Privacy
NextFix, a GRCSAC product. Last updated 9 October 2026.
This website
These pages are static files. They set no cookies and they carry no analytics or advertising. Everything they load comes from this domain, so no web font, embedded video or tracking pixel can follow you to another site. There is nothing to sign into and no form to fill in.
The site is served by Cloudflare Pages, which records ordinary request logs such as IP address, time and user agent in the course of delivering it and to protect against abuse. GRCSAC does not use those logs to build any profile of a visitor.
If you write to us
Mail sent to contact@grcsac.com reaches GRCSAC. We keep the message so we can reply and so we can tell you when there is a build worth trying. Ask us to delete it and we will.
The NextFix software
NextFix runs on your own machine or on a server you control. It has no account system and reports to no service of ours.
- Your source code, your lockfiles and the reports NextFix produces stay on the machine that ran the scan. Scan history is written to a SQLite file in your home directory.
- NextFix sends no usage data, no crash reports and no telemetry of any kind to GRCSAC.
- To find advisories it queries three public services directly from your machine: OSV, FIRST EPSS and the CISA Known Exploited Vulnerabilities catalogue. Those services see the request and therefore your IP address and the package or CVE identifiers being looked up. They do not receive your code.
- Responses are cached locally, and the
--offlineflag runs a scan against the cache with no network access at all.
Children
NextFix is a tool for software and security teams. It is not directed at children and collects nothing from anyone.
Changes
If this policy changes, the new version appears on this page with a new date. The software is still in development, so it is worth re-reading when a release adds anything that touches the network.
Contact
GRCSAC LLC, New Jersey, United States. contact@grcsac.com