Security and data handling
A developer’s view of where data goes. The security page summarizes it for everyone.
What leaves your infrastructure
| Mode | Sent to the service | Stays with you |
|---|---|---|
| Managed | The repository is cloned into a private container for the job, then deleted. | Nothing: the code is processed in our cloud, and only the encrypted index is kept between jobs. |
| Runner | Diagnosis with short code excerpts (file and line references only, with share: references-only), reply draft, verification and test reports, the diff statistics. | The clone, the rest of the code and your provider key. |
| MCP | Diagnosis with short code excerpts (references only, with share: references-only), reply draft, and the reported fix: branch, commit SHA and results. | The clone, the rest of the code and your agent’s credentials. |
Whatever the mode, the demo ticket that follows the connection of a repository runs once in the Managed sandbox, at our expense; its clone is deleted at the end of the job. On public repositories, external pull requests are analysed in the sandbox as well, so code from forks never runs where your secrets are.
What reaches the model
- Logs and messages are scrubbed before they enter a prompt: emails, phone numbers, card numbers, IBANs, IP addresses and secrets. The engine’s Shield scan adds its findings where available.
- Tickets, logs, issues, widget reports and shared patterns enter the prompt wrapped as untrusted data, with the instruction to treat them as data.
- With
share: references-only, diagnoses keep file and line references but no code snippets. - Customer code is not used to train models; the zero-retention options of the providers are used where they exist.
Tokens
- GitHub Actions jobs sign in with OIDC: each ID token is exchanged once, only for a run on the default branch, and only for a job of that repository.
- Job tokens are signed, cover one job and one workspace, and expire after 60 minutes.
- The agent gets its own token, valid only for the MCP tools of its job.
- Runner and MCP tokens are valid for one workspace and expire.
- Only hashes of tokens are stored; provider keys are encrypted with envelope encryption.
Retention
| Data | Kept |
|---|---|
| Error events | 30 days |
| Screenshots and technical details of widget reports | 30 days after the ticket is closed |
| User emails shared through the widget for fix notices | 30 days after they were last shared; longer only while an open ticket still has to notify the user |
| Prompts and outputs of jobs, already masked | 30 days by default, configurable |
| Clones of your repository | Deleted at the end of each job |
| Code index (Managed) | Until disconnection, or 30 days unused |
Report a vulnerability
See the security page for the address and what to include.