Security

What is active. What is in progress. Nothing inflated.

Codepylon works with production codebases. Each item below is labeled with its actual current state. We do not say "SOC 2 compliant" while the audit is in progress. We do not claim encryption at rest without specifying what is encrypted. If you are evaluating Codepylon for procurement, start here.

Active Data isolation
Active No code training
In progress SOC 2 Type II

Security posture

No training on customer code

Repository content is loaded only for the duration of an agent job. When the job completes, all job-specific data is deleted. Your code is not used to fine-tune or train any model, including ours. This constraint is enforced at the infrastructure level: the job execution environment has no persistent write path to any model training store.

Active, by design

Data isolation per job

Each agent job runs in an isolated execution environment. No cross-customer data sharing. Repository content from job A is never accessible to job B, even within the same organization.

Active

Audit logs

Every agent job is logged: who triggered it, which repository, which agent, what was changed, and when. Logs are available in the dashboard for your job history window (7 days Starter, 30 days Team, unlimited Enterprise).

Active

RBAC and team roles

Three roles: Admin (full access), Developer (trigger jobs and view history), Viewer (read-only). Available on Team and Enterprise plans. Role changes take effect immediately.

Active on Team and Enterprise

SOC 2 Type II

We have engaged an auditor and are currently in the observation period for SOC 2 Type II. We expect to receive the report by Q1 2027. We will not claim SOC 2 compliance until the report is issued. If you need a copy of the report for procurement, contact us.

In progress, expected Q1 2027

Minimal GitHub App permissions

The Codepylon GitHub App requests only the permissions required to do its job: read access to code and pull requests, write access to branches and PRs, and webhook delivery. We do not request access to organization secrets, Actions environment variables, billing settings, or repository admin permissions. The full permission manifest is listed in the GitHub App install flow.

Active

Security questions

No. Each job runs in an isolated environment. Data from your repository is never accessible to jobs from other organizations, and is deleted after the job completes.
Repository content is held only for the duration of a job and deleted when it completes. The repository graph index (which contains structural metadata, not raw code) is retained to enable fast subsequent jobs and is deleted when you disconnect the repository.
Self-hosted deployment is available on the Enterprise plan. Your code never leaves your infrastructure. Contact us to discuss deployment architecture, infrastructure requirements, and support terms.
Email [email protected] with the subject "Security vulnerability report." We respond within 24 hours and will coordinate disclosure timeline with you. We do not have a formal bug bounty program yet, but we acknowledge and credit valid reports.