Accounts
Login sessions use secure, HTTP-only cookies. New accounts must verify their email, and sensitive actions are rate-limited.
Pallos is built to inspect the parts you choose without claiming more access—or more certainty—than the first version actually has.
Login sessions use secure, HTTP-only cookies. New accounts must verify their email, and sensitive actions are rate-limited.
Supabase Row Level Security separates account data. Private monitor header values are encrypted with AES-256-GCM before storage.
Pallos requests read-only repository contents and metadata for repositories you select. Short-lived installation tokens are created when needed; permanent GitHub access tokens are not stored.
Pallos makes server-side HTTPS requests, blocks local and private network destinations, caps response size and time, and never sends saved credentials to a different host.
You can disconnect GitHub and remove Pallos webhooks and scan records, or permanently delete your account and associated product data.
Login, connection, scan, monitor-change, and deletion events are recorded for review. IP addresses are hashed instead of stored as plain text.
Pallos V1 uses focused, deterministic checks. A clean result does not prove that an app is secure, compliant, or free from vulnerabilities.
Pallos does not modify repository files, deploy code, approve fixes automatically, or replace a professional penetration test or security review.
API monitoring compares JSON response structure and availability. It does not inspect every business rule, authorization path, or downstream service.
Send security and privacy questions to pallosagent@gmail.com. Please do not include passwords, API keys, or customer data.