Security & compliance

Everything your security team asks first.

SOC2 roadmap, data retention, encryption in transit and at rest, code-data access controls, and the subprocessor list — the questions B2B buyers probe before attaching a security tool to their codebase.

SOC2 roadmap

SOC2 Type II in progress.

The controls are already wired through Pro and Enterprise. The audit window is running; the latest status letter is available on request.

ControlStatus
SOC2 Type II readinessAudit window in progress with our third-party auditor; the readiness gap assessment is closed and the observation window is running.
Audit log exportPer-repo audit log (who/what/when) is available on Pro and Enterprise from day one — it ships before the SOC2 letter.
Scoped access tokensGitHub App permissions are minimum-scope by default; per-installation token rotation on Enterprise.
Single-tenant regionEU/US data residency is an Enterprise option for organisations that need their ingest region pinned.
Data retention

Processed once, then dropped.

What we keep, for how long, and what you can pull out as evidence for your own security review.

Retention & training policy

Your code, your receipts.
  • Diff plus surrounding context are processed once for the review and then dropped from the inference path.
  • Nothing trains on your code — your repository never becomes model input, on any plan.
  • Aggregated retention windows: 24h for hot staging, 30d for retry buffers, 90d for audit logs (exportable on Pro/Enterprise).
  • Pro and Enterprise audit log export shows exactly what was read and when, so your security team has the receipts.
Encryption

Encrypted in transit, encrypted at rest.

Speak-of-the-trade, no invented cipher suites — just the boundaries your security team already checks.

In transit

All client and ingest traffic is TLS 1.2 or higher. The GitHub App talks to GitHub over TLS, the Slack/Teams digest talks to those APIs over TLS, and the browser dashboard talks to our API over TLS. No service accepts plain HTTP on its public surface.

At rest

Persistent storage uses AES-256 standard encryption across the deployment. Per-tenant isolation keys are rotated on the platform schedule; Enterprise customers can pin a dedicated region for residency.

Access controls

Your code stays yours.

Scope, audit, and IdP wiring — the three boundaries a security team asks about before granting repo access.

Access control

GitHub App scope

Read pull requests and the diff. Write inline issue comments as mergehound-bot. Nothing else — no source writes, no branch creation, no rebase, no merge, no clone of the repo outside the App.

Access control

Per-tenant audit log

Every read and write against your repo and your digest channel is captured with timestamp and reviewer id. Export it as CSV from the dashboard on Pro, or via the SOC2 evidence endpoint on Enterprise.

Access control

SAML SSO + SCIM

Enterprise plans wire SAML SSO and SCIM provisioning so seat membership stays in lockstep with your IdP — offboarding is just an IdP-side deprovision.

Subprocessors

Who touches your review.

Every third party your data crosses paths with while running a review. If anyone changes, we email you first.

RoleVendorData handled
IngestGitHubPR metadata and the diff under review
Digest deliverySlackChannel id, digest payload, no message history
Digest deliveryMicrosoft TeamsChannel id, digest payload, no message history
BillingStripeCustomer id and purchase events (handled by the billing module)
Transactional emailPolsia email proxyRecipient, message body, sent on behalf of mergehound@polsia.app
HostingPolsia render infrastructureAudit logs, review state, and aggregated metrics
Review engineDiff/Microscope vendorDiff under review for the duration of inference; not retained for training
Request docs

Need the full packet?

Open a thread with our security team in one click, or send a quick note and we'll route it for you.

The fastest path to our full SOC2 status letter, controls map, DPA, and the complete subprocessor inventory is to email security@polsia.app. Average reply time: under one business day.

Request security docs

Or use the form below — it goes to the same inbox and we'll route it to the right reviewer.

Send us a message

Tell us what's on your mind.

By submitting you agree we may email you back at the address above. Unsubscribe any time.

Ready when you are

Want to talk to a human?

If your security team needs something we haven't surfaced here — pen test results, infra diagrams, CVE history — drop us a line and we'll get on a call.