Security
Vallit reads apps from the outside. Here is what a check touches and never does, and where its results are kept. You also find who at Vallit can see them, and how to tell us about a flaw in Vallit.
- Requests to your app
- GET, HEAD and OPTIONS only
- Where reports are kept
- Frankfurt, EU
- Secrets we find
- Never stored
- Report a vulnerability
- info@vallit.net
What a check touches, and what it never does
A check reads what your app already shows to any visitor, the way a browser would. It never signs in, fills in a form or changes anything.
| Method | What it asks for |
|---|---|
| GET | The page at the address you gave |
| GET | The scripts that page loads |
| GET | Paths where apps leak files by mistake/.env/.git/config/backup.sqland more |
| HEAD | Whether your app answers, and how quickly |
| OPTIONS | Which other sites an API address lets in |
| Never sent. The checker cannot build such a request. |
- It connects only to public addresses. Private, local and cloud metadata addresses are refused, again at every redirect.
- When your pages carry a Supabase address and its public key, it asks up to ten tables for one row each. It records whether a row came back, never the row.
- Public registries receive a package name and version, or your domain name. Never your code, a key or a page.
- Every request names itself: its user-agent starts with VallitBot/ and links vallit.net/bot. The checks run in Vercel’s Frankfurt region, whose outgoing addresses are shared and change, so there is no fixed IP to allow. A firewall that challenges bots should let that user-agent through, or the report says your app did not respond.
How we know the app is yours
The first check starts only after you tick that you own the app, or were asked by its owner. Your answer is stored with the check.
- Type
TXT- Name
_vallit.myapp.com- Value
vallit-verification=<a code made for this app>
- The close watch and the AI sample go further, so they need a confirmed domain. That is a TXT record named _vallit in front of your address, which only someone who controls the domain can add.
- If you let Vallit add the record with a Cloudflare token, the token is used once and never stored, logged or shown again.
- To stay a polite visitor, one domain can be checked three times an hour, and one visitor can start five checks an hour.
Access to your code, and to your fixes
Code checks run only after you connect a GitHub repository. The Vallit GitHub App asks, on the repositories you share with it, to read and write contents, pull requests and issues, to set commit statuses and to read metadata. GitHub lists this before you install it.
main untouched
vallit/<the fix>
- A new branch
- One commit
- A pull request
- You merge it, or not
- Its access token is made for one check and expires within the hour. No token is stored.
- The repository is read into memory at one revision. Nothing is written to disk and none of your code is run.
- A fix arrives as a pull request only for an app where you ticked pull requests, once your installation has accepted write access.
- When it runs, a fix is one commit on a new branch, opened as a pull request. Vallit never merges and never writes to your default branch, and a person at Vallit approves every fix before it goes out.
- Vallit asks for no access to your hosting, your deploys or your database password.
Where your data lives, and for how long
The app runs in Vercel’s Frankfurt region and its database is on Supabase in Frankfurt (eu-central-1).
- A check started without an account, and monitoring results, are deleted after 90 days. Reports in your company stay until you delete the company.
- A check from the front page stores a shortened hash of your IP address, used to count checks per hour, not the address itself.
- Deleting a company deletes its apps, monitoring and settings, and the reports that read its code. Its other reports keep working under their links, with the company, the IP hash and the email address removed.
- A business that needs a data processing agreement under Art. 28 GDPR gets one from us: write to info@vallit.net with the company’s name and address.
Encryption, and the secrets we never keep
Every connection to Vallit is encrypted. app.vallit.net tells browsers to reach it over HTTPS only, and to remember that for two years.
- Kind
Stripe live secret key- Prefix
sk_live_- Length
107 characters- Fingerprint
9f2c41a07be3- Excerpt
Stripe("[107-char value removed]")
- The database sits on Supabase’s encrypted storage. Vallit adds no encryption of its own on top; it keeps secrets out instead.
- A key we find is kept by its kind, its public prefix, its length and a fingerprint that recognises it in a later check. Its value is never stored.
- No GitHub token, no Cloudflare token and no model key is stored either. The AI Gateway is reached with the deployment’s own identity.
Who at Vallit can see what
Each company is kept apart by row-level security in the database. One company cannot read another’s apps or reports.
- Only people on Vallit’s operator list, checked on the server against an email address the sign-in provider has verified, can open the operator console. It shows every check, including an email address a visitor left.
- We get an email when a check finds something critical, when a visitor leaves an address and when a fix is requested.
Services Vallit runs on
| Service | What for |
|---|---|
| Vercel | Hosting, and the AI Gateway to the language models that confirm code findings |
| Supabase | The database |
| Clerk | Sign-in and account details |
| Stripe | Payments; card details stay there |
| Resend | Email, and messages from the contact form |
| GitHub | Only when you connect a repository |
| Anthropic | Through the AI Gateway: reads code excerpts to confirm findings in connected repositories |
| Apple iCloud Mail | Our mailbox |
The privacy policy names what each of them processes, and on what basis.
Found a vulnerability in Vallit?
Write to info@vallit.net. We read every report and would rather hear about a flaw twice than not at all.
info@vallit.netWhat helps us
- The address or part of Vallit that is affected
- The steps that show the problem
- What you could read or change, and what you did with it
- How to reach you, and whether you want to be named
In scope
- vallit.net and www.vallit.net
- app.vallit.net and its reports
- The checker, and the requests it sends
- The Vallit GitHub App
Not in scope
- Apps our customers built. Please tell their owners
- Reports from automated scanners without a way to use the finding
- Denial of service, load testing and spam
- Tricking people who work for Vallit or its customers
While you test
- Use only accounts and companies you created yourself
- Stop as soon as you reach someone else’s data, keep none of it, and tell us
- Do not change or delete anything that is not yours
- Give us time to fix the flaw before you talk about it in public
What we promise
- We reply within five working days, and keep you posted until the flaw is fixed.
- If you want, we name you when the fix is published.
- If you keep to these rules and act in good faith, we will not take legal action against you or file a criminal complaint about your research. We cannot speak for other companies whose services Vallit uses.
Vallit does not pay bounties. The machine-readable version of this section is security.txt.