Security you can verify

The certifications, controls, and access model your security team asks for, kept current and backed by the Trust Center.

Certifications and standards

What’s certified today.

GDPR compliant

GDPR

EU-based team, EU hosting, strict GDPR compliance baked in by default.

SOC 2 Type II

SOC 2 Type II

SOC 2 Type II certified. Controls independently audited, with the report available on request.

View reports in the Trust Center

Identity and access

Match your org’s identity model from day one.

Single sign-on

Google, GitHub, or Azure AD, plus email-based authentication, so you match your org’s identity model from day one.

Role-based access control

Permissions map to your org’s roles out of the box, not a flat everyone-sees-everything model.

Audit logs

Every create, update, and delete on a workspace is logged for accountability and compliance.

Security practices

How we secure the platform itself.

Encrypted in transit and at rest

All data is encrypted in transit and at rest, with access restricted to authenticated, authorized users.

Independently tested

Regular security assessments and penetration testing, on top of the SOC 2 audit itself.

Incident response

A defined incident response process, so if something happens, you hear about it fast.

Data protection

How your code and threat models are handled.

Your code stays yours

We never train models on your code, repositories, or threat models. Full data isolation.

Code processed, not stored

Source code and diffs are processed transiently in sandboxed containers during review, never stored persistently.

EU hosting, EU team

EU-based by default, with Standard Contractual Clauses covering any transfer outside the EU/EEA.

Ready for procurement to move faster?

Get the SOC 2 report, DPA, and security questionnaire answers in one place.

We value your privacy

We use cookies to make the site work better for you and to analyze traffic. You can accept all cookies, customize your settings, or reject non-essential cookies.