Last updated:
Privacy Policy
Tenzai Ltd ("the Company," "we," "us," or "our"), Yigal Alon Street 98, Floor 12, Tel Aviv 6473424, Israel, operates an AI-powered application security scanning platform (the "Platform" or "Service") that connects to software repositories, analyses application code for vulnerabilities, and delivers prioritized findings with automated fix proposals to software development and AppSec teams. Because the Platform processes source code, repository credentials, and security findings data, the Company treats protection of personal information as a core operational obligation.
This Privacy Policy describes how the Company collects, uses, shares, and protects personal information under the Israeli Privacy Protection Law, 5741-1981 ("PPL") and applicable Privacy Protection Regulations.
1. Database Owner
The Company is the database owner, as defined under the PPL, for personal information processed through the Service. For privacy inquiries, contact us at [email protected].
2. Information We Collect
We collect the following categories of personal information:
- Account and identity data: name, work email address, company name, job title, and account credentials provided at registration.
- Repository connection credentials: OAuth tokens, deploy keys, or personal access tokens you submit to connect version-control repositories (GitHub, GitLab, Bitbucket, and similar services). These credentials are retained only for the duration needed to complete the requested scan.
- Source code and repository content: files from connected repositories submitted for vulnerability scanning. Code content is processed to generate security findings and is not retained beyond the current scan session.
- Vulnerability findings data: scan results, severity ratings, affected file paths, and automated fix proposals generated by the Platform, retained for the duration of your subscription.
- Usage and telemetry data: scan counts, API call volumes, feature interaction logs, and session metadata collected automatically to operate and improve the Service.
- Billing information: payment details processed by our third-party payment processor; the Company does not store full payment card numbers.
- Communications: messages you send through contact forms, support tickets, or email.
3. Purposes
We use personal information to:
- Authenticate your account and authorise access to the Service.
- Connect to your code repositories and execute security scans you initiate.
- Generate vulnerability findings reports and automated fix proposals for your team.
- Communicate with you about your account, scan results, and product updates.
- Detect fraud and prevent misuse of the Platform.
- Comply with legal obligations under Israeli law.
Source code submitted to the Platform is processed solely to produce your security findings. The Company does not use customer code to train AI models, develop competing products, or share security intelligence with third parties outside the scope of delivering the Service to your organisation.
4. Sharing and Cross-Border Transfers
Personal information is shared only as follows:
- With cloud infrastructure, analytics, and payment-processing providers who act as data processors under written data-processing agreements.
- With authorised users within your account, according to permissions set by your account administrator.
- When required by Israeli law, a court order, or a lawful law-enforcement request.
Cross-border transfers comply with the Privacy Protection (Transfer of Data Abroad) Regulations. Where data is transferred to countries not recognised as providing adequate protection, we rely on standard contractual clauses or equivalent safeguards.
5. Retention
- Repository credentials: held only while a scan is in progress; deleted on completion.
- Source code content: processed in-session and not retained after the scan completes.
- Vulnerability findings and scan reports: retained for the term of your subscription and deleted within 90 days of account termination.
- Account and billing records: retained for up to 36 months after account closure to satisfy legal and audit obligations.
6. Your Rights under the PPL
Under the Israeli Privacy Protection Law, you have the right to:
- Inspect personal information held about you in our database.
- Request correction of inaccurate information.
- Request removal from a database used for direct marketing.
Email [email protected] to make a request. We respond within 30 days.
7. Security Incidents
The Platform is built on application security principles. We apply encryption in transit and at rest, role-based access controls, and continuous vulnerability scanning of our own infrastructure. Where notification is required by the Privacy Protection (Data Security) Regulations, we will report security incidents to the Privacy Protection Authority and notify affected data subjects within the required timeframes.
8. Complaints and Contact
You may direct complaints to the Israeli Privacy Protection Authority at gov.il/PPA.
Tenzai LtdYigal Alon Street 98, Floor 12
Tel Aviv 6473424, Israel
Email: [email protected]
Phone: +972 3 795 4200