codingassist.bot analyzes your diffs to produce your review — nothing more. We never train models on your code, we hold context in volatile memory for the life of a review, and every tenant is isolated from every other. This page is our public summary; the deeper explanations live in the data-governance and multi-tenancy docs.
Security at a glance
- Encryption in transit — TLS 1.2+ on every connection.
- Encryption at rest — AES-256; secrets and tokens stored encrypted and never returned.
- Least-privilege access — internal access is scoped and logged.
- Tenant isolation — each organization is a separate tenant with its own data boundary.
- No training on your code — your source produces your review and is never used to improve a shared or public model.
- Volatile-memory analysis — diffs and context are held in memory for the duration of a review, then discarded.
How we handle your code
When you authorize a connection, we read the diffs and metadata needed to review a pull request. That content is reasoned over in volatile memory and dropped afterward — there is no long-term retention of your source. Verdicts and audit trails are retained according to your plan's settings so you can replay a decision, but the underlying code is not kept.
Want maximum sovereignty? Point codingassist.bot at your own model key (BYOK) so your code is reasoned over by a model you control. Full detail in Data governance.
Compliance program
We build to recognized standards and are candid about where we are on the certification path:
- GDPR — data-handling principles are followed today; we act as processor for Customer Data and support data-subject requests.
- SOC 2 Type II & ISO 27001 — our architecture and controls are built to these requirements; formal certification is in progress, not yet issued. We'll publish reports (available under NDA) here as soon as they're available.
- Data Processing Agreement (DPA) — available to customers on request at legal@codingassist.bot.
Certification status and any downloadable reports are tracked on the Compliance page.
Subprocessors
We share personal data only with the subprocessors needed to run the Service. The current list — name, purpose, and location — is published and kept up to date at Subprocessors. Material changes are reflected there; enterprise customers can request advance notice of additions.
Report a vulnerability
Found a security issue? We appreciate responsible disclosure. Email security@codingassist.bot with details and reproduction steps. We acknowledge reports within two business days and will keep you updated through remediation. Please don't disclose publicly until we've had a chance to fix the issue.
Resources & contacts
- Data governance — what we store and what we don't.
- Multi-tenancy & isolation — how tenants are separated.
- Subprocessors — the third parties we rely on.
- Privacy Policy · Terms of Service
- Security questions — security@codingassist.bot
- DPA & legal — legal@codingassist.bot