Security & Privacy
Your code is your business.
Here is how we treat it.
Code Swan builds a living catalog of your systems. That only works if you can trust us with access to your repositories, so here is, plainly, what we do and don't do with it.
- Read-only access to your repos, with no write scopes, ever
- Your code is never stored: scanned in memory, only metadata persists
- Your code is never used to train models
- Tenant isolation enforced at the database with row-level security
- Credentials encrypted with per-customer keys
- Disconnect and delete your data anytime
Where we are on compliance
We are an early-stage company, and we won't show badges we haven't earned. Code Swan does not hold SOC 2 or ISO 27001 certification today.
We have started the work toward SOC 2 Type II and we are at an early stage of it: writing and evidencing the internal controls an audit will test. To be precise about what that does and does not mean — no audit period is open, no auditor has been engaged to issue a report, and nothing here has been reviewed by a third party yet. We will update this page when an audit window opens, and again when it closes. ISO 27001 comes after.
If your security review needs answers now, we're happy to complete your security questionnaire directly and walk your team through our architecture, just ask.
And if your code cannot leave your network at all, a self-hosted deployment runs Code Swan on your own clusters, with your own LLM keys, entirely inside your perimeter.
Privacy
What we collect on this website, why, and under which legal basis is covered in our Privacy Policy. We don't sell data, we don't run ad trackers, and analytics only activates with your consent.
Reporting a vulnerability
Found something? We want to know. and we'll respond as fast as we can. Please give us a reasonable window to fix the issue before public disclosure.