Your code is your most valuable asset. Here's how we keep it safe.
Built-in protections to keep your repositories and data secure
We only request read-only permissions to your repositories. We never modify your code, create commits, or change repository settings.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
We never store your actual source code. Only commit metadata (messages, timestamps, authors) is processed and stored.
Secure GitHub OAuth integration. You can revoke access at any time from your GitHub settings.
How we handle your code when generating narratives
Enterprise customers can enable "Metadata Only" mode. We replace all code diffs with placeholders, sending only file names and commit messages to LLMs.
Use your own OpenRouter, Azure OpenAI, or Bedrock keys. Your data, your retention policies, your billing.
Complete transparency. View logs of every LLM transaction, including prompts sent (redacted) and provider responses.
Industry-standard security measures we implement to protect your data
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:
Bug Bounty: We offer rewards for valid security vulnerabilities based on severity. Contact us for details.
Our security team is here to help. Contact us with any questions or concerns.