api.scanoss.com. It never sends your source code there.
This page describes what runs in your environment, what leaves it, and why.
What runs in your environment
Your environment runs all of Earnie:- The web app and the API. Everyone in your organisation signs in to these, and the CLI, the pre-commit hook, CI pipelines, and coding agents connect to them over MCP.
- The scanners. Open-source matching, cryptography detection, and AI provenance each run as a separate scanner process. Your environment runs only the scanners your organisation has.
- The database. It holds your projects, findings, decisions, policies, approvals, and audit trail.
- A data volume. It holds the scan archives, which are the source each scan received, along with scan results and working caches.
What leaves your environment
Everything inside the orange box stays there. The arrows are the only traffic that crosses its edge.To the SCANOSS platform
Two other things come back from SCANOSS:
- Matched open-source file content. When you compare a match side by side, your environment downloads the published open-source file from SCANOSS, by its hash. Only that public file travels, and only towards you. Your own file is read from your environment.
- Detection rules. Your environment downloads the cryptography detection rules from SCANOSS. Detection itself runs inside your environment.
To other services
Earnie doesn’t send your code, findings, or results to any AI model provider.
Operational telemetry
SCANOSS monitors the health of your environment. To do this, your environment sends operational metrics to SCANOSS. These are counters, durations, and identifiers, such as how many scans ran and how long they took, labelled with your environment’s name. They also include the host’s CPU, memory, disk, and network usage. The metrics contain no source code, file content, findings, or scan results. The metrics collector can’t read your environment’s configuration or secrets.What never leaves
- Your source code. It’s fingerprinted inside your environment. Only the fingerprints and hashes described above reach SCANOSS.
- Your findings, triage decisions, policies, and approvals. They stay in your environment’s database.
- Your scan archives and results. They stay on your environment’s data volume.
- Your SBOMs and other evidence. They’re generated inside your environment, and you decide where they go.
What’s next
- Connecting a repository lists the exact permissions Earnie asks your Git provider for.
- Your first scan shows how source reaches Earnie during a scan.