[ SECURITY & PRIVACY ]

Your code never leaves
your control.

Anchoria reads your codebase to build a structural model — it does not store raw source code. Here's exactly what we access, what we keep, and how we protect it.

No raw source stored
Read-only GitHub OAuth
Encrypted at rest
Delete on request
Data Access
What does Anchoria read?

File paths, import statements, function signatures, and call relationships. We parse structure — not logic, strings, or secrets.

Does Anchoria store my code?

No. We build a structural graph from your repo and store that graph. Raw source files are discarded after the scan completes.

What OAuth scopes do you need?

Read-only repo access (contents:read, metadata:read). We never request write permissions.

Infrastructure
Where is data processed?

Scans run in isolated, short-lived compute containers. No scan shares infrastructure with another tenant.

How is data encrypted?

AES-256 at rest. TLS 1.3 in transit. Encryption keys are rotated quarterly.

What regions are available?

US-East by default. EU region available on Enterprise plans. Data residency guarantees on request.

Access Control
Who on my team can see scan results?

Admins configure role-based access. Engineers see full output; PMs and founders see plain-language summaries only if you choose.

Can I revoke access?

Yes — at any time from your GitHub OAuth settings or from the Anchoria dashboard. All associated data is queued for deletion within 24h.

Do Anchoria employees see my code?

No. Support engineers can access metadata (scan status, error logs) with your explicit permission. Source or graph data requires a separate, logged approval.

Compliance
Are you SOC 2 certified?

SOC 2 Type II audit is in progress. Expected completion Q3 2025. Full report shared under NDA for enterprise customers.

Do you sign BAAs / DPAs?

DPAs are available for Enterprise plans. Contact sales for a signed copy.

How do I request data deletion?

Email privacy@anchoria.dev or use the dashboard. We process deletion requests within 7 business days and confirm in writing.

Still have security questions?Our team is happy to walk through our architecture in detail.
Talk to security team →