01
Access control
- GitHub access is scoped through OAuth or a GitHub App installation controlled by your organisation.
- Workspace access is checked against organisation membership and product permissions.
- Sessions use secure cookies in production, and sensitive server credentials are not exposed to the browser.
- You can revoke GitHub access from GitHub or disconnect an organisation from Mergent.
02
Code and agent isolation
- Agent runs work on a repository copy and propose changes through branches and pull requests.
- Preview builds are separated from the production application.
- Generated changes require review and are not treated as trusted merely because an AI produced them.
- Repository context sent to model providers is limited to what is needed for the requested task.
03
Data protection
- Transport encryption is used for connections to the service and its providers.
- GitHub credentials are encrypted at rest before database storage.
- Production secrets are kept in server-side environment configuration.
- Service providers are selected for established security and privacy controls.
04
Operational security
- We log relevant service and security events for troubleshooting and abuse detection.
- Dependencies and platform services are updated as risks are identified.
- Access is limited to what is needed to operate and support the service.
- Backups and recovery capabilities depend on the managed infrastructure used by the service.
05
Your responsibilities
Use least-privilege GitHub installations, review generated pull requests, protect your account, keep secrets out of prompts and repositories where possible, and promptly revoke access for people who leave your organisation.
06
Report a vulnerability
If you believe you found a vulnerability, contact us privately using the link below. Include a clear description, reproduction steps, and potential impact. Do not access data that is not yours, disrupt the service, or publish details before we have had a reasonable opportunity to investigate.
Questions?
Contact us about this document or request a signed DPA.
Contact Mergent