Skip to content
Our open-source security work.See the research

How we protect review data

Andesyte Code Security reviews pull and merge request changes across GitHub and GitLab SaaS. The strongest privacy property is simple: no clone, no retained diff.

Controls we can state today

Diff-only review path

When a review opens or receives a new push, Andesyte fetches the diff and runs the review pipeline without cloning the source repository. The diff stays in memory for the audit run only.

Model-use boundaries

Andesyte does not train models on customer code. Requests set no-train controls where the upstream provider supports them.

Source-host permissions

GitHub and GitLab connections use source-host integration flows. We do not ask for, see or store your source-host password.

Hosting and operations

The maintained provider list lives in the privacy policy. We use managed cloud and source-host services to run the site, dashboard, authentication, billing and audit workflow.

  • Traffic to the public site and application is served over HTTPS.
  • Findings and operational metadata are kept so the product can show audit history, support suppressions and debug product issues.
  • Provider names and international transfer terms are documented in the privacy policy and DPA summary.

Reporting a vulnerability

Our disclosure policy covers scope, safe harbour and coordinated disclosure at /vulnerability-disclosure. Scanners can also read security.txt.

Current compliance posture and the legal document links live at /trust.