Security

Minimize access. Shorten secrets. Preserve evidence integrity.

The MVP is designed around read-only permissions and server-side credential handling.

Collection boundary

  • Read-only metadata permissions
  • No Git blobs or source file contents
  • Short-lived installation access tokens
  • Repository limits enforced per entitlement

Integrity and isolation

  • Canonical JSON plus SHA-256
  • Webhook HMAC verification
  • Delivery-ID idempotency
  • Tenant-scoped PostgreSQL rows and RLS

Operational controls

  • Atomic queue claims
  • Four-attempt retry ceiling
  • Dead-letter visibility
  • Retention cleanup and backup runbook

Disclosure

Report suspected vulnerabilities privately through the support identity configured at deployment. Do not include credentials or customer data.