Last updated 8 September 2026
This describes what CavScope collects, who else it passes through, and why. It is written from what the software actually does, not from a template.
This is a factual disclosure of current data practices. It is not a lawyer-reviewed privacy policy and it does not attempt to state your rights under GDPR, UK GDPR, CCPA or any other regime. If you need a contractual or regulatory answer — a DPA, a subprocessor list with contractual guarantees, a retention commitment, a data-subject request procedure — ask us and we will route it to counsel rather than answer it here.
This site, muster.partners, has no forms, no analytics, no tag manager and no tracking pixels. It sets no cookies of its own and stores no session.
Three third parties see your IP address because your browser fetches files from them directly:
| Who | Why your browser contacts them |
|---|---|
| Google Fonts | The stylesheet and font files for the typefaces on this page. |
| jsDelivr | The Supabase JavaScript client bundle. |
| Vercel | Hosts and serves these pages. Standard server request logs. |
The page makes one call to our Supabase project to read the current published prices. It is an anonymous read of public data and it is configured not to persist a session.
Signing in at app.muster.partners creates an account record. What we hold is your email address, your organization and role, and sign-in timestamps. Authentication is handled by Supabase Auth; your session is stored in your own browser, per origin.
We do not ask for, and the software has no field for, a date of birth, a government identifier, a physical address, or a phone number.
CavScope assesses a website you tell it to assess. It requests pages the same way any anonymous visitor would, identifying itself as CavScope-Scanner/1.0, and it resolves public DNS records for the domain. It does not sign in, does not submit forms, and does not attempt to access anything a visitor could not reach.
What it stores as evidence for each finding:
robots.txt, the sitemap, and /.well-known/security.txtIf the scanned page contains personal data in its public HTML, an excerpt of that HTML may be stored as evidence. That is a consequence of quoting the page we assessed; we do not extract, index or separate personal data out of it.
| Processor | What it handles |
|---|---|
| Supabase | Database, authentication, and the scan engine. Findings, evidence and account records live here. |
| Resend | Email delivery: sign-in links, invitations, password resets, and risk alerts. |
| Stripe | Payments. Card details are entered on Stripe's pages and never reach us. |
| Vercel | Hosting for the pages you are reading. |
| OpenRouter → Anthropic | Findings text is sent to a Claude model to write the plain-English narrative on a SITREP. |
Generating the narrative section of a SITREP sends the findings for that scan — rule identifiers, severities, page URLs and the evidence excerpts they cite — to a language model through OpenRouter. If that is unacceptable for a given engagement, say so and we will turn narrative generation off for your organization; every finding, score and SITREP is produced by the deterministic engine and stands without it.
Access is enforced in the database itself with row-level security, not only in the interface. A signed-in user sees their own organization's websites, scans, findings and SITREPs, and nothing else. 28 Foot Systems staff with super-admin rights can access a tenant's workspace for support; when they do, it is recorded in an append-only audit log that names the administrator, the target, the stated reason and the time window.
Scan history is kept so that findings can be tracked over time — that is the product. We have not yet set a fixed retention period, and rather than publish a number we do not enforce, we will say so: ask and we will delete your organization's data.