Security you can verify
The certifications, controls, and access model your security team asks for, kept current and backed by the Trust Center.
Certifications and standards
What’s certified today.
GDPR
EU-based team, EU hosting, strict GDPR compliance baked in by default.
SOC 2 Type II
SOC 2 Type II certified. Controls independently audited, with the report available on request.
Identity and access
Match your org’s identity model from day one.
Single sign-on
Google, GitHub, or Azure AD, plus email-based authentication, so you match your org’s identity model from day one.
Role-based access control
Permissions map to your org’s roles out of the box, not a flat everyone-sees-everything model.
Audit logs
Every create, update, and delete on a workspace is logged for accountability and compliance.
Security practices
How we secure the platform itself.
Encrypted in transit and at rest
All data is encrypted in transit and at rest, with access restricted to authenticated, authorized users.
Independently tested
Regular security assessments and penetration testing, on top of the SOC 2 audit itself.
Incident response
A defined incident response process, so if something happens, you hear about it fast.
Data protection
How your code and threat models are handled.
Your code stays yours
We never train models on your code, repositories, or threat models. Full data isolation.
Code processed, not stored
Source code and diffs are processed transiently in sandboxed containers during review, never stored persistently.
EU hosting, EU team
EU-based by default, with Standard Contractual Clauses covering any transfer outside the EU/EEA.
Ready for procurement to move faster?
Get the SOC 2 report, DPA, and security questionnaire answers in one place.
