01 Your SBOM is read in your browser
The file goes into a Web Worker on your machine, is turned into a list of
package URLs, and is dropped. It is never sent anywhere — not to us, not to a
parsing service, not to anyone. There is no upload endpoint to point at,
because there is no upload.
02 Your deck lives in the URL, after the #
The deck link is the list of card ids, encoded into the fragment of the
URL. Browsers never send the fragment to a server — not to us, not to a
proxy, not to whoever hosts the page. Open the link and the page decodes it
locally.
03 There is no server to store anything
This site is static files. There is no database, no session, no endpoint
that accepts a deck. Nothing you build here is written anywhere but your own
address bar, and it is gone when you close the tab.
04 No accounts, no cookies, no identifiers
There is nothing to log in to. The Deck Builder sets no cookies, uses no
local storage, runs no analytics script, and does no fingerprinting. Two
decks built on the same machine an hour apart are, to us, two unrelated
events.
The parts we cannot promise away
Two things do leave your machine, and you should know what they are.
Your package list goes to OSV.dev. That is how a component
becomes a vulnerability ID, and it happens directly from your browser to
osv.dev — with no credentials and no referrer, and without passing through us.
We never see it. OSV.dev is a Google-operated open-source project with
its own policies, and it does see
which packages you asked about.
The page fetches each card it shows. A deck of forty cards is
forty requests for /card/…json, and the web server
that hosts this site keeps the ordinary access log every web server keeps: an
address, a time, a path. That is the same trace anyone browsing the card
database leaves, and it is the only trace a deck leaves. We add nothing to
it — no identifier, no cookie, nothing that ties one request to the next.
A deck link is a link. Anyone you hand it to sees the same
deck. It is not secret — treat it like the vulnerability list it is.
How to check
Open your browser's network tab and build a deck. You will see requests to
osv.dev and to /card/…json, and nothing that carries
your file or your deck. The code is
public:
the parser is in deck/sbom/, the fragment codec in
deck/encode.ts, and the tests that hold both to it
are in tests/.