Privacy notice
Last updated: 29 August 2026
quantsec.pro is a cryptographic bill of materials and quantum-readiness scanner operated by NeoTechAdmin. This notice explains what the service does with what you give it. It describes the service as it is actually built, not as a general statement of intent.
Who is responsible
NeoTechAdmin is the controller for the processing described here. For any privacy question, or to exercise any of the rights below, contact [email protected].
What you submit for scanning
Depending on the source type you choose, the service receives a repository URL, a website URL, a container image reference, or a file you upload (a source archive or a container image tarball). That content is written to temporary storage on our infrastructure, scanned, and used to produce your CBOM and report.
Do not submit anything you are not entitled to have scanned. If a repository or archive contains personal data, or third-party code you do not have rights to, you are responsible for that decision. The scanner reads whatever you point it at.
What the CBOM and report contain. The output describes cryptography, not content: algorithm names and primitives, key sizes, padding, certificate details such as issuer, subject, serial number and validity dates, and the public keys contained in those certificates. Where a private key or a secret is detected, the output records only that one was found, its type and size, and the path of the file it was found in — never the key or secret itself. File paths from an archive you upload do appear in the CBOM, and a path can itself carry personal data, so this is worth knowing before you upload.
A limit on erasure and access requests we would rather state than leave implied. If personal data is buried inside a repository or archive you upload, we have no realistic way to find it, identify whose it is, or extract it in response to a request — we hold that content as an opaque payload for the length of a scan, and we do not index it by person. The mitigation is that we do not keep it: uploads and their artifacts are deleted automatically within 1 to 1.5 hours, so inside that window the data is gone regardless of whether anyone asks. If you believe personal data of yours was submitted by someone else, contact us and we will do what we can, but the honest answer is usually that the retention window has already dealt with it.
Access tokens and credentials
If you supply a personal access token to clone a private repository, it is treated as write-only. It is passed to the component that performs the clone, held in memory for at most fifteen minutes, used once, and discarded. It is never written to a database, never included in a stored URL, never returned to your browser, and never written to a log file. Leaving the page before submitting discards it.
How long anything is kept
- Scan artifacts (your CBOM, HTML/PDF report, and the job record shown in the interface) are deleted automatically within 1 to 1.5 hours.
- The working copy of a clone or an extracted upload is deleted as soon as the scan finishes, whether it succeeded or failed. The file you uploaded goes with it: nothing reads it once the scan is over, so it is not kept for the window above.
- Access tokens are held for a maximum of fifteen minutes, as described above.
- Operational logs record that a scan ran and whether it succeeded. They deliberately exclude tokens, authorisation headers, credential-bearing URLs and the content of what you submitted.
Your IP address
Your IP address is processed for two purposes: rate limiting, so that one visitor cannot exhaust the service for everyone, and ordinary network security and abuse prevention. It is read from the connection and from the forwarding headers added by our content delivery network, and is held only for as long as the rate-limiting window requires.
Because the service sits behind Cloudflare, Cloudflare also processes your IP address as part of delivering and protecting the site. If you accept analytics, Google also receives your IP address.
Cookies and local storage
| Name | Type | Purpose | Optional? |
|---|---|---|---|
| qs-notice-ack | Local storage | Records that you have seen this notice, so it is not shown on every visit. | No — required before a scan can be submitted |
| qs-consent | Local storage | Remembers your choice on this banner so you are not asked again. | No — it exists only to honour your choice |
| qs-theme | Local storage | Remembers light or dark appearance. | No — a display preference, not tracking |
| _ga, _ga_* | Cookie (Google) | Google Analytics: which pages are visited, and roughly how often. | Yes — set only if you accept |
Analytics are off until you opt in, and opting in is not a condition of using the scanner — you can decline and scan exactly as normal. Until you opt in, nothing is requested from Google at all: the analytics script is not loaded, not merely restricted. No Google cookie is set and no request is made.
Acknowledging this notice is separate, and is required before a scan can be submitted. That is a confirmation that you have been told what happens to what you send us — not consent to analytics, which stays optional either way.
Why we are allowed to do this
- Running your scan — performance of the service you asked for, and our legitimate interest in providing it.
- Rate limiting and abuse prevention — our legitimate interest in keeping the service available and secure.
- Sign-in — performance of the service, where you choose to use it.
- Analytics — your consent, which you can withdraw at any time.
Who else is involved
Cloudflare provides content delivery and denial-of-service protection, and therefore processes traffic to this site. Google provides analytics, but only if you accept. We do not sell personal data, and we do not use what you submit for scanning to train anything or to build a profile of you. Processing takes place on infrastructure we operate; Cloudflare and Google are international providers and may process data outside your country.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to object to or restrict processing, to receive it in a portable form, and to withdraw consent for analytics at any time. Because scan artifacts are deleted within 1 to 1.5 hours and tokens within fifteen minutes, there is usually very little left to act on. Note the limit described under “What you submit for scanning”: personal data inside an upload is not something we can search for or extract on request, and the retention window is the mitigation. Write to [email protected] and we will respond.
Security
Traffic is served over HTTPS. Uploads are treated as hostile and extracted under strict limits on path, size and compression ratio. The component that inspects container images is isolated from the host. Credentials are excluded from logs by design rather than by convention.
Changes
If this notice changes materially, the date above changes with it, and the banner is shown again where the change affects what you consented to.