Last updated: May 28, 2026

Security Overview

Scanner-lite is designed for a low-friction security review by running inside the customer's own Databricks workspace and avoiding external data movement.

Security Commitments

Recommended Controls

Read-Only Scope

The scanner reads operational metadata from Databricks system tables and optional customer-provided BI metadata. It does not require production table data, cluster manage permissions, warehouse manage permissions, job edit permissions, dashboard edit permissions, or external network access.

Vulnerability Reports

Report suspected scanner package vulnerabilities to support@sig.ai. Include the package version, notebook step, and a redacted description of the issue. Do not include secrets, tokens, or sensitive customer telemetry.