Security & Compliance
Busfactor reads the most sensitive artifact your company has - how your engineering org actually works. Here is exactly how we protect it, who touches what, and where every framework stands.
Last updated 2026-08-02
Our commitments
These are the practices the platform is built on - not aspirations. Where something is still a roadmap item, it says so, below, in plain text.
The metric engine is deterministic code end to end. No language model reads your data, nothing of yours is sent to a model provider, and the same rows rerun to the identical byte.
To read history we take a read-only bare clone of the repos you connect and extract metadata from it: commit headers, file paths, and added/deleted line counts. File contents are never stored in the product database, never sent to a third party, and never sent to a model.
Stored data - including your connector tokens - is encrypted at rest with AES-256. Tokens are additionally sealed with a dedicated application key, separate from the database.
All traffic to the product and to your connected tools runs over TLS 1.2+. No plaintext transport, anywhere.
Every connector - GitHub, GitLab, Bitbucket, Azure DevOps, Linear, Sentry, Google Calendar, Calendar feed (.ics), CI - is read-only by construction. Busfactor never writes to, mutates, or acts on your systems.
You choose where your ingested data lives - EU (the default) or US - during onboarding. The two regions are separate deployments, so your choice is where the data physically sits, not a flag on a shared one. Moving an existing org between regions is a manual migration our team runs for you - ask support and we will schedule it.
Ask for the narrowest token scopes that work (read-only PATs, read scopes on Sentry). Internally, production access is restricted to the people who operate the platform, on a need-to-operate basis.
Shared, exported, and screenshot surfaces are always anonymized. Person names on sensitive findings are blurred by default and guarded by org- and user-level controls.
Certifications & frameworks
Send us your security review and it gets a real packet, this week: the control set, your questionnaire answered by someone who knows the code, an architecture and data-flow walkthrough, a DPA, and read-only scopes you can verify yourself in your own admin console. Most of the hard questions are already answered by the architecture above - a deterministic engine with no model in the path, metadata rather than file contents, and your region as a separate deployment rather than a flag.
Now the status, in one line: we hold no security certification today. We never claim one before the report is in hand, we never offer a report that doesn’t exist, and we don’t call an audit “in progress” before an auditor is engaged - so the statuses below are exactly where each framework really stands, and a status flips here the day the engagement is signed, not a day earlier. If a certificate is a hard gate for you this quarter, you now know that in ten seconds rather than three calls in. Everything else, ask: support@busfactor.tech.
On the roadmap, not started: no auditor is engaged and no observation window is running, so there is no report and no date to promise. What you can have today is the control set, our answers to your security questionnaire, and the architecture review - ask and we will send them.
On the certification roadmap, sequenced after SOC 2 Type II. Not started either - same offer in the meantime: controls, questionnaire, architecture.
We process engineering metadata, not patient data, and we run no HIPAA program today - there is no Business Associate Agreement waiting on a shelf. If your compliance team needs one scoped, talk to us and we will tell you honestly whether we can meet it.
Our data-handling practices follow GDPR: lawful basis, data-subject rights, EU residency option.
Enterprise controls
Enterprise controls, provisioned on demand - talk to us. These are provisioned per Enterprise agreement rather than self-serve toggles - if your security or identity setup needs one, tell us what you need and we’ll scope it: support@busfactor.tech.
Run Busfactor inside your own infrastructure under an enterprise agreement.
Run it with no outbound route at all. The engine is deterministic and LLM-free, so nothing needs to leave your perimeter.
Single sign-on against your identity provider, provisioned per agreement.
Data-processing and master service agreements tailored with your legal team.
Automated user provisioning and deprovisioning from your directory.
A response-time SLA and a named contact who knows your deployment, written into the agreement.
Detectors, metrics and integrations built for your stack, scoped per agreement.
Purchase orders, vendor onboarding and invoicing that fit your finance process.
Questionnaires, NDA’d documentation, and due-diligence support.
We sign Data Processing Agreements - a DPA covering the processing described below is available on request.
What we collect - and what we don’t
Busfactor ingests engineering metadata from the tools you connect: commits, pull requests, reviews, tickets, workflow runs, and the channels you explicitly point us at. We use it for one purpose - computing your org’s assessment - and nothing else.
- Connector tokens you provide are scoped read-only, encrypted, and shown back to you only as a masked suffix.
- Review-comment bodies used for classification are retained on a short, configurable TTL, then nulled.
- We don’t sell data, train models on your private data, or share it beyond the subprocessors listed below.
GDPR & data-subject rights
Your team’s members can exercise the full set of GDPR data-subject rights over the personal data (names, handles, work activity metadata) processed on your org’s behalf:
- Access & export - a copy of the personal data we hold, in a portable format.
- Rectification - identity records (merges, name fixes) are editable in the product.
- Erasure - deletion of a person’s data, or the whole org’s, on request.
Send data-subject requests to support@busfactor.tech - we verify and answer within the GDPR’s timelines.
Retention & deletion
- Ingested data is kept while your subscription is active - it is what your history and trends are computed from.
- Cancel, and your data is kept 90 days from the end of your term, then deleted (sooner on request).
- Full deletion requests are honored any time at support@busfactor.tech.
Subprocessors
The complete list of parties that process customer data on our behalf, and why. A connector only appears here once it actually ingests.
| Party | Purpose | Access |
|---|---|---|
| Cloud hosting provider | Runs the platform and stores ingested data in your selected region (EU or US). | Storage & compute |
| GitHub | Source of repository, pull-request, and review metadata you connect. | Read-only connector |
| GitLab | Source of repository, merge-request, and review metadata you connect. | Read-only connector |
| Bitbucket | Source of repository, pull-request, and review metadata you connect. | Read-only connector |
| Azure DevOps | Source of repository, pull-request, and review metadata you connect. | Read-only connector |
| Linear | Source of ticket and project metadata you connect. | Read-only connector |
| Sentry | Source of incident/error metadata you connect. | Read-only connector |
| Google Calendar | Source of meeting times, durations and attendee responses from the calendars you connect. Never event titles, descriptions, locations or meeting links. | Read-only connector |
| Calendar feed (.ics) | Source of meeting times, durations and attendee responses from the calendar feeds you publish or the exports you upload. Never event titles, descriptions, locations or meeting links. | Read-only connector |
| CI providers (e.g. GitHub Actions) | Source of workflow/deploy run metadata, read through your code-host connection. | Read-only connector |
Questions, reports, disclosures
Security questionnaires, NDA’d report requests, or a vulnerability to report: support@busfactor.tech. We read everything.