Everything your security team asks first.
SOC2 roadmap, data retention, encryption in transit and at rest, code-data access controls, and the subprocessor list — the questions B2B buyers probe before attaching a security tool to their codebase.
SOC2 Type II in progress.
The controls are already wired through Pro and Enterprise. The audit window is running; the latest status letter is available on request.
| Control | Status |
|---|---|
| SOC2 Type II readiness | Audit window in progress with our third-party auditor; the readiness gap assessment is closed and the observation window is running. |
| Audit log export | Per-repo audit log (who/what/when) is available on Pro and Enterprise from day one — it ships before the SOC2 letter. |
| Scoped access tokens | GitHub App permissions are minimum-scope by default; per-installation token rotation on Enterprise. |
| Single-tenant region | EU/US data residency is an Enterprise option for organisations that need their ingest region pinned. |
Processed once, then dropped.
What we keep, for how long, and what you can pull out as evidence for your own security review.
Retention & training policy
- Diff plus surrounding context are processed once for the review and then dropped from the inference path.
- Nothing trains on your code — your repository never becomes model input, on any plan.
- Aggregated retention windows: 24h for hot staging, 30d for retry buffers, 90d for audit logs (exportable on Pro/Enterprise).
- Pro and Enterprise audit log export shows exactly what was read and when, so your security team has the receipts.
Encrypted in transit, encrypted at rest.
Speak-of-the-trade, no invented cipher suites — just the boundaries your security team already checks.
All client and ingest traffic is TLS 1.2 or higher. The GitHub App talks to GitHub over TLS, the Slack/Teams digest talks to those APIs over TLS, and the browser dashboard talks to our API over TLS. No service accepts plain HTTP on its public surface.
Persistent storage uses AES-256 standard encryption across the deployment. Per-tenant isolation keys are rotated on the platform schedule; Enterprise customers can pin a dedicated region for residency.
Your code stays yours.
Scope, audit, and IdP wiring — the three boundaries a security team asks about before granting repo access.
Access control
Read pull requests and the diff. Write inline issue comments as mergehound-bot. Nothing else — no source writes, no branch creation, no rebase, no merge, no clone of the repo outside the App.
Access control
Every read and write against your repo and your digest channel is captured with timestamp and reviewer id. Export it as CSV from the dashboard on Pro, or via the SOC2 evidence endpoint on Enterprise.
Access control
Enterprise plans wire SAML SSO and SCIM provisioning so seat membership stays in lockstep with your IdP — offboarding is just an IdP-side deprovision.
Who touches your review.
Every third party your data crosses paths with while running a review. If anyone changes, we email you first.
| Role | Vendor | Data handled |
|---|---|---|
| Ingest | GitHub | PR metadata and the diff under review |
| Digest delivery | Slack | Channel id, digest payload, no message history |
| Digest delivery | Microsoft Teams | Channel id, digest payload, no message history |
| Billing | Stripe | Customer id and purchase events (handled by the billing module) |
| Transactional email | Polsia email proxy | Recipient, message body, sent on behalf of mergehound@polsia.app |
| Hosting | Polsia render infrastructure | Audit logs, review state, and aggregated metrics |
| Review engine | Diff/Microscope vendor | Diff under review for the duration of inference; not retained for training |
Need the full packet?
Open a thread with our security team in one click, or send a quick note and we'll route it for you.
The fastest path to our full SOC2 status letter, controls map, DPA, and the complete subprocessor inventory is to email security@polsia.app. Average reply time: under one business day.
Request security docsOr use the form below — it goes to the same inbox and we'll route it to the right reviewer.
Send us a message