Pallos AgentBack to Pallos
SECURITY AT PALLOS

Useful access. Clear boundaries.

Pallos is built to inspect the parts you choose without claiming more access—or more certainty—than the first version actually has.

Last reviewed August 11, 2026

Accounts

Login sessions use secure, HTTP-only cookies. New accounts must verify their email, and sensitive actions are rate-limited.

Stored data

Supabase Row Level Security separates account data. Private monitor header values are encrypted with AES-256-GCM before storage.

GitHub access

Pallos requests read-only repository contents and metadata for repositories you select. Short-lived installation tokens are created when needed; permanent GitHub access tokens are not stored.

API monitoring

Pallos makes server-side HTTPS requests, blocks local and private network destinations, caps response size and time, and never sends saved credentials to a different host.

Your control

You can disconnect GitHub and remove Pallos webhooks and scan records, or permanently delete your account and associated product data.

Account history

Login, connection, scan, monitor-change, and deletion events are recorded for review. IP addresses are hashed instead of stored as plain text.

HONEST LIMITS

What Pallos does not promise

Pallos V1 uses focused, deterministic checks. A clean result does not prove that an app is secure, compliant, or free from vulnerabilities.

Pallos does not modify repository files, deploy code, approve fixes automatically, or replace a professional penetration test or security review.

API monitoring compares JSON response structure and availability. It does not inspect every business rule, authorization path, or downstream service.

QUESTIONS OR REPORTS

Tell us if something looks wrong.

Send security and privacy questions to pallosagent@gmail.com. Please do not include passwords, API keys, or customer data.