Skip to content

Security & Compliance

Enterprise-grade security from day one. Your code never leaves your repositories.

Infrastructure

  • • Hosted on Azure France Central (GDPR-compliant region)
  • • PostgreSQL with Row-Level Security — strict multi-tenant isolation
  • • AES-256 encryption at rest, TLS 1.3 in transit
  • • Azure Container Apps with private VNet, no public DB access
  • • Automated daily backups with geo-redundancy (14-day retention)

Data & Privacy

  • • We never store source code — only metadata (commits, PRs, metrics)
  • • GDPR-compliant: data minimization, right to deletion, DPA available
  • • Configurable data retention (90 days to 24 months by plan)
  • • No data sharing with third parties — no ad tracking, no selling
  • • Provider tokens encrypted with per-tenant keys (Azure Key Vault)

Authentication & Access

  • • SSO via Microsoft Entra ID (Enterprise plan)
  • • MFA support on all plans
  • • Role-based access: Owner, Admin, Member, Viewer
  • • API keys with configurable scopes and expiration
  • • Complete audit trail of all administrative actions

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@devprism.io . We commit to acknowledging within 24h and providing a fix timeline within 72h.