> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deployment & data flow

> How each customer's Earnie environment is isolated, what stays inside it, and what it sends to SCANOSS and to other services.

Every customer gets an isolated Earnie environment, a deployment of its own that is separate from every other customer's. Your source code, the Earnie database, your scan archives, and your results stay in that environment.

To match your code against open source, Earnie sends fingerprints and hashes to the SCANOSS platform at `api.scanoss.com`. It never sends your source code there.

This page describes what runs in your environment, what leaves it, and why.

## What runs in your environment

Your environment runs all of Earnie:

* **The web app and the API.** Everyone in your organisation signs in to these, and the CLI, the pre-commit hook, CI pipelines, and coding agents connect to them over MCP.
* **The scanners.** Open-source matching, cryptography detection, and AI provenance each run as a separate scanner process. Your environment runs only the scanners your organisation has.
* **The database.** It holds your projects, findings, decisions, policies, approvals, and audit trail.
* **A data volume.** It holds the scan archives, which are the source each scan received, along with scan results and working caches.

Your source reaches Earnie in one of two ways. Earnie fetches it from a connected GitHub or GitLab repository, or a producer uploads it. Producers are the [Earnie CLI](/en/latest/earnie/using-earnie/earnie-cli), the pre-commit hook, and the upload in the web app. Either way, the source goes to your own environment and nowhere else.

## What leaves your environment

```mermaid theme={null}
flowchart LR
    subgraph ENV["<span style='color:#0B1F3A'>Your Isolated Earnie Environment</span>"]
        direction TB
        E1["Source code<br/>and scan archives"]
        E2["Database: findings,<br/>decisions, policies, audit"]
        E3["Scan results<br/>and evidence"]
    end

    ENV -- "Fingerprints and hashes,<br/>package identifiers" --> SC
    SC -- "Matches, licences,<br/>vulnerabilities, matched<br/>open-source file content" --> ENV

    subgraph SC["<span style='color:#0B1F3A'>SCANOSS Platform</span>"]
        direction TB
        S1["api.scanoss.com"]
    end

    ENV <-- "Source fetched in;<br/>checks and comments posted" --> GH["<span style='color:#0B1F3A'>Your GitHub<br/>or GitLab</span>"]

    style ENV fill:#FFF3EA,stroke:#FF6A1A,color:#0B1F3A
    style SC fill:#fff,stroke:#0B1F3A,color:#0B1F3A
    style GH fill:#fff,stroke:#0B1F3A,color:#0B1F3A
    style E1 fill:#FF6A1A,stroke:#E85D0F,color:#fff
    style E2 fill:#FF6A1A,stroke:#E85D0F,color:#fff
    style E3 fill:#FF6A1A,stroke:#E85D0F,color:#fff
    style S1 fill:#0B1F3A,stroke:#FF6A1A,color:#fff
```

Everything inside the orange box stays there. The arrows are the only traffic that crosses its edge.

### To the SCANOSS platform

| What Earnie sends | Why |
| - | - |
| **Fingerprints of each scanned file**, with the file's CRC64 checksum, its size, and its path within the project | To match your files against the SCANOSS knowledge base. The fingerprints are computed inside your environment. The path lets Earnie report each match against the right file. |
| **Package identifiers**, meaning package URLs and versions, of the components a scan found | To look up licences, vulnerabilities, component status, and available versions for those components. |
| **Package identifiers and version requirements of your dependencies**, where cryptography is enabled | To fetch the cryptography SCANOSS has already found in those packages, instead of analysing each one again. |
| **A fingerprint of each AI model file**, where AI provenance is enabled | To identify the model. The model file is fingerprinted inside your environment, then deleted. |
| **The hash of a matched open-source file**, when you open it in the Review Workspace | To fetch that open-source file's content for the side-by-side comparison. |

Two other things come back from SCANOSS:

* **Matched open-source file content.** When you compare a match side by side, your environment downloads the published open-source file from SCANOSS, by its hash. Only that public file travels, and only towards you. Your own file is read from your environment.
* **Detection rules.** Your environment downloads the cryptography detection rules from SCANOSS. Detection itself runs inside your environment.

### To other services

| Destination | What happens |
| - | - |
| **Your GitHub or GitLab** | Earnie fetches the source of the repositories you connected, using the access you granted. It posts its check, a summary comment, and inline comments on pull and merge requests. Those comments describe findings and verdicts. See [Connecting a repository](/en/latest/earnie/getting-started/connecting-a-repository). |
| **Public package registries** | Where cryptography is enabled, Earnie downloads your project's dependencies, such as source packages from Maven Central, to analyse the cryptography inside them. This runs in a sandbox whose network access is restricted to package registries. |
| **The CISA Known Exploited Vulnerabilities feed** | Earnie downloads the public list of known exploited vulnerabilities, once a day by default, to flag them on findings and in policies. Earnie sends nothing to CISA except the download request. |
| **Your identity provider** | If your organisation signs in with single sign-on, sign-in goes through your own identity provider. |

Earnie doesn't send your code, findings, or results to any AI model provider.

### Operational telemetry

SCANOSS monitors the health of your environment. To do this, your environment sends operational metrics to SCANOSS. These are counters, durations, and identifiers, such as how many scans ran and how long they took, labelled with your environment's name. They also include the host's CPU, memory, disk, and network usage.

The metrics contain no source code, file content, findings, or scan results. The metrics collector can't read your environment's configuration or secrets.

## What never leaves

* **Your source code.** It's fingerprinted inside your environment. Only the fingerprints and hashes described above reach SCANOSS.
* **Your findings, triage decisions, policies, and approvals.** They stay in your environment's database.
* **Your scan archives and results.** They stay on your environment's data volume.
* **Your SBOMs and other evidence.** They're generated inside your environment, and you decide where they go.

## What's next

* [Connecting a repository](/en/latest/earnie/getting-started/connecting-a-repository) lists the exact permissions Earnie asks your Git provider for.
* [Your first scan](/en/latest/earnie/getting-started/first-scan) shows how source reaches Earnie during a scan.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.