Privacy policy

Local analysis should stay local.

This notice explains what Developer Defence keeps on your device, what limited information reaches our service, and the choices available to you.
Effective:
23 July 2026
Controller:
Jam Data Solutions Ltd

Scope and controller

This policy covers the Developer Defence desktop application and the public website and service at developerdefence.com.
Developer Defence is operated by Jam Data Solutions Ltd, company number 14075684, of 102-116 Windmill Road, Croydon, England, CR0 2XQ. Jam Data Solutions Ltd is the data controller for the personal data described here.
The current scanner does not upload your source code, local package inventory, project paths, lockfiles, findings, scan history, or vault contents to Developer Defence.

Data kept on your device

Package discovery and vulnerability matching run on your computer. The application reads directory metadata and supported package manifests or lockfiles inside the scan boundaries you configure.
The mutable application-state PersonalDB stores information needed to operate the app, including:
  • scan roots, exclusions, traversal limits, schedule, and ecosystem choices;
  • discovered projects, package coordinates, local occurrences, findings, suppressions, and scan history;
  • intelligence release identifiers and digests used for each finding;
  • application preferences and pseudonymous device-authority state.
A separate, read-only PersonalDB contains signed threat intelligence. Encryption and device signing keys are stored through the operating system's secure credential store. Where protected paths and vaults are available, vault contents remain encrypted locally and are not sent to our service.

Data sent to our service

The application makes bounded network requests for device authority, signed intelligence updates, downloads, and features you explicitly request.
  • Data
    Pseudonymous device data
    Purpose and legal basis
    A random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service.
    When
    On first enrolment and credential refresh.
  • Data
    Intelligence request data
    Purpose and legal basis
    Requested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests.
    When
    When checking for or downloading updates.
  • Data
    Optional email notices
    Purpose and legal basis
    If you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent.
    When
    Only after you submit the form.
  • Data
    Support communications
    Purpose and legal basis
    Your email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product.
    When
    When you contact support.
Data
Purpose and legal basis
When
Pseudonymous device data
A random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service.
On first enrolment and credential refresh.
Intelligence request data
Requested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests.
When checking for or downloading updates.
Optional email notices
If you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent.
Only after you submit the form.
Support communications
Your email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product.
When you contact support.
Standard network infrastructure may necessarily process your IP address to deliver a response. We do not use device enrolment or intelligence requests to create advertising profiles.

Website analytics and storage

Optional analytics are off until you choose Allow analytics. If you allow them, the site loads Google Tag Manager, which may enable configured analytics tags to process page URLs, referral information, browser and device details, approximate location derived from IP address, and analytics identifiers.
Your choice is stored in local browser storage under developer-defence-analytics-consent-v1. Selecting Continue without analytics does not limit the website. You can withdraw or change the choice using the Cookie settings button on this page or in the footer.
Essential delivery logs may still record IP address, request time, requested path, user agent, and response status for security and reliability.

Sharing and international transfers

We use service providers for infrastructure, release distribution, email delivery, error investigation, and consented website analytics. They process data only for the relevant service and under their own contractual and legal obligations.
Signed application installers may be delivered through our download proxy from private GitHub releases. Google may process consented website analytics in countries outside the United Kingdom. Where personal data is transferred internationally, we use an applicable adequacy decision or approved contractual safeguards.
We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate confidentiality safeguards. We do not sell personal data.

Retention and deletion

Local scanner data remains on your device until you remove it through the product or uninstall and delete its application data. Secure credential items may require separate removal through the operating system credential manager.
We retain active device-authority records while a device is enrolled, with limited security and audit records retained only as needed to prevent replay, investigate abuse, meet legal obligations, and prove revocation. Operational request logs are retained for a limited period based on security and reliability needs.
Email subscriptions remain active until you withdraw consent or the requested notice has been delivered and no continuing purpose remains. Support records are kept for as long as needed to resolve the request, maintain an appropriate history, and meet legal obligations.

Your choices and rights

Depending on where you live, you may have rights to access, correct, erase, restrict, or receive personal data, and to object to certain processing. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
  • Change scan roots, exclusions, schedules, and intelligence ecosystems in the app.
  • Decline or reset optional website analytics.
  • Ask us to unsubscribe an email address.
  • Request access to or deletion of cloud-held device or account information.
Contact [email protected] to exercise a right. We may need to verify that you control the relevant device, account, or email address. You may also complain to the UK Information Commissioner's Office.

Security

Developer Defence separates mutable local state from signed read-only intelligence. Intelligence metadata and application release descriptors are verified against trusted signing keys before activation. Device private keys and local encryption keys are kept in operating-system secure storage, and network requests use encrypted transport.
No system can guarantee absolute security. If you believe you found a security issue, contact [email protected] with the subject Security report. Do not include live credentials, private source code, or exploit data that could put others at risk.

Changes and contact

We will update this page when our data practices materially change and revise the effective date above. Material changes will be explained in the application or on this site where appropriate.
Jam Data Solutions Ltd, trading as Developer Defence
Company number 14075684
102-116 Windmill Road, Croydon, England, CR0 2XQ
Privacy and support: [email protected]

Scope and controller

This policy covers the Developer Defence desktop application and the public website and service at developerdefence.com.
Developer Defence is operated by Jam Data Solutions Ltd, company number 14075684, of 102-116 Windmill Road, Croydon, England, CR0 2XQ. Jam Data Solutions Ltd is the data controller for the personal data described here.
The current scanner does not upload your source code, local package inventory, project paths, lockfiles, findings, scan history, or vault contents to Developer Defence.

Data kept on your device

Package discovery and vulnerability matching run on your computer. The application reads directory metadata and supported package manifests or lockfiles inside the scan boundaries you configure.
The mutable application-state PersonalDB stores information needed to operate the app, including:
  • scan roots, exclusions, traversal limits, schedule, and ecosystem choices;
  • discovered projects, package coordinates, local occurrences, findings, suppressions, and scan history;
  • intelligence release identifiers and digests used for each finding;
  • application preferences and pseudonymous device-authority state.
A separate, read-only PersonalDB contains signed threat intelligence. Encryption and device signing keys are stored through the operating system's secure credential store. Where protected paths and vaults are available, vault contents remain encrypted locally and are not sent to our service.

Data sent to our service

The application makes bounded network requests for device authority, signed intelligence updates, downloads, and features you explicitly request.
  • Data
    Pseudonymous device data
    Purpose and legal basis
    A random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service.
    When
    On first enrolment and credential refresh.
  • Data
    Intelligence request data
    Purpose and legal basis
    Requested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests.
    When
    When checking for or downloading updates.
  • Data
    Optional email notices
    Purpose and legal basis
    If you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent.
    When
    Only after you submit the form.
  • Data
    Support communications
    Purpose and legal basis
    Your email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product.
    When
    When you contact support.
Data
Purpose and legal basis
When
Pseudonymous device data
A random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service.
On first enrolment and credential refresh.
Intelligence request data
Requested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests.
When checking for or downloading updates.
Optional email notices
If you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent.
Only after you submit the form.
Support communications
Your email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product.
When you contact support.
Standard network infrastructure may necessarily process your IP address to deliver a response. We do not use device enrolment or intelligence requests to create advertising profiles.

Website analytics and storage

Optional analytics are off until you choose Allow analytics. If you allow them, the site loads Google Tag Manager, which may enable configured analytics tags to process page URLs, referral information, browser and device details, approximate location derived from IP address, and analytics identifiers.
Your choice is stored in local browser storage under developer-defence-analytics-consent-v1. Selecting Continue without analytics does not limit the website. You can withdraw or change the choice using the Cookie settings button on this page or in the footer.
Essential delivery logs may still record IP address, request time, requested path, user agent, and response status for security and reliability.

Sharing and international transfers

We use service providers for infrastructure, release distribution, email delivery, error investigation, and consented website analytics. They process data only for the relevant service and under their own contractual and legal obligations.
Signed application installers may be delivered through our download proxy from private GitHub releases. Google may process consented website analytics in countries outside the United Kingdom. Where personal data is transferred internationally, we use an applicable adequacy decision or approved contractual safeguards.
We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate confidentiality safeguards. We do not sell personal data.

Retention and deletion

Local scanner data remains on your device until you remove it through the product or uninstall and delete its application data. Secure credential items may require separate removal through the operating system credential manager.
We retain active device-authority records while a device is enrolled, with limited security and audit records retained only as needed to prevent replay, investigate abuse, meet legal obligations, and prove revocation. Operational request logs are retained for a limited period based on security and reliability needs.
Email subscriptions remain active until you withdraw consent or the requested notice has been delivered and no continuing purpose remains. Support records are kept for as long as needed to resolve the request, maintain an appropriate history, and meet legal obligations.

Your choices and rights

Depending on where you live, you may have rights to access, correct, erase, restrict, or receive personal data, and to object to certain processing. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
  • Change scan roots, exclusions, schedules, and intelligence ecosystems in the app.
  • Decline or reset optional website analytics.
  • Ask us to unsubscribe an email address.
  • Request access to or deletion of cloud-held device or account information.
Contact [email protected] to exercise a right. We may need to verify that you control the relevant device, account, or email address. You may also complain to the UK Information Commissioner's Office.

Security

Developer Defence separates mutable local state from signed read-only intelligence. Intelligence metadata and application release descriptors are verified against trusted signing keys before activation. Device private keys and local encryption keys are kept in operating-system secure storage, and network requests use encrypted transport.
No system can guarantee absolute security. If you believe you found a security issue, contact [email protected] with the subject Security report. Do not include live credentials, private source code, or exploit data that could put others at risk.

Changes and contact

We will update this page when our data practices materially change and revise the effective date above. Material changes will be explained in the application or on this site where appropriate.
Jam Data Solutions Ltd, trading as Developer Defence
Company number 14075684
102-116 Windmill Road, Croydon, England, CR0 2XQ
Privacy and support: [email protected]