CodanopySecurity scanning for AI-generated apps
FAQ

Questions people ask before scanning

Is the scan actually free?

Yes, every time, no card required. The score, the summary, and the severity breakdown cost nothing to run or to see. Payment only unlocks the finding-by-finding explanations and fix prompts — it never gates the scan itself.

Does Codanopy store my code?

We keep the problematic code sections until the solution report is provided, or for one week at most. Your repository itself is never stored. We clone or extract your source into a temporary directory, analyse it, and delete that directory when the scan ends. The only fragments kept afterward are the specific lines each finding refers to, needed to write a useful fix prompt — deleted as soon as your unlocked report is delivered, or after seven days, whichever comes first.

What happens to a ZIP I upload?

It's extracted into a scan-scoped temporary directory with the same abuse guards as any other upload target: a 50 MB compressed size cap, rejection of entries that try to write outside that directory, a decompression limit, and an extraction timeout. It's deleted along with everything else once the scan completes.

How much does it cost to unlock a report?

$49, once, per report. It's not a subscription and not metered — one payment unlocks every finding's explanation and fix prompt for that report, permanently.

What's the refund policy?

Ask within 14 days of paying and you get a no-questions refund. A refund re-locks the report to its free teaser state — you're un-buying it, not keeping the unlocked version and the money. It's one no-questions refund per customer; after that we read the request first. If Codanopy fails to deliver what you paid for, you're refunded without needing to ask.

Do I need an account?

No. There's no signup, no password, and no dashboard. Your email address is only a delivery address for your report link and, if you pay, for the unlock notification.

Who can see my report?

Anyone with the link, and only people with the link. Report URLs are public but unlisted — they're excluded from search engines with a noindex directive and from robots.txt — so treat the link itself as the credential it is.

Is there a limit on how many scans I can run?

Yes, to keep the free scan sustainable: a per-IP limit and a per-email limit, plus a shared daily cap across all users. If a repository was already scanned recently, a repeat submission reuses that existing report instead of re-scanning.

Is a Codanopy report a full security audit?

No. It's an automated review, not a guarantee — a clean score means nothing was found, not that nothing exists to find. For anything handling money or sensitive data, treat it as a fast first pass, not a replacement for a human look. If your report has critical findings, you can order a review by the person who built Codanopy straight from it.

Can a person review my code?

Yes. When a report has critical findings, it offers a $300 review by the person who built Codanopy: your code read by hand — how auth and data access work across files, and the business logic scanners can't see — delivered as a written report and a 45-minute Loom walkthrough within 5 business days. No calls, and the full report unlock is included (if you already paid $49, it is credited). After checkout you invite a GitHub account to the repo or send a zip.

More detail on data handling lives in the short data-handling summary, the Terms of Service, and the Privacy Policy.