Skip to main content
Trust

What Codespeed does with your code and credentials.

A security review starts with a short list of questions and gets slower every time the answer has to be requested. The answers Codespeed can give in public are on this page, with the limits stated as plainly as the controls.

Data Handling

Your work stays scoped to your organization.

Organization and project isolation

Code, context, and work records belong to the customer organization that produced them, and project access levels decide who inside that organization sees a given project.

Credentials encrypted at rest

Stored credentials are encrypted with AES-256-GCM. Values marked backend-only are never placed into a specialist sandbox at all, and reach the systems that need them through a proxied request instead.

Every credential read recorded

Each access to a stored secret writes a record naming the actor, the result, and whether the attempt was blocked, without ever writing the value itself.

Logs written to be readable

Security records, errors, and telemetry pass through redaction before they are stored, so reviewing what happened does not mean handling secrets a second time.

Model Providers

Your inputs and outputs stay out of model training.

The active providers are OpenAI and Anthropic

Both run under commercial API terms whose default excludes customer inputs and outputs from model training.

Telemetry carries metadata only

Codespeed records which model ran, at what cost, and for what purpose. The content of the work is not part of that record.

Retention is the provider standard

Codespeed uses standard provider retention rather than zero data retention or a named processing region. Bring the requirement to onboarding if your review needs either one.

Model output is a proposal

What a model returns cannot grant tool, connector, production, database, secret, or review access on its own. Authority comes from your policy.

Disclosure

Report a vulnerability to security@codespeed.ai.

What to expect

Reports are acknowledged within two business days and triaged within five. Codespeed credits researchers on coordinated disclosure and runs no paid bounty program at this stage. Send findings to security@codespeed.ai with enough detail to reproduce the issue.

Security review requests

The current provider and subprocessor list, tenant isolation detail, retention specifics, and questionnaire responses come with a security review packet. Ask for one at security@codespeed.ai or through Codespeed Applied.

Compliance

The audit report does not exist yet.

Codespeed holds no SOC 2 report today, and a badge on this page would be the first thing worth distrusting on it. What exists instead is the operating structure an audit later measures, which is a control register with named owners and cadences, evidence retained for each control, a vendor inventory reviewed monthly, and incident response documented ahead of the first incident. Bring the timeline question to onboarding and it gets a dated answer.

The controls themselves are named on Security & Trust, and identity administration is covered on Identity & Access.

Send the questionnaire. Codespeed will answer it.