Privacy

Source code stays where Radar runs.

Code Radar is a local-first, offline code scanner for no source upload SAST workflows. License checks and optional telemetry use metadata; scans and reports remain in the local workspace or CI runner.

Direct answer

No-Source-Upload Privacy

Review Code Radar privacy boundaries for no-source-upload SAST, local scans, license validation, telemetry metadata, reports, and checkout attribution.

What private data does Code Radar avoid collecting?

Radar does not collect source text, source paths, source snippets, repository contents, secrets found in code, report payloads, raw license keys, raw hardware identifiers, or code archives.

What data is used for licensing?

License validation uses entitlement identifiers, activation identifiers, machine fingerprint hashes, optional CI repository fingerprints, plan code, status, and client version.

Can telemetry be disabled?

Yes. CLI telemetry can be disabled with `DO_NOT_TRACK=1` or `RADAR_TELEMETRY=0`, and telemetry is not required to scan source code.

Where should no-source-upload buyers go next?

Use /security/ for controls, /docs/privacy-telemetry/ for implementation details, /download/ for local proof, and /pricing/ only after the private workflow fits.

Intentanswer no source upload SAST, offline code scanner, and local security review tool privacy questions
Proofsource text, paths, snippets, secrets, reports, raw keys, raw hardware identifiers, and code archives are not collected
Next actionreview the security model and privacy telemetry docs before installing Radar on sensitive repositories or adding CI validation

Decision evidence

Privacy proof before source-sensitive scans.

Privacy pages should answer exactly what is collected, what is not collected, how to disable telemetry, and when paid validation enters the workflow.

no source upload SAST

Radar does not collect source text, source paths, source snippets, repository contents, secrets found in code, report payloads, raw license keys, raw hardware identifiers, or code archives.

Evidence to inspect
Privacy data boundary table, security model, telemetry controls, and report ownership.
Boundary
Licensing metadata is allowed to leave the environment; repository content is not.
Review security controls
offline code scanner

Local scans and reports remain in the shell, workspace, runner, or requested output path.

Evidence to inspect
Terminal output, SARIF, JSON, HTML report ownership, and telemetry opt-out commands.
Boundary
Paid commands may require online entitlement validation even when source scanning stays local.
Read telemetry docs
local security review tool

Privacy-sensitive teams should prove value locally before moving to checkout or repository validation.

Evidence to inspect
Free Preview quick scan, privacy table, security model, sample report, and pricing boundaries.
Boundary
The proof path should happen before a sensitive repository depends on the CI gate.
Start local proof

Privacy proof

Make the no-source-upload claim inspectable.

Privacy objections should be answered before checkout or installation. Radar separates scan data from entitlement metadata and gives teams explicit controls for telemetry-sensitive environments.

Never sentSource textSource snippets, paths, secrets, reports, and repository archives are not uploaded by Radar.
TelemetryOptionalCLI telemetry can be disabled through standard environment controls.
ReportsLocal artifactsHTML, JSON, SARIF, and terminal output stay where the command writes them.
CheckoutAttribution onlyWebsite and billing events track conversion metadata, not repository contents.
DO_NOT_TRACK=1 radar scan . --quick
RADAR_TELEMETRY=0 radar scan . --quick
radar scan . --format html > radar.html

This page should convert no source upload SAST, offline code scanner, private code security scan, and local security review tool demand.

Privacy objection router

Route no-source-upload searches to the exact boundary and action.

Privacy visitors should not have to infer what stays local. The page should answer the data boundary, show controls, and move qualified buyers to install or security review.

I need private local scanning.

Use the download path when the team wants source scanning before a hosted platform or procurement workflow.

offline code scannerlocal security review toolprivate code security scan
Run private scan

I need security controls, not only privacy wording.

Use the security model when license validation, rate limits, CI validation, and abuse controls need review.

no source upload sastlocal code security scannerprivate sast tool
Review security model

I need exact telemetry controls.

Use telemetry docs when teams need environment variables and command behavior before installing on sensitive repositories.

disable scanner telemetryscanner telemetry privacylocal scanner preview
Open telemetry docs

Trust evidence checklist

Separate scan data from attribution metadata.

Privacy buyers need to distinguish repository content from licensing, checkout, and telemetry metadata. This checklist makes the boundary actionable before install or procurement.

Repository content is not the telemetry payload.

Source text, source paths, secrets, report payloads, and repository archives are not collected by Radar telemetry.

Read the telemetry documentation when policy requires exact environment controls.

scanner telemetry privacydisable scanner telemetryoffline code scanner
Read telemetry docs

Telemetry can be disabled for scans.

Use standard environment controls when a repository or CI job should run without CLI telemetry.

Run a private local scan after setting the environment control required by policy.

local security review toolprivate code security scanno source upload sast
Run private scan

License validation uses entitlement metadata.

Activation and validation use license, plan, activation, machine, repository, status, and client-version metadata.

Review the security model when entitlement validation must be approved before rollout.

license validation metadataprivate sast toollocal code security scanner
Review security model

Checkout attribution stays separate from code.

Website and checkout events track landing pages, CTA context, plan metadata, and billing state, not repository contents.

Move to pricing only after the data boundary is clear.

developer first sastteam sast pricingrepository security gate
Review plans

Data boundary

The privacy model should be easy to inspect before a team runs Radar as a private code security scanner on sensitive repositories.

Repository sourceNever uploaded by Radar. Source files are read only where the scan runs.
ReportsTerminal, SARIF, JSON, and HTML reports are written only to the local shell, runner, or paths requested by the user.
License validationEntitlement identifiers, activation identifiers, machine fingerprint hashes, optional CI repository fingerprints, plan code, status, and client version.
CLI telemetryCommand name, scan profile, output format, duration, file counts, finding counts, severity counts, scores, platform, architecture, and whether the command ran in GitHub Actions.
Website analyticsPage views, pricing/download/docs events, checkout events, anonymous session ids, and attribution parameters such as UTM tags.
Never collectedSource text, source paths, source snippets, repository contents, secrets found in code, report payloads, raw license keys, raw hardware identifiers, or customer code archives.

Website analytics settings

Website analytics are optional, run only in production after explicit consent, and remain disabled when Do Not Track or Global Privacy Control is active.

Website analytics are waiting for your choice.

User controls

Telemetry is not required to scan source code. These commands keep the behavior explicit for local shells and automation.

Disable CLI telemetryDO_NOT_TRACK=1 radar scan . --quick
Disable Radar telemetryRADAR_TELEMETRY=0 radar scan . --quick
Inspect license stateradar license status
Run without exportsradar scan . --quick

Privacy FAQ

What private data does Code Radar avoid collecting?

Radar does not collect source text, source paths, source snippets, repository contents, secrets found in code, report payloads, raw license keys, raw hardware identifiers, or code archives.

What data is used for licensing?

License validation uses entitlement identifiers, activation identifiers, machine fingerprint hashes, optional CI repository fingerprints, plan code, status, and client version.

Can telemetry be disabled?

Yes. CLI telemetry can be disabled with `DO_NOT_TRACK=1` or `RADAR_TELEMETRY=0`, and telemetry is not required to scan source code.

Where should no-source-upload buyers go next?

Use /security/ for controls, /docs/privacy-telemetry/ for implementation details, /download/ for local proof, and /pricing/ only after the private workflow fits.

Need the security model too?

Review licensing, entitlement validation, rate limits, and CI controls.