Security & Privacy

Your code is your most valuable asset. AnchorScape isolates processing and makes retention depend on the workflow you choose.

Temporary Job Processing

The job uses an isolated temporary workspace that can include container storage. The workspace is removed by the job cleanup policy; reports and operational evidence are retained separately.

Isolated Processing

Scan and fix jobs run in isolated, temporary environments that are removed after the job. Temporary processing can use container storage; “ephemeral” does not mean that every byte remains only in RAM.

  • Jobs run in restricted Kubernetes workloads separated from other customers
  • Temporary job containers and their working storage are destroyed after completion
  • Normal workloads do not receive platform service-account credentials
  • Reports and operational evidence are stored separately from temporary job workspaces

What We Store

Account and analysis workflows retain operational records:

  • Project name and scan timestamp
  • The generated report (findings, scores, recommendations)
  • Your user account details
  • Usage statistics for billing purposes

When Source Persists

Retention depends on the feature the user chooses:

  • Scan-only working copies are removed with the temporary scan job
  • Fix and deployment workflows may retain a source archive so an environment can be rebuilt and investigated
  • Drydock workspaces use persistent volumes by design; Stop retains them and Delete removes them
  • Connected GitHub remains the preferred external source of truth for repository history

Do not upload source if its retention requirements are incompatible with the selected workflow. Pilot customers can request a workflow-specific retention review.

Analysis and Build Are Different Workflows

Lookout performs static analysis in its scanner workflow. Deployment and Drydock are explicitly execution workflows: they install dependencies, build code, run containers, and must be treated as higher-trust operations with separate isolation and egress controls.

Responsible Disclosure

If you believe you have found a vulnerability in Anchorscape, please email [email protected]