Short version: the scan never leaves your machine, and paid verification sends counts, not credentials.
The blast CLI and MCP server scan locally and make no network calls. They report credential types, locations and fingerprints, never values. Nothing is uploaded and there is no telemetry. The npm launcher contacts npm and GitHub only to download the checksum-pinned binary.
When you run blast verify, abr.kloudle.dev receives the number of checks per type (for example aws-sts-identity:2), the blast version and the manifest schema it supports. It never receives credential values, profile names, environment variable names, file paths or scan output. The checks run on your machine.
For each claim we keep: claim id, pay code, check counts, price, state and timestamps, and once paid, the payment transaction id and payer address (both public on the Algorand blockchain). Paid claims are collectable for 30 days; claim records are deleted 90 days after payment or expiry. We keep a ledger of settlements (amount, transaction, payer, claim) to answer payment questions.
Payments are processed by the GoPlausible x402 facilitator and settled on Algorand. Browser wallet connections go through the wallet's own service (Pera and Defly use WalletConnect-style relays).
No cookies, no analytics scripts. The site runs on Cloudflare, which processes requests (including IP addresses) to serve and protect it; rate limiting uses IP addresses briefly and doesn't store them with claims.
Questions: open an issue or reach out on LinkedIn.