Privacy note
A short, plain description of what code Nordik Audit receives, who processes it and when it is deleted.
Who we are
Nordik Audit is a code audit service. Contact is by email only: outreach@getnordik.com.
What code we receive
- One JavaScript or TypeScript repository, as one Git bundle file, at one exact commit that you name by its full commit ID. Nothing is uploaded to an account, and we need no access to your GitHub account, no token and no write access.
- A bundle holds only committed history. A git-ignored
.envfile stays on your machine. A secret that was committed earlier is in the history, and the audit checks for it. - Please remove database dumps, user exports and real customer records before you make the bundle. Anything sent beyond the bundle (a live
.env, credentials, customer data) is not used, is deleted, and you are told. - We never run your code, and we never need production, hosting or database access.
How it is processed
This is the consent you agree to before anything is sent:
To deliver this service we send your repository at the named commit, in whole or in part, to Anthropic (Claude), the only AI model provider Nordik uses for this service. The AI reviewer can read the files checked out from your snapshot directly, so a credential committed in your code may reach the provider even though Nordik masks secret-shaped values in the excerpts it places in prompts. The provider handles this content under the terms of the account plan Nordik uses and may keep it for a limited period as those terms describe. The operator of Nordik has confirmed that those plan terms permit this commercial use; Nordik does not itself promise anything about the provider's retention or use of the content beyond what those terms say. We do not send it to anyone else. If you do not agree, we cannot do the audit.
The report is produced with AI (Claude). A person releases it to you. Dependency checking uses a public advisory snapshot matched offline; nothing about your repository is sent for that step.
How long we keep it, and what is deleted
- The bundle file is deleted automatically as soon as it is unpacked. If we decline your repository, it is deleted at once and no audit is made.
- Our working copy, the findings, AI session transcripts and the report are kept for 30 days after the report is released, then deleted. Our own backups do not contain audits.
- Email: an attachment is deleted from the mailbox and its deleted-items folder by the same date. Messages that hold no code stay as the business record.
- A short record remains after deletion: an internal ID, the release and deletion dates, and fingerprints (hashes) of the report and of any fixes we delivered. It holds none of your code, findings, fixes or report text.
Not covered: copies you or anyone else saved, copies held by your email or file-storage provider, and the AI provider's own retention, which follows its terms. We do not promise erasure beyond what we control.
Payment
Payments are handled by Stripe. We do not see or store your card details.
This website
This site is a static page. It sets no cookies, loads no analytics or trackers, and has no forms. Whoever hosts the site (Cloudflare) may keep ordinary technical request logs, as any web host does.
Questions
Email outreach@getnordik.com.
Last updated: October 2026.