Security

What StackRadar can touch, where your code goes, and what we still owe you. Short answers, no hedging.

Access, scoped by you

A GitHub App with per-repo grants: read code, write branches and pull requests. It merges only when your required checks pass. Where reviews gate the merge, you add StackRadar to your ruleset’s bypass list yourself: one reviewed settings change, visible in the audit log, revocable any time. Uninstalling the App ends access on GitHub’s side.

Your code stays yours

Agents read the paths a fix touches, in a per-run sandbox. The index they build dies with the sandbox. Model calls run under a zero-retention agreement with our model provider, and nothing trains on your code.

Where data lives

StackRadar runs in EU regions of our infrastructure providers. The current subprocessor list sits in the DPA, and you can request it or subscribe to change notifications at any time.

Read the DPA

Nothing merges without your rules

Observe mode is the default. Policy lives in your repo as a committed file, every change passes your own CI, a soak window holds green changes short of the merge, and one click opens the revert PR.

The full mechanism

Certifications

We hold no SOC 2 or ISO 27001 today. Certification is on the roadmap, and this page will say so the day that changes. Until then: the DPA, the subprocessor list, and the permission scopes above are current.

Report a problem

Found something? security@stackradar.com reaches people who can act on it. We read every report.