Security

Vallit reads apps from the outside. Here is what a check touches and what it never does, where the results are kept, who at Vallit can see them, and how to tell us about a flaw in Vallit itself.

Requests to your app
GET, HEAD and OPTIONS only
Where reports are kept
Frankfurt, EU
Secrets we find
Never stored
Report a vulnerability
info@vallit.net

What a check touches, and what it never does

A check reads what your app already shows to any visitor, the way a browser would. It never signs in, fills in a form or changes anything.

Everything a check asks your app for
MethodWhat it asks for
GETThe page at the address you gave
GETThe scripts that page loads
GETPaths where apps leak files by mistake/.env/.git/config/backup.sqland more
HEADWhether your app answers, and how quickly
OPTIONSWhich other sites an API address lets in
POSTPUTPATCHDELETENever sent. The checker cannot build such a request.
  • It connects only to public addresses. Private, local and cloud metadata addresses are refused, again at every redirect.
  • When your pages carry a Supabase address and its public key, it asks up to ten tables for one row each and records whether a row came back, never the row.
  • Public registries receive a package name and version, or your domain name. Never your code, a key or a page.
  • Every request names itself: its user-agent starts with VallitBot/ and links vallit.net/bot. The checks run in Vercel’s Frankfurt region, whose outgoing addresses are shared and change, so there is no fixed IP to allow. A firewall that challenges bots should let that user-agent through, or the report says your app did not respond.

How we know the app is yours

The first check starts only after you tick that you own the app, or were asked by its owner. Your answer is stored with the check.

The record that confirms myapp.com
Type
TXT
Name
_vallit.myapp.com
Value
vallit-verification=<a code made for this app>
  • The close watch and the AI sample go further, so they need a confirmed domain: a TXT record named _vallit in front of your address, which only someone who controls the domain can add.
  • If you let Vallit add the record with a Cloudflare token, the token is used once and never stored, logged or shown again.
  • To stay a polite visitor, one domain can be checked three times an hour, and one visitor can start five checks an hour.

Access to your code, and to your fixes

Code checks run only after you connect a GitHub repository. The Vallit GitHub App asks to read the contents and metadata of the repositories you share with it.

How a fix arrives, once pull requests are on

main untouched

vallit/<the fix>

  1. A new branch
  2. One commit
  3. A pull request
  4. You merge it, or not
  • Its access token is made for one check and expires within the hour. No token is stored.
  • The repository is read into memory at one revision. Nothing is written to disk and none of your code is run.
  • Because the access is read-only, no fix arrives as a pull request today. The pull request path is off until you tick it for an app, and needs write access first.
  • When it runs, a fix is one commit on a new branch, opened as a pull request. Vallit never merges and never writes to your default branch, and a person at Vallit approves every fix before it goes out.
  • Vallit asks for no access to your hosting, your deploys or your database password.

Where your data lives, and for how long

The app runs in Vercel’s Frankfurt region and its database is on Supabase in Frankfurt (eu-central-1).

  • A check started without an account, and monitoring results, are deleted after 90 days. Reports in your workspace stay until you delete the workspace.
  • A check from the front page stores a shortened hash of your IP address, used to count checks per hour, not the address itself.
  • Deleting a workspace deletes its apps, monitoring and settings. Its reports keep working under their links, with the workspace, the IP hash and the email address removed.
  • A business that needs a data processing agreement under Art. 28 GDPR gets one from us: write to info@vallit.net with the company’s name and address.

Encryption, and the secrets we never keep

Every connection to Vallit is encrypted. app.vallit.net tells browsers to reach it over HTTPS only, and to remember that for two years.

What a finding keeps about an exposed key (example)
Kind
Stripe live secret key
Prefix
sk_live_
Length
107 characters
Fingerprint
9f2c41a07be3
Excerpt
Stripe("[107-char value removed]")
  • The database sits on Supabase’s encrypted storage. Vallit adds no encryption of its own on top; it keeps secrets out instead.
  • A key we find is kept by its kind, its public prefix, its length and a fingerprint that recognises it in a later check. Its value is never stored.
  • No GitHub token, no Cloudflare token and no model key is stored either. The AI Gateway is reached with the deployment’s own identity.

Who at Vallit can see what

Each workspace is kept apart by row-level security in the database. One workspace cannot read another’s apps or reports.

  • Only people on Vallit’s operator list, checked on the server against an email address the sign-in provider has verified, can open the operator console. It shows every check, including an email address a visitor left.
  • The team is emailed when a check finds something critical, when a visitor leaves an address and when a fix is requested.

Services Vallit runs on

ServiceWhat for
VercelHosting, and the AI Gateway to the language models that confirm code findings
SupabaseThe database
ClerkSign-in and account details
StripePayments; card details stay there
ResendEmail, and messages from the contact form
GitHubOnly when you connect a repository
AnthropicThrough the AI Gateway: reads code excerpts to confirm findings in connected repositories
Apple iCloud MailOur mailbox

The privacy policy names what each of them processes, and on what basis.

Found a vulnerability in Vallit?

Write to info@vallit.net. We read every report and would rather hear about a flaw twice than not at all.

info@vallit.net

What helps us

  • The address or part of Vallit that is affected
  • The steps that show the problem
  • What you could read or change, and what you did with it
  • How to reach you, and whether you want to be named

In scope

  • vallit.net and www.vallit.net
  • app.vallit.net and its reports
  • The checker, and the requests it sends
  • The Vallit GitHub App

Not in scope

  • Apps our customers built. Please tell their owners
  • Reports from automated scanners without a way to use the finding
  • Denial of service, load testing and spam
  • Tricking people who work for Vallit or its customers

While you test

  • Use only accounts and workspaces you created yourself
  • Stop as soon as you reach someone else’s data, keep none of it, and tell us
  • Do not change or delete anything that is not yours
  • Give us time to fix the flaw before you talk about it in public

What we promise

  • We reply within five working days, and keep you posted until the flaw is fixed.
  • If you want, we name you when the fix is published.
  • If you keep to these rules and act in good faith, we will not take legal action against you or file a criminal complaint about your research. We cannot speak for other companies whose services Vallit uses.

Vallit does not pay bounties. The machine-readable version of this section is security.txt.