Frequently asked questions
Everything people ask before pointing us at their org - the product, the data, the people-safety rules, the numbers, and the money.
The basics
What is Busfactor?
A brutally honest verdict on your engineering org. It connects read-only to the tools you already run on - code host, ticketing, chat, CI, incidents - computes deterministic metrics over that data, and delivers what a world-class fractional CTO would: an opinionated, evidence-linked diagnosis of what’s working, what’s quietly on fire, what it costs you, and how to fix it. Then it keeps watching.
How does it actually work?
You connect your tools (a few minutes, read-only tokens). Busfactor ingests the history, computes metrics - cycle-time anatomy, knowledge concentration, review health, investment allocation, quality signals and more - judges each one against expert bands calibrated to your org’s size, and turns the significant ones into findings and praises, each with two readings, a stance, receipts, and a fix. From then on it re-syncs on a schedule and tells you what moved.
Who is it for?
CTOs, VPs of Engineering, founders, and engineering managers who want a truthful read on how the org actually runs - without hiring a consultant or building a metrics team. It works from ~5 developers to a few hundred; judgment bands adapt to your size.
How is this different from a metrics dashboard?
Dashboards hand you sixty charts and make you do the judging. Busfactor takes a stance: every metric is graded (healthy / watch / bad) for your org size, every finding names a concrete problem, prices its consequence, links the exact PRs and tickets that prove it, and ends in a fix - a door, never a wall. Praise gets the same machinery as critique.
Connecting your tools
Which tools does it connect to?
A code host for repos, PRs and reviews (required - GitHub, GitLab, Bitbucket, Azure DevOps), Linear (tickets), Sentry (incidents and errors), and CI signals read through your code host (e.g. GitHub Actions workflow runs).
That is the whole list. If your stack needs something that is not on it, tell us before you buy: support@busfactor.tech.
What access does it need? Can it change anything in my repos?
No. Every connector is read-only by construction - Busfactor never writes to, mutates, or acts on your systems. You provide read-scoped tokens (e.g. a GitHub PAT with repo read); tokens are encrypted at rest and only ever shown back to you as a masked suffix.
How long does onboarding take?
Connecting takes minutes - a guided wizard walks you through tokens and repos (you can connect a whole GitHub org at once). The first analysis then clones and reads your history; first runs take a few minutes to complete depending on repo size. First verdict before your next standup.
Do I need to connect everything?
Only the code host is required. Ticketing sharpens the delivery picture considerably, and Sentry sharpens the incident and reliability signals. Everything except the code host is skippable and can be added later in Settings.
Data, privacy & security
Where is my data stored?
You choose: EU (the default) or US, picked during onboarding - the two regions are separate deployments, so your region is where your data physically sits. Moving an existing org between regions is a manual migration our team runs for you - ask support and we will schedule it. Details on the Security & Compliance page.
How is it protected?
Encryption at rest (AES-256) and in transit (TLS 1.2+), least-privilege access, read-only connector scopes, and connector tokens sealed with a dedicated application key. The full posture - including our subprocessor list - lives on the Security & Compliance page.
Are you SOC 2 / ISO 27001 / HIPAA certified?
No certificate today. What a security review does get, this week: the control set, your questionnaire answered, an architecture and data-flow walkthrough, EU or US data residency, read-only connector scopes, and a DPA. The metric engine is deterministic with no language model in the path, so your data is never handed to a model provider, and we read repository metadata - commit headers, file paths, line counts - rather than storing your file contents.
Framework by framework, from the same roster the Security & Compliance page renders:
- SOC 2 Type II - Planned. On the roadmap, not started: no auditor is engaged and no observation window is running, so there is no report and no date to promise. What you can have today is the control set, our answers to your security questionnaire, and the architecture review - ask and we will send them.
- ISO 27001 - Planned. On the certification roadmap, sequenced after SOC 2 Type II. Not started either - same offer in the meantime: controls, questionnaire, architecture.
- HIPAA (BAA) - On request. We process engineering metadata, not patient data, and we run no HIPAA program today - there is no Business Associate Agreement waiting on a shelf. If your compliance team needs one scoped, talk to us and we will tell you honestly whether we can meet it.
- GDPR - Aligned. Our data-handling practices follow GDPR: lawful basis, data-subject rights, EU residency option.
A status flips there the day the engagement is signed and not a day earlier: not yet, and we will not pretend otherwise. If a certificate is a hard gate for you this quarter, say so on the first call and we will tell you straight rather than run you through three: support@busfactor.tech. The live statuses are on the Security & Compliance page.
Do you train AI models on my data, or sell it?
No and no. Your org’s data is used for exactly one thing: computing your org’s assessment. See the Privacy Policy.
What happens to my data if I cancel?
Your access runs to the end of the paid term, then the account locks and nothing is deleted. We keep your data 90 days from there, then delete it - sooner if you ask (support@busfactor.tech). Data-subject requests (access, export, erasure) are honored any time.
People & fairness
Does it rank or shame individual engineers?
It ranks in the open, and it never shames. Standing orders your engineers on delivery, review, knowledge and momentum - and every position opens the pull requests behind it, so a position is evidence, never a vibe. A thin sample is labelled on the row, not hidden. Anyone marked exempt from negative surfaces leaves every ordering and stays anonymized, everywhere.
Where a finding involves a person, it still carries at least two interpretations, the evidence, and a fix - and everything shared, exported or screenshotted is anonymized by construction.
How does the anonymize toggle work?
Both the org and each user can control name visibility. By default, sensitive finding cards blur names and let you reveal on demand; working surfaces like the work log and directory show names (they’re operational, not verdicts). The toggle overrides either way.
And anything shared, exported, or screenshotted is always anonymized - that’s not a setting, it’s construction.
Can my manager use this against me?
The product is built to make that hard: receipts and a two-sided reading on every claim, exemptions that take a person off every negative surface, and always-anonymized sharing. Our terms also prohibit using assessments for automated adverse action against individuals. Praise, meanwhile, gets the same machinery as critique - half the product is credit.
The numbers & accuracy
Are the numbers made up by an AI?
Never. Numbers are computed deterministically from your connected data - same inputs, byte-identical outputs - and the writing layer is only allowed to quote them, never generate them. That rule is enforced mechanically: prose carries typed references that resolve to computed values, and lints reject anything else.
How do I know a finding is right?
Every finding carries receipts - the actual PRs, tickets, and events it was computed from, linked. You can click through and check. Findings also state their interpretation honestly: each one gives at least two readings of the data and says which it believes and why.
What are findings judged against?
Expert bands calibrated per org size - what healthy looks like for a 10-dev org differs from a 150-dev org. Bands and thresholds are inspectable, and org admins can tune every knob in Settings if their context genuinely differs.
Does a language model read our code?
No. Every measurement is deterministic code - no model touches a number - and the written diagnosis is composed from those computed values, so the same rows produce the same words. There is no language model in the product. The writing layer is pluggable, and if one is ever switched on it inherits the quote-only rule: prose may reference a computed value, never invent one.
Pricing & plans
What does it cost?
Per active dev, per month, billed annually: Pro €20/dev/mo (unlimited repos, near-live), Enterprise Talk to us (unlimited repos, custom). Monthly billing costs more - paying annually saves 33%. There is no seat cap on any tier and no feature behind a paywall: every tier runs the same product, and tiers differ only by capacity. Enterprise is quoted rather than published: it is sold on deployment (self-hosted or air-gapped, inside your own network) and priced per agreement. The full capacity table is on the pricing page.
What counts as an "active dev"?
Anyone who authored a commit, opened a pull request, or submitted a review on a connected repo in the trailing 60 days - counted once per person, after identity merges. Bots and accounts you have marked exempt never count, and a contribution from a git identity that is not linked to a person counts as nobody, so the number is a floor rather than an estimate. Settings → Plan shows you every person counted, what qualified them, and everyone excluded with the reason - so you can check the number instead of trusting it.
What happens when the free trial ends?
On day 15 the account locks until you subscribe. Nothing is deleted - your history, findings and receipts are kept and come straight back. Kept for 90 days. There is no card on file, so nothing charges you and there is nothing to cancel.
Is there a contract or a minimum term?
Not on the self-serve tiers - monthly billing is month to month, cancel anytime, and your subscription runs to the end of the paid period. Annual billing is a twelve-month term, which is what the 33% saving pays for. Enterprise is an annual agreement with a minimum commitment, agreed in the contract rather than published, which is the one place we do ask for a commitment.
How does this compare to hiring a consultant?
A fractional CTO engagement costs multiples of any tier and delivers a slide deck that goes stale the day it’s handed over. Busfactor delivers the diagnosis continuously, with receipts, on your live data - for 0.27% to 0.33% of the payroll it watches, depending on your tier (at €90,000 loaded cost per developer). Because the price is per dev, that share does not move with headcount. Check it yourself with the calculator on the landing page.
Getting started & leaving
How do I start?
Sign up, create your org, and the wizard walks you through connecting your code host (and optionally ticketing and Sentry), choosing your data region, and starting the first analysis. You watch it run live.
Do you support SSO?
Self-serve sign-in is email + password, with invite-based org roles. SSO/SAML and SCIM provisioning are provisioned on demand under Enterprise agreements - tell us what your identity setup needs: support@busfactor.tech.
Can we self-host / run on-prem?
Yes - under an Enterprise agreement. The self-serve product is cloud-hosted (EU or US, your choice); a self-hosted deployment inside your own infrastructure is provisioned per agreement. Talk to us: support@busfactor.tech.
Do you sign DPAs?
Yes. A Data Processing Agreement covering the processing described in our Privacy Policy is available on request, and custom DPA/MSA terms come with Enterprise agreements: support@busfactor.tech.
How do I cancel, and what happens then?
Cancel anytime - no retention dance. Your access runs to the end of the paid term, then your org’s data is kept 90 days and deleted (sooner on request). Export what you need first; findings and finance rollups have export surfaces built in.
I have a question this page doesn’t answer.
Write to support@busfactor.tech - a human reads it.