Skip to content

CodeArmor 2.6 adds policy-as-code architecture rules and GitLab merge request audits

Read the changelog
CodeArmor AI

Security & trust

Built by security engineers. Audited by third parties.

CodeArmor reads the most sensitive asset your company owns. Here is exactly how we protect it, what we keep, and what we never do.

  • SOC 2 Type IIAudited annually
  • GDPRDPA available
  • ISO 27001Certification in progress
  • OWASP ASVS L2Self-assessed

Data handling

  • Repositories are cloned into an isolated, ephemeral sandbox that is destroyed when the audit completes.
  • Source code is never used to train or fine-tune models. Model inference runs under a zero-retention agreement.
  • Findings, diffs and audit logs are encrypted at rest with AES-256 and in transit with TLS 1.3.
  • Customer data is logically isolated per tenant and physically isolated for private cloud deployments.

Platform security

  • Every audit runs in a fresh micro-VM with no network egress except to the configured source control provider.
  • Remediation patches are executed only inside the sandbox; nothing runs in your CI until you merge.
  • Secrets detected during an audit are redacted before they reach the reasoning engine.
  • Infrastructure is deployed from reviewed infrastructure-as-code with continuous vulnerability scanning.

Access and governance

  • SSO with SAML 2.0 and OIDC, SCIM user provisioning and enforced MFA for all workspace roles.
  • Granular roles for viewers, reviewers, admins and auditors, scoped per organization or repository.
  • Immutable audit logs for every finding, patch, merge decision and configuration change, exportable to your SIEM.
  • Background checks and least-privilege access for all CodeArmor staff, with production access reviewed quarterly.

Deployment options

Choose the boundary that matches your compliance posture. Every option runs the same audit engine and receives the same releases.

Cloud

Multi-tenant SaaS hosted in AWS us-east-1 and eu-central-1 with regional data residency.

Private cloud

Single-tenant deployment inside your AWS or GCP account, managed by CodeArmor through a control plane.

On-premises

Air-gapped installation on Kubernetes for regulated environments, including offline model serving.

Subprocessors

Third parties that may process customer data on our behalf. Customers are notified 30 days before any addition.

ProviderPurposeLocation
AnthropicModel inference (zero-retention)United States
Amazon Web ServicesHosting and storageUnited States, Germany
GitHub, GitLab, AtlassianSource control integrationPer provider
StripeBillingUnited States

Responsible disclosure

We welcome reports from security researchers. Email our security team with reproduction steps and we will acknowledge within one business day and keep you updated until resolution. We do not pursue legal action against good-faith research.

admin@codearmor.site

Put a senior AppSec engineer on every pull request.

Start free with up to three repositories, or book a walkthrough with our team. We will run CodeArmor against a repository of your choice and show you what your current tooling missed.

Prefer email? Reach the team at admin@codearmor.site