Skip to main content
CodePulse
CodePulse Trust Center

Your code stays yours.

CodePulse turns engineering workflow data into delivery insight through a least-privilege, read-only connection. We never clone your repository, read your files, or ask for write access. This page sets out what we collect, which providers process it, and the one kind of code snippet we keep.

Read-only GitHub App

No write, delete, or administration permissions.

Your code stays yours

We never clone your repository or read your files.

Encrypted credentials

Connected-service tokens and secrets are encrypted with Fernet before storage.

No passwords held

You sign in with GitHub or Azure DevOps, so your own MFA policy applies.

Data flow

A narrow path from GitHub to answers

The integration is intentionally constrained at each step. Repository owners control scope in GitHub and can revoke the installation at any time.

  1. 01

    Selected repositories

    An organization owner chooses exactly which repositories CodePulse can access.

  2. 02

    Read-only connection

    All traffic is encrypted with TLS and HSTS, and inbound webhooks are verified before processing.

  3. 03

    Scoped processing

    CodePulse reads workflow fields from the GitHub API. It never clones your repository.

  4. 04

    Tenant-scoped analytics

    Stored workflow data and calculated metrics are partitioned by organization.

Data boundary

Engineering context, without repository contents

CodePulse needs enough workflow context to explain delivery patterns. It does not need the files that make up your product.

What CodePulse processes

  • GitHub account, organization, repository, and team identifiers
  • Developer names, logins, and email addresses as they appear in GitHub
  • Pull request titles, descriptions, states, branches, labels, and timestamps
  • Commit identifiers, messages, authorship, timestamps, and change counts
  • Changed file paths and aggregate additions/deletions
  • Review activity, comments, and discussion
  • The short code snippet GitHub attaches to an inline review comment, kept with that comment so review depth and quality can be measured
  • Check-run and commit-status names, states, and conclusions
  • Connected issue titles, descriptions, status, and ownership when enabled
  • Developer survey responses and AI coding-tool usage, when your organization uses those features

What stays outside CodePulse

  • Your source files - CodePulse never clones your repository or reads file contents
  • Complete pull request patches or full source-code diffs
  • Secrets, environment variables, or private keys
  • CI/CD logs and build output
  • Write, delete, or repository administration access
  • Keystrokes, screen activity, browser history, or telemetry from developers' machines

AI features

Some features send limited data to AI providers in the United States (Anthropic and OpenAI) to produce a result:

  • Pull request summaries and the summary emails we send to your own team read pull request titles, descriptions, and file paths.
  • Matching AI coding-tool accounts to developers reads developer names, logins, and email addresses.
  • Drafting our replies to your support requests reads the messages you send us.
  • Review-quality analysis, which reads review comments with their attached snippet, is off by default.

An organization admin can switch AI features off in settings. While they are off, we send none of your organization’s data to AI providers. We do not train AI models on your code or data. Each provider and the data it receives is listed in the sub-processor list.

Your developers

CodePulse is built for team visibility, not surveillance.

  • CodePulse measures teams and delivery systems, not individual output.
  • Ranked per-developer comparisons are off by default. Only an organization admin can turn them on.
  • Team awards recognize healthy behaviors such as thorough reviews and mentoring.
  • Nothing is collected from developers' machines: no keystrokes, screen activity, or browser history.

Your organization tells its developers that CodePulse is in use, as described in the DPA.

GitHub permissions

Read-only, repository-selectable access

GitHub organization owners approve the installation and may grant access to all repositories or a selected list. CodePulse requests no write permissions.

PermissionLevelWhy it is requested
MetadataReadRepository identity and installation metadata. GitHub grants this automatically.
ContentsReadCommit history, branch information, file paths, and change counts. CodePulse never requests file contents.
Pull requestsReadPull request lifecycle, reviews, comments, requested reviewers, and changed-file metadata.
Checks and commit statusesReadCheck names, status, conclusion, and timing used for delivery-health metrics.
IssuesReadOptional issue analytics and links between delivery work and pull requests.
MembersReadOrganization membership used for access control and team configuration.

Security controls

The controls behind the connection

These controls are documented and open to review as part of your vendor assessment. The control map shows the current status of each one.

Access control

  • Role-based product permissions
  • Organization membership checks
  • Restricted production administration
  • Revocable GitHub App installations

Encryption and secrets

  • TLS in transit, with HSTS
  • Encryption at rest and of credentials
  • Webhook verification
  • Production secret startup checks

Tenant isolation

  • Organization-scoped data models
  • Authenticated membership enforcement
  • Role checks on protected actions
  • Staff administrative-action logging

Application integrity

  • Peer-reviewed changes
  • Automated tests and dependency checks
  • Parameterized database access
  • Input validation; public-endpoint rate limits

Operational resilience

  • UK-hosted production (Oracle Cloud, London)
  • Encrypted backups, restore-tested weekly
  • Error and performance monitoring
  • Documented incident response

Privacy and lifecycle

  • Public Data Processing Agreement
  • Documented sub-processors
  • Organization deletion workflow
  • Access revocation and data-subject support

Assurance

What you can verify today

You do not have to take our word for the things that matter most in a vendor review. The GitHub App requests read permissions only and GitHub itself shows you the scopes. You choose the repositories, and you can uninstall the App at any time. Production runs in the United Kingdom and encrypted backups stay in the EU. The DPA and full sub-processor list are public, and our SOC 2-aligned controls are mapped to the applicable AICPA Trust Services Criteria.

CodePulse has not yet completed an independent SOC 2 examination, so no Type I or Type II report exists yet. The control map shows each control, its Trust Services Criteria mapping and its current status, and is available on request.

Our free public-repository tool, which works without signing in, reads the commit history of public repositories only, using no customer credentials or data.

Write access requested
None
Repository cloning
Never
Production region
UK (London)
DPA and sub-processors
Public
SOC 2 control map
Mapped
Independent SOC 2 report
Not yet issued

Review materials

Everything your security reviewer needs

Also available to security reviewers on request: our Information Security Policy, Incident Response Plan, and SOC 2 readiness control map. Email security@codepulsehq.com.

Service availability

Review current and historical service status.

Open status page

Bring us your security questions

We support vendor reviews, permission walkthroughs, DPA questions, and security questionnaires.

security@codepulsehq.com

Satisfied? Connect a repository and see your own data

Read-only, five minutes, no credit card. Start with a single repository if you would rather see it work before widening the installation.

Prefer to bring your security reviewer first? Send them this page and the security overview - we are happy to answer the questionnaire before you connect anything.