CodeFlowOps
Security IndexFAQ

Privacy Policy

Last updated: September 13, 2026 · CodeFlowOps is operated by ClayDesk LLC (Texas, USA)

What we collect

  • Scan submissions: the endpoint URL you submit and the resulting report (findings, grades, timestamps). Reports are stored so their share links keep working, and are accessible to anyone who has the report link.
  • Bearer tokens you optionally provide for authenticated scans are used in-flight to perform the scan and are never stored, logged, or included in reports.
  • Waitlist signups: the email address you submit, a timestamp, and the submitting IP address (for abuse prevention).
  • Operational logs: our infrastructure (Amazon Web Services) records standard request logs (IP address, timestamp, request path) used for security, debugging and abuse prevention.

What we don't do

  • No cookies and no third-party analytics or advertising trackers on this site today.
  • We don't sell or share personal information with third parties for their marketing.
  • We don't execute tools on scanned servers or store their business data — scans are read-only protocol and configuration checks.

How we use information

To run the scans you request, keep share links working, publish the aggregate MCP Security Index, contact waitlist members about the product, and protect the service from abuse.

Where data lives

Data is processed and stored on Amazon Web Services in the United States.

Retention and deletion

Reports are retained so links keep working; waitlist emails are retained until you ask to be removed. To have a report or your email deleted, contact us with the report link or address: support@codeflowops.com. We respond within 30 days.

Changes

We'll update this page when our practices change; the date above always reflects the current version.

Contact

ClayDesk LLC · support@codeflowops.com

© 2026 ClayDesk LLC · Privacy · Terms · Contact