ShipGate by ErmazDocs

Privacy Policy

Last updated: 15 September 2026

What ShipGate processes

Repository scans. ShipGate fetches metadata and a small number of files (workflows, manifests, security policy, README) from the GitHub repository you specify, evaluates them in memory, and returns the result to your browser. Repository contents are processed transiently to produce the gate result and are not retained after the scan completes.

Artifact scans (OSS licence gate and MPL evidence report). When you name a package or a release, ShipGate downloads that published artifact — an npm tarball from the npm registry, or a release asset from GitHub — and opens it in memory to inspect what it contains. Nothing is executed, nothing is written to disk, and the artifact bytes are discarded when the report is returned. The OSS gate may additionally fetch a component's LICENSE or NOTICE file from the unpkg CDN to check notice text. These artifacts are public packages, not your private code; the only thing you send us is the package name and version you asked about.

What ShipGate stores

What ShipGate does not do

Third parties

Depending on what you scan, ShipGate makes outbound requests to:

The service is hosted on Railway (subject to Railway's privacy policy), whose infrastructure logs standard request metadata (IP addresses, timestamps) for operations. ShipGate itself additionally keeps a short-lived in-memory count of recent requests per client address, solely to rate limit the endpoints that download remote artifacts; it is not persisted and not used for any other purpose.

Contact

Privacy questions: support@ermaz.app — ShipGate is operated by Ermaz LLC.