Diff-only review path
When a review opens or receives a new push, Andesyte fetches the diff and runs the review pipeline without cloning the source repository. The diff stays in memory for the audit run only.
Andesyte Code Security reviews pull and merge request changes across GitHub and GitLab SaaS. The strongest privacy property is simple: no clone, no retained diff.
When a review opens or receives a new push, Andesyte fetches the diff and runs the review pipeline without cloning the source repository. The diff stays in memory for the audit run only.
Andesyte does not train models on customer code. Requests set no-train controls where the upstream provider supports them.
GitHub and GitLab connections use source-host integration flows. We do not ask for, see or store your source-host password.
The maintained provider list lives in the privacy policy. We use managed cloud and source-host services to run the site, dashboard, authentication, billing and audit workflow.
Our disclosure policy covers scope, safe harbour and coordinated disclosure at /vulnerability-disclosure. Scanners can also read security.txt.
Current compliance posture and the legal document links live at /trust.