Skip to content

CodeArmor 2.6 adds policy-as-code architecture rules and GitLab merge request audits

Read the changelog
CodeArmor AI

Legal

Privacy policy

Last updated June 1, 2026

This policy explains what CodeArmor AI collects when you use our website and services, how we use it, and the choices you have.

Information we collect

Account information such as your name, work email, company and billing details when you create a workspace or request a demo.

Usage information such as pages visited, features used, browser type and approximate location derived from IP address, collected through privacy-preserving analytics.

Repository metadata required to run audits, including repository names, commit identifiers and findings. Source code is processed transiently in an isolated sandbox and is not retained after an audit completes.

How we use information

To provide, maintain and improve the service, including running audits and opening remediation pull requests you have authorized.

To communicate with you about your account, security notices, product updates and, where you have opted in, marketing.

To protect the service, our customers and the public from abuse, fraud and security incidents.

What we never do

We never use your source code to train or fine-tune machine learning models, and our model providers are contractually bound to zero data retention.

We never sell personal information and never share it with third parties for their own marketing.

Sharing and subprocessors

We share information with subprocessors that help us operate the service, such as cloud hosting, model inference and billing providers. A current list is published on our security and trust page.

We may disclose information when required by law or to protect rights, safety and the integrity of the service.

Retention and security

Account and finding data is retained for the life of your workspace and deleted within 30 days of termination unless a longer period is required by law.

Data is encrypted in transit and at rest. Our controls are audited annually under SOC 2 Type II.

Your rights

Depending on your location you may have rights to access, correct, delete or export your personal information, and to object to or restrict certain processing.

To exercise these rights or ask questions about this policy, contact admin@codearmor.site.