Last updated: 15 September 2026
Repository scans. ShipGate fetches metadata and a small number of files (workflows, manifests, security policy, README) from the GitHub repository you specify, evaluates them in memory, and returns the result to your browser. Repository contents are processed transiently to produce the gate result and are not retained after the scan completes.
Artifact scans (OSS licence gate and MPL evidence report). When you name a package or a release, ShipGate downloads that published artifact — an npm tarball from the npm registry, or a release asset from GitHub — and opens it in memory to inspect what it contains. Nothing is executed, nothing is written to disk, and the artifact bytes are discarded when the report is returned. The OSS gate may additionally fetch a component's LICENSE or NOTICE file from the unpkg CDN to check notice text. These artifacts are public packages, not your private code; the only thing you send us is the package name and version you asked about.
Depending on what you scan, ShipGate makes outbound requests to:
registry.npmjs.org) — package metadata and published tarballs, for the OSS licence gate and the MPL evidence report (subject to npm's privacy policy).unpkg.com) — component LICENSE/NOTICE files during an OSS repository scan.The service is hosted on Railway (subject to Railway's privacy policy), whose infrastructure logs standard request metadata (IP addresses, timestamps) for operations. ShipGate itself additionally keeps a short-lived in-memory count of recent requests per client address, solely to rate limit the endpoints that download remote artifacts; it is not persisted and not used for any other purpose.
Privacy questions: support@ermaz.app — ShipGate is operated by Ermaz LLC.