Garlavatch
Legal

Security

How we protect what you connect: meetings, work items, and the repositories we read.

01

Our approach

Two of the most sensitive things a team has are its conversations and its source code, and Garlavatch reads both. We follow industry best practices to keep them safe and only process what you connect, for the purposes you switched it on for.

02

Repository access

Repository access is read-only and scoped to the repositories you select. We use it to derive the architecture map and code-ownership signals; we do not write to your repositories and we do not use your code to train models.

03

Encryption

Data is encrypted in transit with TLS and encrypted at rest. Connections to the tools you integrate are made over secure, authorised channels.

04

Access controls

Access within your workspace is governed by roles — owner, admin and member — so people only see what they should. Internally, access to production data is restricted and audited.

05

Infrastructure

We run on reputable cloud infrastructure with isolated environments and regular backups, so your data stays available and recoverable.

06

Compliance controls

SSO / SAML, custom data retention and an SLA are available for organisations with stricter compliance needs. These are agreed in writing rather than attached to a plan tier.

07

Reporting a vulnerability

Found something? We appreciate responsible disclosure. Email [email protected] and we'll get back to you quickly.