Data Handling — AppHandoff Documentation

AppHandoff processes your source code during scans but does not store raw code after analysis is complete. The scanner extracts structural metadata, such as endpoint paths, parameter names, and response shapes, and discards the source files. Mismatch reports reference file paths and line numbers but do not embed code snippets.

All data is encrypted in transit via TLS 1.2 or higher and at rest using AES-256 encryption provided by the underlying database and storage services. Project data is isolated per account. Deleting a project permanently removes all associated scan results, tickets, and metadata within thirty days.