Code review runs on the diff
Andesyte fetches pull and merge request diffs from the connected source host. The documented review path uses no source clone and no retained diff.
No badge wall. This page says what Andesyte can stand behind today, where the legal documents live and how to reach us about a security issue.
We do not claim certifications we do not hold. Procurement teams can use this as the current public answer, then ask for a signed DPA if needed.
Andesyte fetches pull and merge request diffs from the connected source host. The documented review path uses no source clone and no retained diff.
Andesyte does not train models on customer code. Where an upstream model provider supports no-train controls, requests use them.
The product keeps findings and operational metadata needed for audit history, suppressions, billing and support. Source-host findings remain in your source host.
The maintained list lives in the privacy policy. We avoid duplicating vendor tables here because that creates a second place for legal data to drift.
Open the listThe DPA summary is public. Customers who need a countersigned copy can request one through the privacy contact route.
Read the DPA summarySecurity reports go to security@andesyte.com. Privacy and DPA requests go through the contact form so they reach the right person.