pg-checkup
Workspace
HomeReports
Learn
OverviewQuickstartChecks referenceConnectingTools that helpSecurity & privacyFAQ
Help
File a ticketRequest a featurePricing
PrivacyTerms
Docs/Security & privacy
Sign inNew checkupC

Security & privacy

What we read

Checkups read only PostgreSQL statistics and catalog views (for example pg_stat_activity, pg_stat_user_tables, pg_stat_statements, pg_replication_slots, pg_policies). A checkup never reads the contents of your tables.

Setting values whose names suggest secrets (for example archive_command, primary_conninfo, anything containing password, secret, token or key) are shown as (hidden), and string literals in running-query text are masked. We never display an archive command, only which tool it uses.

Findings can include object names (tables, indexes, roles) and normalized query text from pg_stat_statements, which may reveal schema details.

Encryption in transit

For remote hosts the scanner requests TLS by default. With no sslmode in your connection string the certificate is not verified, so traffic is encrypted but the server's identity isn't authenticated. Set sslmode yourself for stricter behaviour.

Read-only guarantee

Each scan session runs SET default_transaction_read_only = on. Combined with a pg_monitor-only role, the scan cannot modify data.

What we store

  • Connection string: used to run one scan, held in memory, never written to disk or logs. Errors are redacted before display.
  • Scan results (findings and evidence): stored under an unguessable link: 7 days without an account, 30 days with a free account, and permanently once you unlock it (until you delete it or your account). Anyone with the link can view it, so treat it like a secret.
  • Accounts: email, an optional name, and either a salted password hash (scrypt) or your GitHub/Google id. Sessions are stored hashed. You can delete your account, reports and sign-in details from the Account page.
  • Payments: handled by Paystack. We never see card details.
  • Waitlist: your email, only if you join.

Recommendations

  • Create a dedicated role and rotate its password after use.
  • Restrict the role to specific databases where you can.

Reporting a vulnerability

Email [email protected]. Please do not test against databases you do not own.

PreviousTools that helpNextFAQ