← Back to the Deck Builder A CLOSER LOOK

Your data.
Your business.

How the Deck Builder handles your file, your package identifiers, and the links you share.

01

Your SBOM is read in your browser

The file goes into a Web Worker on your machine, is turned into a list of package URLs, and is dropped. It is never sent anywhere — not to us, not to a parsing service, not to anyone. There is no upload endpoint to point at, because there is no upload.

02

Your deck lives in the URL, after the #

The deck link is the list of card ids, encoded into the fragment of the URL. Browsers never send the fragment to a server — not to us, not to a proxy, not to whoever hosts the page. Open the link and the page decodes it locally.

03

There is no server to store anything

This site is static files. There is no database, no session, no endpoint that accepts a deck. Nothing you build here is written anywhere but your own address bar, and it is gone when you close the tab.

04

No accounts, no cookies, no identifiers

There is nothing to log in to. The Deck Builder sets no cookies, uses no local storage, runs no analytics script, and does no fingerprinting. Two decks built on the same machine an hour apart are, to us, two unrelated events.

The parts we cannot promise away

Two things do leave your machine, and you should know what they are.

Your package list goes to OSV.dev. That is how a component becomes a vulnerability ID, and it happens directly from your browser to osv.dev — with no credentials and no referrer, and without passing through us. We never see it. OSV.dev is a Google-operated open-source project with its own policies, and it does see which packages you asked about.

The page fetches each card it shows. A deck of forty cards is forty requests for /card/…json, and the web server that hosts this site keeps the ordinary access log every web server keeps: an address, a time, a path. That is the same trace anyone browsing the card database leaves, and it is the only trace a deck leaves. We add nothing to it — no identifier, no cookie, nothing that ties one request to the next.

A deck link is a link. Anyone you hand it to sees the same deck. It is not secret — treat it like the vulnerability list it is.

How to check

Open your browser's network tab and build a deck. You will see requests to osv.dev and to /card/…json, and nothing that carries your file or your deck. The code is public: the parser is in deck/sbom/, the fragment codec in deck/encode.ts, and the tests that hold both to it are in tests/.