Security
This page is not legal advice, not a promise of a refund, and not a guarantee that any migration is safe.
Vercel Deployment Protection stays enabled. Sunset does not turn it off. A paid report is unlocked only after the server reads the Checkout Session from Stripe and the stored snapshot matches that session.
Webhook deliveries are accepted only with a valid Stripe signature. A delivery does not unlock a report by itself. Replays of the same event id are recorded once when the database is configured. A database failure on that receipt returns an error and does not grant access.
Public GitHub repositories are read with GET requests and no token. A private repository uses SUNSET_GITHUB_TOKEN only, as a read-only credential for Sunset. The token is not written into reports. Sunset does not push, open pull requests, or run repository code.
A test Stripe key accepts only Stripe objects with livemode false. A live Stripe key accepts only Stripe objects with livemode true. The stored report has to be the same mode as the Checkout Session. A mismatched mode does not unlock the report.
Contact
Security and support mail goes to support@sunsetscanner.com.