tanav.aiScanLeaderboardResearchBlogGet Started
Open appTry free scan →
Legal

Privacy Policy

Last updated: July 4, 2026

What Tanav is

Tanav ("we," "us," "our") operates an AI supply chain security platform that scans publicly available GitHub repositories, MCP servers, skill files, and related AI agent configuration for security findings, and provides organization-level scanning for connected GitHub accounts. This policy covers tanav.ai, app.tanav.ai, our API, our CLI, and our Claude/Claude Code plugin.

Data we collect

Public registry use (no account): looking up or requesting a scan of a public GitHub repository does not require an account. We log the repository identifier and scan results themselves — this data concerns public code, not you personally.

Waitlist / get-started requests: if you submit your email (directly, or via the Claude plugin's org-scan request) to be contacted about a private repository or organization scan, we store your email address, optional company information, and the source you came from (e.g. our marketing site or the Claude plugin) so we can follow up.

Connected GitHub accounts: if you connect your GitHub account via OAuth to scan your organization's repositories, we receive your GitHub login and the access needed to read the repositories you authorize. We do not request write access to your code.

Usage data: like most web services, we log standard technical data (IP address, request timestamps, error logs) for security and reliability purposes.

What we don't do

We don't sell your data. We don't use scanned repository content or your account data to train AI models. We don't share your email or account information with third parties except the infrastructure providers needed to operate the service (see below).

Where data is stored

Tanav runs on Google Cloud Platform — Cloud Run for application hosting, Cloud SQL (Postgres) for our database, and Firebase for authentication. Scanned public registry data is, by nature, about public code and is treated as such. Organization-scoped data (your GitHub org's scan results, findings, and account details) is isolated per organization and is not visible to other Tanav customers or to the public registry.

The Claude / Claude Code plugin specifically

The Tanav plugin for Claude and Claude Code has no login or account system of its own. It makes anonymous, unauthenticated requests to our public API on your behalf when you ask Claude to check or scan a repo.

If you ask the plugin to route a private repository or organization request to us, it will ask for your email and submit it to our waitlist as described above — the plugin itself never scans private code or requests any credentials from you.

Data retention

Public registry scan data is retained indefinitely, since it reflects the current and historical security posture of public code. Waitlist submissions and organization account data are retained for as long as your account is active, or until you request deletion.

Your choices

You can request access to, correction of, or deletion of your personal data (email, account information) by contacting us at the address below. Because public registry scan results describe publicly available code rather than personal data about you, deletion requests for registry entries are handled case by case.

Changes to this policy

We'll update the date at the top of this page when this policy changes. Material changes will be reflected here before they take effect.

Contact us

Questions about this policy or your data: admin@tanav.ai