AcquiCode diligence

Security and data handling

Source code is the most sensitive thing a company owns. This is exactly what happens to it.

Two ways to run

Local (CLI or CI). The analyzer runs on your infrastructure. The dossier contains paths, hashes, commit metadata and short structured values (license identifiers, URLs, trailer text), never source code. You can drop even those with --omit-extracts. Uploading a dossier is optional.

Hosted. For GitHub, access is granted per repository through a GitHub App with read-only permissions (contents, metadata, pull requests). Each scan mints a token scoped to one repository that expires within an hour and is never stored. The repository is cloned into an isolated working directory, analysed in a separate process with memory and time limits, and deleted when the scan ends, successful or not. Uploaded archives are deleted after analysis. GitLab project tokens are encrypted at rest and decrypted only for the clone.

What we keep

What we never do

Isolation

Every organisation-scoped table is protected by PostgreSQL row-level security keyed on the organisation of the current transaction, forced for the table owner, and the application role cannot bypass it. A query that forgets a filter returns nothing rather than another customer's data.

Deletion

Deleting a repository removes its scans, dossiers, declarations, change history and share links. Deleting an organisation removes everything it owns. Both are immediate and irreversible.

Verification

Hosted dossiers are signed (DSSE over an in-toto statement, Ed25519). The platform public key is published at /.well-known/acquicode-signing-key.pem. Anyone can check a dossier at /verify without signing in.

Reporting a vulnerability

See SECURITY.md in the source repository for the disclosure process.