Skip to content
Our open-source security work.See the research

Current facts about code and data

No badge wall. This page says what Andesyte can stand behind today, where the legal documents live and how to reach us about a security issue.

Compliance posture

We do not claim certifications we do not hold. Procurement teams can use this as the current public answer, then ask for a signed DPA if needed.

SOC 2 / ISO 27001
No certification or audit report published today
HIPAA / PCI
Not in scope
DPA
Summary published; signed copy available on request
Vulnerability disclosure
Policy and security.txt are published

How Andesyte handles review data

Code review runs on the diff

Andesyte fetches pull and merge request diffs from the connected source host. The documented review path uses no source clone and no retained diff.

Your code is not training data

Andesyte does not train models on customer code. Where an upstream model provider supports no-train controls, requests use them.

Audit records stay practical

The product keeps findings and operational metadata needed for audit history, suppressions, billing and support. Source-host findings remain in your source host.

The legal source of truth

Sub-processors

The maintained list lives in the privacy policy. We avoid duplicating vendor tables here because that creates a second place for legal data to drift.

Open the list

Signed documents

The DPA summary is public. Customers who need a countersigned copy can request one through the privacy contact route.

Read the DPA summary

Tell us if something looks wrong

Security reports go to security@andesyte.com. Privacy and DPA requests go through the contact form so they reach the right person.