Security
What StackRadar can touch, where your code goes, and what we still owe you. Short answers, no hedging.
Access, scoped by you
A GitHub App with per-repo grants: read code, write branches and pull requests. It merges only when your required checks pass. Where reviews gate the merge, you add StackRadar to your ruleset’s bypass list yourself: one reviewed settings change, visible in the audit log, revocable any time. Uninstalling the App ends access on GitHub’s side.
Your code stays yours
Agents read the paths a fix touches, in a per-run sandbox. The index they build dies with the sandbox. Model calls run under a zero-retention agreement with our model provider, and nothing trains on your code.
Where data lives
StackRadar runs in EU regions of our infrastructure providers. The current subprocessor list sits in the DPA, and you can request it or subscribe to change notifications at any time.
Read the DPANothing merges without your rules
Observe mode is the default. Policy lives in your repo as a committed file, every change passes your own CI, a soak window holds green changes short of the merge, and one click opens the revert PR.
The full mechanismCertifications
We hold no SOC 2 or ISO 27001 today. Certification is on the roadmap, and this page will say so the day that changes. Until then: the DPA, the subprocessor list, and the permission scopes above are current.
Report a problem
Found something? security@stackradar.com reaches people who can act on it. We read every report.