, operated by ZLT Technologies Private Limited (“Zolt”, “we”, “us”) operates an automated application-security platform that scans your source code repositories for vulnerabilities, leaked secrets, dependency issues, and infrastructure misconfigurations. This policy explains what we collect, why, and how we protect it.
Authentication — we never see your password
You sign in with GitHub OAuth. When you click “Sign in”, you are redirected to GitHub’s official authorization page (github.com) where you authenticate directly with GitHub. We never receive, see, or store your GitHub password. GitHub returns a standard OAuth access token, which we use only to perform the actions you authorize (reading repositories you connect, and posting scan results).
Information we collect
- Account information — your GitHub username, display name, email address, and avatar, as provided by GitHub during sign-in.
- Repository content — source code, configuration, commit history, and metadata from the repositories you explicitly connect, accessed only to run scans.
- Scan results — the findings our analysis produces (vulnerabilities, secrets, dependency advisories, misconfigurations) and their status.
- Usage data — basic logs needed to operate the service, diagnose errors, and keep it secure.
- Waitlist — while access is invite-only, if you attempt to sign in without an invite we record your GitHub username, name, and email so we can grant you access later. You can ask us to delete this at any time.
How we use your information
- To run security scans on the repositories you connect and show you the results.
- To post analysis to your pull requests and checks when you enable that.
- To authenticate you and maintain your session.
- To operate, secure, debug, and improve the service.
We do not sell your data, and we do not use your source code to train third-party models for unrelated purposes.
How we protect it
All traffic is encrypted in transit over HTTPS. Sessions are held in signed, httpOnly cookies. Access tokens are stored encrypted and used only to fulfill the actions you authorize. We scope repository access to the minimum needed and process repository contents transiently for the duration of a scan.
Sharing
We share data only with infrastructure providers that help us run the service (for example, hosting and compute), under contracts that require them to protect it, and where required by law. We do not sell or rent your personal information.
Your choices
You can disconnect any repository, revoke Zolt’s access from your GitHub settings at any time, or request deletion of your account and associated data by contacting us. Revoking access immediately stops further scanning.
Contact
Questions about this policy or your data? Email business@zoltsecurity.com.