Security
How we protect what you connect: meetings, work items, and the repositories we read.
Our approach
Two of the most sensitive things a team has are its conversations and its source code, and Garlavatch reads both. We follow industry best practices to keep them safe and only process what you connect, for the purposes you switched it on for.
Repository access
Repository access is read-only and scoped to the repositories you select. We use it to derive the architecture map and code-ownership signals; we do not write to your repositories and we do not use your code to train models.
Encryption
Data is encrypted in transit with TLS and encrypted at rest. Connections to the tools you integrate are made over secure, authorised channels.
Access controls
Access within your workspace is governed by roles — owner, admin and member — so people only see what they should. Internally, access to production data is restricted and audited.
Infrastructure
We run on reputable cloud infrastructure with isolated environments and regular backups, so your data stays available and recoverable.
Compliance controls
SSO / SAML, custom data retention and an SLA are available for organisations with stricter compliance needs. These are agreed in writing rather than attached to a plan tier.
Reporting a vulnerability
Found something? We appreciate responsible disclosure. Email [email protected] and we'll get back to you quickly.