Security & Compliance
Enterprise-grade security from day one. Your code never leaves your repositories.
Infrastructure
- • Hosted on Azure France Central (GDPR-compliant region)
- • PostgreSQL with Row-Level Security — strict multi-tenant isolation
- • AES-256 encryption at rest, TLS 1.3 in transit
- • Azure Container Apps with private VNet, no public DB access
- • Automated daily backups with geo-redundancy (14-day retention)
Data & Privacy
- • We never store source code — only metadata (commits, PRs, metrics)
- • GDPR-compliant: data minimization, right to deletion, DPA available
- • Configurable data retention (90 days to 24 months by plan)
- • No data sharing with third parties — no ad tracking, no selling
- • Provider tokens encrypted with per-tenant keys (Azure Key Vault)
Authentication & Access
- • SSO via Microsoft Entra ID (Enterprise plan)
- • MFA support on all plans
- • Role-based access: Owner, Admin, Member, Viewer
- • API keys with configurable scopes and expiration
- • Complete audit trail of all administrative actions
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@devprism.io . We commit to acknowledging within 24h and providing a fix timeline within 72h.
Scope and ground rules
In scope: devprism.io, app.devprism.io and our public API. Please test only against an account you created yourself, and never access, alter or retain data belonging to someone else. No denial-of-service testing, no automated scanning at a rate that degrades the service, no social engineering of our team or our customers.
Rewards
We do not run a bug bounty programme and we do not offer monetary rewards — we would rather say so plainly than let you assume otherwise. For a report we accept, we are glad to credit you publicly, by the name you choose, on this page and in the changelog entry for the fix.