CODEAWARE COMPLIANCE & TRUST

Privacy Policy

Last Updated: August 5, 2026 • Effective Date: January 1, 2026

GDPR & ATLASSIAN VERIFIED PRIVACY

Welcome to Codeaware.ai. This Privacy Policy outlines how Codeaware ("we", "our", or "us") manages repository telemetry, user metadata, and autonomous agent analysis logs. Our control plane acts as an out-of-band monitoring shield, guaranteeing total isolation of your intellectual property. By utilizing our dashboard or integrating our webhooks, you explicitly consent to the terms delineated herein.

01

Information We Collect

We collect information required to evaluate autonomous engineering agent operations and human collaboration metrics within your secure software development lifecycle (SDLC).

  • Repository Metadata: Pull request IDs, commit hashes, lines of code changed, and agent attribution logs.
  • FinOps Telemetry: Token consumption rates, LLM provider endpoints, model run durations, and circuit breaker telemetry.
  • Collaborative Signal: Slack commands, Jira issue IDs, active loop alerts, and developer review feedback patterns.
02

Data We Do NOT Collect

As an out-of-band control plane, Codeaware is architected to minimize what it stores. The following categories are explicitly and permanently excluded from our persistent data stores:

  • No Raw Source Code: We never persist raw file contents or source blobs. All code analysis occurs via transient, in-memory Abstract Syntax Tree (AST) parsing that is destroyed immediately after evaluation.
  • No Password Hashes: Codeaware never stores user or service-account password hashes. Authentication is delegated entirely to your identity provider (SSO / OAuth) and the source control providers you connect.
  • No Integration Credentials in DB: OAuth tokens and webhook secrets for GitHub, GitLab, Jira, and Sentry are held exclusively in an encrypted secrets vault, never in our primary application database.
03

How We Use Your Information

Collected metrics are processed out-of-band to drive the Codeaware governance dashboard, trigger automated FinOps circuit breakers, and optimize human-in-the-loop task routing.

  • Anonymized evaluation benchmarks published via our vendor-agnostic Agent Leaderboard.
  • Real-time alerts sent back to Sentry when recursive agent loops exceed safety thresholds.
  • Predictive SLA scoring matrices for enterprise AI code quality assurance.
04

Data Sharing & Disclosure

We enforce strict row-level context security (RLS). Codeaware does not sell, lease, or distribute source code or metadata to public LLM training clusters. Data is shared exclusively under secure sandbox guidelines.

  • Authorized Integrations: Secure API handshakes with GitHub webhooks, GitLab instances, Jira, and Sentry.
  • Legal Compliance: Disclosures required strictly under court order or to prevent malicious command-injection exploits.
05

Data Retention

We retain repository telemetry, FinOps spending data, and agent attribution scorecards only as long as necessary to fulfill active enterprise audit requirements.

  • Audit trail database indexes are automatically purged 90 days after subscription termination.
  • Transient RAG retrieval embeddings are stored in memory and permanently destroyed immediately after vector execution.
06

Your Rights & Data Subject Requests

Enterprise administrators and individual data subjects maintain complete self-service control over the footprint of tracked engineering workspaces, including the right to access, correct, and erase personal data under GDPR, CCPA, and equivalent frameworks.

  • Right to Erasure: Instantly trigger an out-of-band flush of cached agent behavioral analytics and PR index trees.
  • Context Isolation: Define workspace boundaries to prevent agents from viewing unauthorized modules.
  • Data Subject Access Requests (DSAR): Submit a verified request to security@codeaware.ai to receive a full export of the personal data processed on your behalf within 30 days.
07

Zero-Trust RAG Processing

Our Incident-to-Agent RAG Dispatcher operates under a strict zero-trust boundary. Retrieval-Augmented Generation never persists your proprietary codebase inside a durable vector store.

  • Ephemeral Embeddings: Vector embeddings generated for retrieval are held exclusively in-memory and destroyed immediately after the LLM context window is populated.
  • No Cross-Tenant Retrieval: Row-level security (RLS) enforces that retrieval requests can only surface vectors scoped to the requesting agent's authorized workspace boundary.
  • No Open-Model Training: Retrieved context is never used to fine-tune or train third-party foundation models.
08

Security & Sandbox Infrastructure

Security is the foundation of our zero-trust architecture. Codeaware executes all background verification builds in isolated, firewalled SOC2 sandboxes.

  • No persistent caching of actual file blobs; strictly transient AST (Abstract Syntax Tree) processing.
  • Strict network security controls to neutralize reverse-shell vulnerabilities in generated code.
09

Atlassian Personal Data Reporting API

As a verified Atlassian Marketplace partner, Codeaware implements the Atlassian Personal Data Reporting API to support GDPR Data Subject Access Requests (DSARs) initiated through connected Jira and Confluence accounts.

  • Reporting Endpoint: We expose POST /app/report-accounts/ so Atlassian can programmatically request a report of what personal data we hold for a given accountId.
  • 72-Hour Response Window: Personal data reports are generated and returned within 72 hours of a verified request, per Atlassian Marketplace compliance requirements.
  • Scope of Reporting: Reports cover Jira issue identifiers, display names, and avatar URLs cached for dispatch routing — never Atlassian account passwords or session tokens.
10

International Transfers

To provide redundant global monitoring, telemetry metrics may be securely transferred and cached within isolated European and United States SOC2 datacenters.

  • Transfers are safeguarded by Standard Contractual Clauses (SCCs) to maintain a persistent security posture.
11

Children's Privacy

Codeaware.ai is strictly designed as an enterprise software governance platform for professional developers and is not directed at or meant for children under 13.

12

Changes to This Policy

We may update this Privacy Policy to reflect changing compliance frameworks or support for new autonomous IDE systems. Major changes will be highlighted directly inside the dashboard control room.

13

Contact Us

For any questions regarding repository security boundaries, SOC2 sandbox auditing, or RLS parameters, reach our dedicated trust team:

  • Email: security@codeaware.ai
  • Office: 100 Pine Street, San Francisco, CA 94111

Security Compliance & Certifications

Codeaware is dedicated to upholding enterprise-grade privacy and zero-trust guidelines. Our background testing sandboxes are isolated from external model loops, satisfying strict compliance criteria.

GDPR & ATLASSIAN PRIVACY COMPLIANT
SOC 2 COMPLIANT INFRASTRUCTURE (GCP)
ATLASSIAN MARKETPLACE READY