Frequently asked questions

What to know before connecting a repository.

Straight answers about GitHub access, repository scans, plans, billing, and the limits of automated security checks.

What does SecureRepos scan?

SecureRepos checks connected GitHub repositories for exposed secrets, broad GitHub Actions permissions, risky Dockerfile and infrastructure patterns, known vulnerable dependency versions across supported package ecosystems, and repository hygiene issues.

Who operates SecureRepos?

SecureRepos is operated by Secure Repos. For account, billing, legal, or support questions, contact [email protected].

Does SecureRepos replace a security audit?

No. It is an automated scanning and workflow tool. It helps surface likely issues and keeps ownership visible, but findings still need human review before you treat them as confirmed vulnerabilities.

How does GitHub access work?

After email verification and checkout, users install the SecureRepos GitHub App and select repositories they are authorized to monitor. Each SecureRepos account is permanently linked to the first GitHub account it connects.

Do you store repository code?

The service uses GitHub App access to inspect repository content needed for scans. Repository code is processed for scanning and temporary scanner workspaces are removed after parsing. Scan results, finding metadata, selected file paths, and account activity are stored for your account. SecureRepos does not sell repository code.

How is SecureRepos different from GitHub dependency alerts?

Dependency alerts are useful, but they focus mainly on vulnerable packages. SecureRepos adds repository-level checks for secrets, CI/CD workflow risk, Docker and infrastructure configuration, repository hygiene, risk summaries, scan history, remediation context, CLI access, MCP access, and critical/high alert channels.

Can scans produce false positives?

Yes. Findings are generated by automated rules and need human review. A finding can be a real risk, an intentional configuration decision, or a false positive depending on the repository context.

Can another person use my account?

No. SecureRepos plans are designed for one developer account. Login credentials and account access should not be shared with another person.

How does billing work?

Checkout is handled by Paddle and requires a payment method to prevent abuse and keep private repository scanning sustainable. The 7-day Security Preview includes one repository and one limited scan. Unless cancelled, Paddle charges the card when the preview ends and the selected paid plan activates automatically.

Is the Security Preview a complete scan?

No. It checks a small default-branch sample and displays up to five sample findings, with useful context on the first high-value items. Full scheduled scanning, complete evidence, and plan-specific automation unlock with the paid subscription.

Can I cancel my plan?

If your plan renews, you can request cancellation through available account options or by contacting support. Cancellation stops future renewal according to checkout terms, but it does not automatically refund prior charges.

Do you offer refunds?

SecureRepos is a digital SaaS product. Once an account is activated and access is delivered, fees are generally non-refundable unless required by law or approved by support. Billing errors and duplicate charges can be reviewed by contacting support.

Can GitHub access be revoked?

You can remove or suspend the GitHub App installation from GitHub, but doing so stops repository sync and scans. The original GitHub account remains permanently bound to the SecureRepos account and cannot be replaced through self-service.

What happens if I choose more repositories than my plan allows?

Your plan controls how many active repositories can be monitored. If more repositories are available through GitHub, SecureRepos may keep only the allowed number active until your plan changes or more capacity becomes available.

How do I contact support?

Email [email protected] or use the contact form. Include your account email and repository name when the issue is account-specific.

Before you sign up

Open the demo before creating an account.

The demo shows the product shape without connecting a real repository.

View demo