We scan code for a living.
We hold ourselves to the same bar.
Impact runs its own detector on its own source on every push. We use the same encryption, the same OAuth scopes, the same secret-management patterns we recommend to our customers. This page is a complete inventory of how that works.
Encrypted in transit and at rest
Every connection runs over TLS 1.3. Git PATs are AES-256-GCM encrypted before they touch our database. JWT secrets are stored exclusively in your cloud provider's secret manager (Azure Key Vault, AWS Secrets Manager, GCP Secret Manager).
Read-only by default
Impact analyzes your code. It does not modify it. The GitHub / GitLab / Bitbucket OAuth scopes we request are read-only on repository contents and metadata. We never request write access, push permission, or admin rights.
Single-tenant on request
Self-host the entire stack in your own VPC with our docker-compose bundle, or take our Enterprise tier for a dedicated GCP / AWS project managed by us. Your code never leaves your boundary.
No long-lived secrets in our source
We use the same hardcoded-credential detector on our own codebase as we ship to customers. Every push runs through it. CI fails if a real secret is committed.
Your source code
How we handle your code.
Analysis is read-only, storage is ephemeral, and you stay in control of your data.
We never train models on your source
Your code is used to analyze your code — nothing else. It is never used to train, fine-tune, or improve any model, ours or a third party's.
Analysis is strictly read-only
Impact reads and parses your repositories to produce metrics. It never writes, commits, or pushes. The scopes we request are read-only on contents and metadata.
Ephemeral scan storage
Source is cloned into isolated, short-lived scan storage for the duration of an analysis and removed once the scan completes. We keep the derived metrics, not your files.
Export and delete everything
You can export your data at any time and permanently delete your organization, projects, and associated records — a clean, complete takeout on your terms.
Data protection
Encrypted, isolated, and never leaked.
Defense in depth from the transport layer down to the last log line.
Encryption in transit and at rest
All traffic runs over TLS. Data persisted to our managed database and storage is encrypted at rest by default.
Per-tenant isolation
Every query is scoped by organization and project access. One tenant can never read another tenant's projects, scans, or metrics — isolation is enforced at the data layer.
Connected git tokens are encrypted
Personal access tokens and OAuth credentials for connected git providers are AES-256-GCM encrypted before they touch our database.
Secrets are never logged
Tokens, keys, and credentials are redacted from logs and telemetry. What flows into our observability pipeline never contains a usable secret.
Access & identity
Controls for who gets in, and what they can do.
Enterprise-grade identity, least-privilege roles, and a tamper-evident trail.
SSO and SAML
Bring your own identity provider with SAML-based single sign-on, so access follows your directory and offboarding is instant.
MFA / TOTP
Multi-factor authentication with time-based one-time passcodes (TOTP) adds a second factor on top of primary credentials.
Role-based access control
Assign viewer, analyst, or admin roles so each person sees exactly what their job requires — and nothing more.
Tamper-evident audit log
Sensitive actions are recorded in a hash-chained audit log. Each entry links to the previous one, so any alteration or deletion is detectable.
Session and token revocation
Revoke sessions and API tokens on demand. When access needs to end, it ends immediately across the platform.
Infrastructure
Where Impact runs.
Managed cloud infrastructure with isolated workers and guarded egress.
Google Cloud Platform
The platform runs on Google Cloud — Cloud Run for compute and Cloud SQL for Postgres — a managed, patched foundation we do not hand-roll.
Regional hosting
Compute and data are hosted in a defined cloud region, so you know where your analysis runs and where your metrics live.
Isolated scan workers
Repository scans run on isolated worker capacity, separated from the API and from other tenants' analysis so one scan can't reach into another.
SSRF-guarded cloning
Repository clone URLs are validated against an allowlist of known git hosts, with internal and private address ranges blocked to prevent server-side request forgery.
Controls Inventory
What we do, in detail.
Identity & Access
- JWT auth with short-lived access tokens (15 min) + refresh rotation
- Per-user tier overrides for granular access control
- Owner / Admin / Member / Viewer role-based access
- SAML 2.0 SSO via WorkOS (Enterprise tier)
- OAuth via GitHub / GitLab / Bitbucket with read-only scopes
- API key rotation with one-click revoke and per-key usage telemetry
Data Protection
- TLS 1.3 for all customer traffic; HSTS preload, modern cipher suites only
- AES-256-GCM encryption for Personal Access Tokens at rest
- Cloud SQL for PostgreSQL with encryption at rest and automated encrypted backups
- Per-environment secret isolation via Google Cloud Secret Manager
- No third-party trackers, no advertising pixels, no session replay
- PII minimization: we never store source code beyond the active analysis window
Application Security
- Rate-limited authentication endpoints (express-rate-limit)
- SSRF protection on user-supplied repo URLs (no internal-IP fetch)
- CORS allowlist enforced on every API surface
- Webhook payloads verified via HMAC-SHA256 (GitHub-app-style)
- Content Security Policy headers on every response
- All dependencies scanned against OSV.dev CVE feed on every deploy
Infrastructure
- Hosted on Google Cloud Run with a dedicated service account (no long-lived service creds)
- Structured request + audit logging — every config change tracked
- Encryption at rest for all persistent storage (Cloud SQL + Cloud Storage)
- DDoS protection via Google Cloud’s global network edge
- Backups every 4 hours, 30-day point-in-time restore
- Tear-down + redeploy verified weekly via the documented runbook
Detection & Response
- Application Insights alerts on error-rate spikes and auth anomalies
- Stripe webhook signature verification for every billing event
- OSV.dev CVE feed wired into analysis output — alerts on vulnerable deps
- Quarterly tabletop exercise for incident response procedures
- Coordinated disclosure: security@impactcodeanalysis.com with 90-day patch SLA
Vendor Management
- Google Cloud Platform (data hosting) — SOC 2 Type II, ISO 27001, FedRAMP High
- Stripe (billing) — SOC 2 Type II, PCI DSS Level 1
- Anthropic (AI explain) — SOC 2 Type II, no training on customer data
- Resend (email) — SOC 2 Type II
- WorkOS (SSO) — SOC 2 Type II
- Sub-processor list reviewed quarterly; updated in this page when it changes
Sub-processors
Who we rely on.
We keep the list short and honest. The current, complete sub-processor list is available on request, and customers are notified before it materially changes.
Need the full current list for a vendor review? Request it here.
Compliance Posture
Certifications & frameworks.
We tell you the truth about where we are, not where we want to be.
Controls in place today
Encryption in transit and at rest, per-tenant data isolation, encrypted git credentials, least-privilege role-based access, a tamper-evident audit log, and SSRF-guarded scanning are all live in production today. Formal third-party certifications are tracked below honestly — as attained, in progress, or on the roadmap — so you always know exactly where we stand.
Found a vulnerability?
We run a coordinated-disclosure program. Email security@impactcodeanalysis.com with reproduction steps. We acknowledge within 24 hours, patch within 90 days, and credit you in the changelog (your choice).
Please do not file disclosure reports as public GitHub issues.
Responsible Disclosure
Security researchers, we want to hear from you.
If you have found a potential vulnerability, report it and we will work with you to confirm, fix, and credit it.
Our commitment
We acknowledge every good-faith report, keep you updated on our progress, and work to remediate confirmed issues promptly. With your permission, we are happy to credit you once a fix has shipped.
Safe harbor
We will not pursue legal action for security research conducted in good faith under this policy — testing that avoids privacy violations, data destruction, and service disruption, and that stops at the first sign of access and reports promptly. Please do not access other customers' data or run automated attacks against production.
Data Processing Agreement
A DPA covering how we process personal data on your behalf — including sub-processor terms and international transfer safeguards — is available for customers on request. Request a DPA and we will turn it around quickly.
Need a DPA, BAA, or security questionnaire?
We turn around standard procurement docs in under 48 hours. If you're filling out a security review, we have pre-completed CAIQ / SIG / VSA responses ready to send.