Privacy

Privacy

This site collects nothing beyond ordinary server logs. The tool it describes uploads nothing at all. Both statements are short because they are complete.

Website hosting & server logs

This site is hosted on our own server infrastructure in the EU. When you visit, the web server processes the technical data your browser transmits (IP address, time of request, requested page, user agent) in standard server logs, used solely to operate and secure the site (legal basis: Art. 6 (1) f GDPR) and deleted on a short rotation.

There are no analytics, no tracking pixels, no cookies, and no embedded third-party scripts. Typefaces are self-hosted, so no requests are made to any font CDN. There are no forms and no accounts, so there is nothing to submit and nothing stored about you.

The tool itself

This is the part worth reading, because it is the one thing BlastRadius does that an ordinary program does not: it reads credentials.

  • There is no telemetry, and no server to report to. BlastRadius never transmits what it finds to anyone, including us. It is a command-line tool with no hosted component; a service that accepted other people's credentials would be the very thing this tool warns about.
  • Discovery is entirely offline. Scanning your working tree, dotfiles, environment and agent configuration happens on your machine. Nothing leaves it.
  • Resolution is opt-in and narrowly targeted. Only when you pass --resolve does the tool contact anything — and only the provider that issued each credential. Each provider module declares in advance which hosts it may contact, and a guard blocks every other destination and all plaintext HTTP, so a credential cannot be sent somewhere unexpected even by a faulty or malicious module.
  • Credentials are never written to disk and never printed. Everything user-facing is fingerprinted, and error messages are scrubbed before display so a secret cannot leak through a stack trace.

Your rights

Under the GDPR you may request access to, correction of, or erasure of personal data held about you, object to processing, or lodge a complaint with a supervisory authority. In practice the only such data is the server log described above. Contact details are in the imprint.

Back →