Your code stays yours.
CodePulse turns engineering workflow data into delivery insight through a least-privilege, read-only connection. We never clone your repository, read your files, or ask for write access. Everything a security reviewer needs is on this page, including the one place code ever touches CodePulse.
Read-only GitHub App
No write, delete, or administration permissions.
Your code stays yours
We never clone your repository or read your files.
Encrypted credentials
GitHub tokens and webhook secrets are encrypted with Fernet before storage.
SOC 2-aligned controls
Controls are mapped to the applicable AICPA Trust Services Criteria.
Data flow
A narrow path from GitHub to answers
The integration is intentionally constrained at each step. Repository owners control scope in GitHub and can revoke the installation at any time.
- 01
Selected repositories
An organization owner chooses exactly which repositories CodePulse can access.
- 02
Read-only connection
GitHub API traffic is encrypted in transit and inbound webhooks are signature-verified.
- 03
Scoped processing
CodePulse reads workflow fields from the GitHub API. It never clones your repository.
- 04
Tenant-scoped analytics
Stored workflow data and calculated metrics are partitioned by organization.
Data boundary
Engineering context, without repository contents
CodePulse needs enough workflow context to explain delivery patterns. It does not need the files that make up your product.
What CodePulse processes
- GitHub account, organization, repository, and team identifiers
- Pull request titles, descriptions, states, branches, labels, and timestamps
- Commit identifiers, messages, authorship, timestamps, and change counts
- Changed file paths and aggregate additions/deletions
- Review activity, comments, and discussion
- The short code snippet GitHub attaches to an inline review comment, kept with that comment so review depth and quality can be measured
- Check-run names, states, conclusions, and deployment events
- Connected issue titles, descriptions, status, and ownership when enabled
What stays outside CodePulse
- Your source files - CodePulse never clones your repository or reads file contents
- Complete pull request patches or full source-code diffs
- Secrets, environment variables, or private keys
- CI/CD logs and build output
- Write, delete, or repository administration access
- Keystrokes, screen activity, browser history, or local machine telemetry
GitHub permissions
Read-only, repository-selectable access
GitHub organization owners approve the installation and may grant access to all repositories or a selected list. CodePulse requests no write permissions.
| Permission | Level | Why it is requested |
|---|---|---|
| Metadata | Read | Repository identity and installation metadata. GitHub grants this automatically. |
| Contents | Read | Commit history, branch information, file paths, and change counts. CodePulse never requests file contents. |
| Pull requests | Read | Pull request lifecycle, reviews, comments, requested reviewers, and changed-file metadata. |
| Checks and commit statuses | Read | Check names, status, conclusion, and timing used for delivery-health metrics. |
| Issues | Read | Optional issue analytics and links between delivery work and pull requests. |
| Members | Read | Organization membership used for access control and team configuration. |
Security controls
The controls behind the connection
These controls are in place today, documented, and open to review as part of your vendor assessment.
Access control
- Role-based product permissions
- Organization membership checks
- Restricted production administration
- Revocable GitHub App installations
Encryption and secrets
- TLS for data in transit
- Application-level credential encryption
- Webhook signature validation
- Production secret startup checks
Tenant isolation
- Organization-scoped data models
- Authenticated membership enforcement
- Role checks on protected actions
- Administrative action logging
Application integrity
- Peer-reviewed changes
- Automated tests and dependency checks
- Parameterized database access
- Input validation and rate limits
Operational resilience
- EU-hosted production infrastructure
- Operational backups
- Error and performance monitoring
- Documented incident response
Privacy and lifecycle
- Public Data Processing Agreement
- Documented sub-processors
- Organization deletion workflow
- Access revocation and data-subject support
Assurance
What you can verify today
You do not have to take our word for the things that matter most in a vendor review. The GitHub App requests read permissions only and GitHub itself shows you the scopes. You choose the repositories. You revoke access in one click. Production runs in the EU, the DPA and sub-processor list are public, and the security program is mapped to the applicable AICPA Trust Services Criteria.
To be precise about assurance: CodePulse has not yet completed an independent SOC 2 examination, and no Type I or Type II report has been issued. We say “SOC 2-aligned controls” and never “certified” or “compliant”. The control map is in the security overview if your reviewer wants the detail.
- Write access requested
- None
- Repository cloning
- Never
- Production region
- EU (Ireland)
- DPA and sub-processors
- Public
- SOC 2 control map
- Mapped
- Independent SOC 2 report
- Not yet issued
Review materials
Everything your security reviewer needs
Security overview
A concise brief for security and procurement reviews.
Download PDFData Processing Agreement
Processing terms, technical measures, and transfer safeguards.
Review DPASub-processors
Current service providers that may process customer personal data.
View listPrivacy policy
How CodePulse collects, uses, retains, and protects personal data.
Read policyService availability
Review current and historical service status.
Bring us your security questions
We support vendor reviews, permission walkthroughs, DPA questions, and reasonable security questionnaires.
security@codepulsehq.comSatisfied? Connect a repository and see your own data
Read-only, five minutes, no credit card. Start with a single repository if you would rather see it work before widening the installation.
Prefer to bring your security reviewer first? Send them this page and the security overview - we are happy to answer the questionnaire before you connect anything.