Latest incident:TanStack + @uipath mini-Shai-Hulud compromise (11 May 2026)
Privacy Policy

How we handle your data.

The headline: visiting and scanning are anonymous. Lockfiles are parsed in your browser and never leave your device. We only know who you are if you choose to tell us, for example by submitting an incident report with your name and email.

Last updated: 13 May 2026

1.Who we are

DependencyWatch.io is operated by Precursor Security, a UK-based cyber security company. Precursor Security is the data controller for personal data processed in connection with this Service. Our registered office is 55 St Paul's Street, Leeds, LS1 2TE, United Kingdom. For privacy enquiries, contact us at info@precursorsecurity.com.

2.Scanning is anonymous

When you paste or upload a lockfile, it is parsed and matched against our incident database entirely in your browser. The file is not transmitted to us, not logged, and not stored anywhere outside your device. We do not see your lockfile, the package names in it, or your scan results.

3.Analytics: Google Analytics and Microsoft Clarity

If you accept analytics on the cookie banner, we load Google Analytics and Microsoft Clarity. These help us understand how the Service is used (which pages get visited, which features get used, where people get stuck) so we can improve it. They collect aggregated, anonymous usage data, not your identity.

If you decline, neither service is loaded and no analytics data is collected. You can change your mind any time by clearing site data for DependencyWatch.io in your browser.

4.When you submit an incident report

If you use the submission form, we process the information you send us: the incident details, and (if you choose to provide them) your name and email. We use this information to triage the report, publish it to the public incident feed if it checks out, and credit or reply to you if you asked us to. Your name and email are kept only while we need them for those purposes and can be removed on request.

5.Cookies

We set one essential cookie (dw_cookie_consent) to remember your cookie-banner choice. Beyond that, only the cookies set by Google Analytics and Microsoft Clarity, and only if you have accepted them.

We do not use cookies for advertising, profiling, or to share data with ad networks. We do not sell personal data.

6.Your rights

Under the UK GDPR you have the right to ask us for a copy of your personal data, to have it corrected or deleted, to restrict or object to its processing, to withdraw consent (for example, to analytics) at any time, and to complain to the UK Information Commissioner's Office at ico.org.uk/concerns. To exercise any of these rights, email us at info@precursorsecurity.com.

7.Changes to this notice

We may update this notice from time to time. The updated version will be identified by a revised “Last updated” date and takes effect as soon as it is posted.

8.Contact

For any privacy enquiry, email info@precursorsecurity.com, call +44 (0) 113 328 1626, or write to Leeds HQ, 55 St Paul's Street, Leeds, LS1 2TE, United Kingdom.

See also our Terms of Service.