Security & trust
Built by security engineers. Audited by third parties.
CodeArmor reads the most sensitive asset your company owns. Here is exactly how we protect it, what we keep, and what we never do.
- SOC 2 Type IIAudited annually
- GDPRDPA available
- ISO 27001Certification in progress
- OWASP ASVS L2Self-assessed
Data handling
- Repositories are cloned into an isolated, ephemeral sandbox that is destroyed when the audit completes.
- Source code is never used to train or fine-tune models. Model inference runs under a zero-retention agreement.
- Findings, diffs and audit logs are encrypted at rest with AES-256 and in transit with TLS 1.3.
- Customer data is logically isolated per tenant and physically isolated for private cloud deployments.
Platform security
- Every audit runs in a fresh micro-VM with no network egress except to the configured source control provider.
- Remediation patches are executed only inside the sandbox; nothing runs in your CI until you merge.
- Secrets detected during an audit are redacted before they reach the reasoning engine.
- Infrastructure is deployed from reviewed infrastructure-as-code with continuous vulnerability scanning.
Access and governance
- SSO with SAML 2.0 and OIDC, SCIM user provisioning and enforced MFA for all workspace roles.
- Granular roles for viewers, reviewers, admins and auditors, scoped per organization or repository.
- Immutable audit logs for every finding, patch, merge decision and configuration change, exportable to your SIEM.
- Background checks and least-privilege access for all CodeArmor staff, with production access reviewed quarterly.
Deployment options
Choose the boundary that matches your compliance posture. Every option runs the same audit engine and receives the same releases.
Cloud
Multi-tenant SaaS hosted in AWS us-east-1 and eu-central-1 with regional data residency.
Private cloud
Single-tenant deployment inside your AWS or GCP account, managed by CodeArmor through a control plane.
On-premises
Air-gapped installation on Kubernetes for regulated environments, including offline model serving.
Subprocessors
Third parties that may process customer data on our behalf. Customers are notified 30 days before any addition.
| Provider | Purpose | Location |
|---|---|---|
| Anthropic | Model inference (zero-retention) | United States |
| Amazon Web Services | Hosting and storage | United States, Germany |
| GitHub, GitLab, Atlassian | Source control integration | Per provider |
| Stripe | Billing | United States |
Responsible disclosure
We welcome reports from security researchers. Email our security team with reproduction steps and we will acknowledge within one business day and keep you updated until resolution. We do not pursue legal action against good-faith research.
Put a senior AppSec engineer on every pull request.
Start free with up to three repositories, or book a walkthrough with our team. We will run CodeArmor against a repository of your choice and show you what your current tooling missed.
Prefer email? Reach the team at admin@codearmor.site