Organization and project isolation
Code, context, and work records belong to the customer organization that produced them, and project access levels decide who inside that organization sees a given project.
A security review starts with a short list of questions and gets slower every time the answer has to be requested. The answers Codespeed can give in public are on this page, with the limits stated as plainly as the controls.
Code, context, and work records belong to the customer organization that produced them, and project access levels decide who inside that organization sees a given project.
Stored credentials are encrypted with AES-256-GCM. Values marked backend-only are never placed into a specialist sandbox at all, and reach the systems that need them through a proxied request instead.
Each access to a stored secret writes a record naming the actor, the result, and whether the attempt was blocked, without ever writing the value itself.
Security records, errors, and telemetry pass through redaction before they are stored, so reviewing what happened does not mean handling secrets a second time.
Both run under commercial API terms whose default excludes customer inputs and outputs from model training.
Codespeed records which model ran, at what cost, and for what purpose. The content of the work is not part of that record.
Codespeed uses standard provider retention rather than zero data retention or a named processing region. Bring the requirement to onboarding if your review needs either one.
What a model returns cannot grant tool, connector, production, database, secret, or review access on its own. Authority comes from your policy.
Reports are acknowledged within two business days and triaged within five. Codespeed credits researchers on coordinated disclosure and runs no paid bounty program at this stage. Send findings to security@codespeed.ai with enough detail to reproduce the issue.
The current provider and subprocessor list, tenant isolation detail, retention specifics, and questionnaire responses come with a security review packet. Ask for one at security@codespeed.ai or through Codespeed Applied.
Codespeed holds no SOC 2 report today, and a badge on this page would be the first thing worth distrusting on it. What exists instead is the operating structure an audit later measures, which is a control register with named owners and cadences, evidence retained for each control, a vendor inventory reviewed monthly, and incident response documented ahead of the first incident. Bring the timeline question to onboarding and it gets a dated answer.
The controls themselves are named on Security & Trust, and identity administration is covered on Identity & Access.