inspect.software

Contact

How to reach inspect.software — certification enquiries, data corrections, security disclosures, and general questions.

Updated 2026-08-25

The channels below route to the people who operate inspect.software directly.

Certification and commercial enquiries

Private repository audits, on-demand certification, monitoring, and enterprise reporting: mail@inspect.software

The available services and the rules they operate under are described on the certification & pricing page — including the rule that payment never changes a result.

Data corrections

A factual error in a published report — a mismatched package, stale evidence, a value that cannot be reproduced from its inputs — should be flagged with the repository's full name and the specific metric in question: mail@inspect.software

Confirmed data errors trigger a re-scan. Disagreements with the methodology itself are answered with the documented formula; well-argued cases inform the methodology roadmap. If the code and documentation disagree, open an issue in the scanner's public repository, where the diagnosis and fix can be reviewed.

Security

Report a vulnerability in inspect.software or the published scanner privately to the same address, with security in the subject line, before public disclosure. Do not open a public issue. Reports are acknowledged and handled with priority.

Data protection

Requests about personal data — access, correction, erasure, restriction, portability, or an objection to processing — go to the same address, and are answered within one month: mail@inspect.software

Two cases come up most often. A contributor whose public GitHub profile was read for a report may have those enriched fields deleted and excluded from future scans. A maintainer whose address was collected from a package registry may have it deleted the same way. Neither request has to be justified.

What is processed, on what basis, and for how long is set out on the privacy page, which also names the supervisory authority.

Methodology questions

Most questions are already answered in public documentation:

  • Methodology — the complete specification.
  • Wiki — per-metric and per-category reference.
  • FAQ — common questions, including corrections and independence.
  • Scanner source — the AGPL-licensed production engine that computes published values.

Send a message