Read-only access. Encrypted data. Transparent practices. No surprises.
GitSense requests only read-only access to your repos via OAuth. We never ask for write permissions. You can verify this in your GitHub/GitLab settings at any time.
Settings → Applications → GitSense in GitHub to see exact permissions.
Your code is analyzed in-transit and never stored permanently. We retain only metadata and insights needed to provide GitSense features.
Data is encrypted in transit and at rest using industry-standard protocols. We follow OWASP guidelines and conduct regular security audits.
GitSense runs on hardened infrastructure with network isolation, DDoS protection, and 24/7 monitoring. Enterprise customers can opt for self-hosted deployment.
GitSense undergoes regular third-party audits and maintains compliance with industry standards. Audit reports available to Enterprise customers under NDA.
Annual audit covering security, availability, and confidentiality. Last audit: Q4 2023.
Full compliance with EU data protection regulations. Data processing agreements available.
Information security management system certified. Recertified annually.
California Consumer Privacy Act compliant. User data rights honored within 48 hours.
We log all access and changes for audit trails. Security incidents are detected, contained, and disclosed according to our incident response plan.
We're transparent about our practices. If you have questions or need to report a vulnerability, contact us.