COPPICE

COPPICE

Third-party services

Last updated 23 August 2026

GitHub requires a list of third-party dependencies this app uses and shares data with. Coppice is not “None”.

GitHub

Identity and OAuth. We send you to GitHub to authorize Coppice. GitHub returns profile data and an access token. We call GitHub’s API to list repositories you can link, and — after you open Explore more — open pull requests, issues, and PR file names so we can overlay Coppice scan findings. Privacy: GitHub privacy statement.

TekReign

Coppice is a TekReign product. Support and company operations use tekreign.com and contact-us.

Vercel (when the public site is hosted there)

The Next.js landing may run on Vercel. Vercel receives HTTP requests, logs, and the usual hosting telemetry for that site. We do not send GitHub tokens to Vercel as a separate product integration; OAuth still completes through our Django API when DJANGO_ORIGIN is set. Privacy: Vercel privacy policy.

Cursor / VS Code (editor, not this website)

Scans run in the editor. Agent Scan uses Cursor’s agent SDK and is billed to your Cursor plan. Coppice does not ask for a Cursor API key on this website and does not proxy that key through GitHub.

OSV (Open Source Vulnerabilities)

The local engine may query OSV to match advisories to exact lockfile versions. That happens from your machine during a scan, not from GitHub OAuth. osv.dev

What we do not use

  • No second OAuth provider (no Google, no NextAuth-on-Vercel login).
  • No FastAPI beside Django.
  • No advertising SDKs.

Related: Privacy Policy · Terms