Skip to content

Security & Compliance

Enterprise-grade security from day one. Your code never leaves your repositories.

Infrastructure

  • • Hosted on Azure France Central (GDPR-compliant region)
  • • PostgreSQL with Row-Level Security — strict multi-tenant isolation
  • • AES-256 encryption at rest, TLS 1.3 in transit
  • • Azure Container Apps with private VNet, no public DB access
  • • Automated daily backups with geo-redundancy (14-day retention)

Data & Privacy

  • • We never store source code — only metadata (commits, PRs, metrics)
  • • GDPR-compliant: data minimization, right to deletion, DPA available
  • • Configurable data retention (90 days to 24 months by plan)
  • • No data sharing with third parties — no ad tracking, no selling
  • • Provider tokens encrypted with per-tenant keys (Azure Key Vault)

Authentication & Access

  • • SSO via Microsoft Entra ID (Enterprise plan)
  • • MFA support on all plans
  • • Role-based access: Owner, Admin, Member, Viewer
  • • API keys with configurable scopes and expiration
  • • Complete audit trail of all administrative actions

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@devprism.io . We commit to acknowledging within 24h and providing a fix timeline within 72h.

Scope and ground rules

In scope: devprism.io, app.devprism.io and our public API. Please test only against an account you created yourself, and never access, alter or retain data belonging to someone else. No denial-of-service testing, no automated scanning at a rate that degrades the service, no social engineering of our team or our customers.

Rewards

We do not run a bug bounty programme and we do not offer monetary rewards — we would rather say so plainly than let you assume otherwise. For a report we accept, we are glad to credit you publicly, by the name you choose, on this page and in the changelog entry for the fix.