Product data handling
What happens to a credential finding
From a connected source to an owner review, and what an organization deletion request actually removes.
This note describes the current application behavior. It does not replace your agreement, privacy notice, or a security assessment for your deployment.
Follow the record
- 01
Connected source
Cremit scans connected sources and, when enabled, monitored external assets.
- 02
Protected finding
A detected value is encrypted; a masked version and the finding context are stored for review.
- 03
Scoped review
Organization permissions govern actions. The public finding API returns a masked value.
- 04
Owner action
An owner acts at the issuer. An organization deletion request starts a separate seven-day restore window.
What the finding contains
A finding is useful only when its evidence and limits travel together.
Location and status
The record connects a detected credential to its observed locations and verification state. A pattern match alone does not prove that a key still works or was misused.
Encrypted value, masked display
The detection worker encrypts credential values through KMS and stores a separate masked representation. The public finding API serializes the masked value and excludes the encrypted payload and key identifiers.
Supported checks
Issuer-side validity checks apply only to supported credential types. AWS access-key and GCP API-key permission analysis requires the relevant integration; neither result proves that a key was abused.
Organization deletion has two stages
The current product keeps a restoration period. Deletion from the console is not immediate physical erasure.
- 01
Request and restore window
An authorized owner requests deletion. The organization is marked deleted, active access is removed, and the owner may restore it during the following seven days.
- 02
Scheduled local purge
After that window, a scheduled process hard-deletes the local organization graph and associated organization-scoped OAuth state. The request itself does not perform that purge.
What this action does not do
- 01
Deleting a Cremit organization does not revoke a credential at its issuer or erase copies in connected repositories and services. The owner handles those separately.
- 02
Database backups follow a separate retention lifecycle. This page does not promise a fixed backup expiry or row-by-row removal from snapshots; request the current terms for your deployment.
- 03
This page does not claim SOC 2 or ISO 27001 certification, a universal recovery target, or a fixed patch or penetration-test schedule. Ask for current evidence when those controls matter to your review.