BUSFACTOR.TECH
Trust

Security & Compliance

Busfactor reads the most sensitive artifact your company has - how your engineering org actually works. Here is exactly how we protect it, who touches what, and where every framework stands.

Last updated 2026-08-02

Our commitments

These are the practices the platform is built on - not aspirations. Where something is still a roadmap item, it says so, below, in plain text.

No model in the path

The metric engine is deterministic code end to end. No language model reads your data, nothing of yours is sent to a model provider, and the same rows rerun to the identical byte.

Metadata, not file contents

To read history we take a read-only bare clone of the repos you connect and extract metadata from it: commit headers, file paths, and added/deleted line counts. File contents are never stored in the product database, never sent to a third party, and never sent to a model.

Encryption at rest

Stored data - including your connector tokens - is encrypted at rest with AES-256. Tokens are additionally sealed with a dedicated application key, separate from the database.

Encryption in transit

All traffic to the product and to your connected tools runs over TLS 1.2+. No plaintext transport, anywhere.

Read-only connectors

Every connector - GitHub, GitLab, Bitbucket, Azure DevOps, Linear, Sentry, Google Calendar, Calendar feed (.ics), CI - is read-only by construction. Busfactor never writes to, mutates, or acts on your systems.

EU / US data residency

You choose where your ingested data lives - EU (the default) or US - during onboarding. The two regions are separate deployments, so your choice is where the data physically sits, not a flag on a shared one. Moving an existing org between regions is a manual migration our team runs for you - ask support and we will schedule it.

Least-privilege access

Ask for the narrowest token scopes that work (read-only PATs, read scopes on Sentry). Internally, production access is restricted to the people who operate the platform, on a need-to-operate basis.

Anonymization by default

Shared, exported, and screenshot surfaces are always anonymized. Person names on sensitive findings are blurred by default and guarded by org- and user-level controls.

Certifications & frameworks

Send us your security review and it gets a real packet, this week: the control set, your questionnaire answered by someone who knows the code, an architecture and data-flow walkthrough, a DPA, and read-only scopes you can verify yourself in your own admin console. Most of the hard questions are already answered by the architecture above - a deterministic engine with no model in the path, metadata rather than file contents, and your region as a separate deployment rather than a flag.

Now the status, in one line: we hold no security certification today. We never claim one before the report is in hand, we never offer a report that doesn’t exist, and we don’t call an audit “in progress” before an auditor is engaged - so the statuses below are exactly where each framework really stands, and a status flips here the day the engagement is signed, not a day earlier. If a certificate is a hard gate for you this quarter, you now know that in ten seconds rather than three calls in. Everything else, ask: support@busfactor.tech.

SOC 2 Type IIPlanned

On the roadmap, not started: no auditor is engaged and no observation window is running, so there is no report and no date to promise. What you can have today is the control set, our answers to your security questionnaire, and the architecture review - ask and we will send them.

ISO 27001Planned

On the certification roadmap, sequenced after SOC 2 Type II. Not started either - same offer in the meantime: controls, questionnaire, architecture.

HIPAA (BAA)On request

We process engineering metadata, not patient data, and we run no HIPAA program today - there is no Business Associate Agreement waiting on a shelf. If your compliance team needs one scoped, talk to us and we will tell you honestly whether we can meet it.

GDPRAligned

Our data-handling practices follow GDPR: lawful basis, data-subject rights, EU residency option.

Enterprise controls

Enterprise controls, provisioned on demand - talk to us. These are provisioned per Enterprise agreement rather than self-serve toggles - if your security or identity setup needs one, tell us what you need and we’ll scope it: support@busfactor.tech.

Self-hosted / on-prem

Run Busfactor inside your own infrastructure under an enterprise agreement.

Air-gapped deployment

Run it with no outbound route at all. The engine is deterministic and LLM-free, so nothing needs to leave your perimeter.

SSO / SAML

Single sign-on against your identity provider, provisioned per agreement.

Custom DPA & MSA

Data-processing and master service agreements tailored with your legal team.

SCIM provisioning

Automated user provisioning and deprovisioning from your directory.

SLA & named support

A response-time SLA and a named contact who knows your deployment, written into the agreement.

Custom development

Detectors, metrics and integrations built for your stack, scoped per agreement.

Procurement & invoicing

Purchase orders, vendor onboarding and invoicing that fit your finance process.

Security review & DD

Questionnaires, NDA’d documentation, and due-diligence support.

We sign Data Processing Agreements - a DPA covering the processing described below is available on request.

What we collect - and what we don’t

Busfactor ingests engineering metadata from the tools you connect: commits, pull requests, reviews, tickets, workflow runs, and the channels you explicitly point us at. We use it for one purpose - computing your org’s assessment - and nothing else.

GDPR & data-subject rights

Your team’s members can exercise the full set of GDPR data-subject rights over the personal data (names, handles, work activity metadata) processed on your org’s behalf:

Send data-subject requests to support@busfactor.tech - we verify and answer within the GDPR’s timelines.

Retention & deletion

Subprocessors

The complete list of parties that process customer data on our behalf, and why. A connector only appears here once it actually ingests.

PartyPurposeAccess
Cloud hosting providerRuns the platform and stores ingested data in your selected region (EU or US).Storage & compute
GitHubSource of repository, pull-request, and review metadata you connect.Read-only connector
GitLabSource of repository, merge-request, and review metadata you connect.Read-only connector
BitbucketSource of repository, pull-request, and review metadata you connect.Read-only connector
Azure DevOpsSource of repository, pull-request, and review metadata you connect.Read-only connector
LinearSource of ticket and project metadata you connect.Read-only connector
SentrySource of incident/error metadata you connect.Read-only connector
Google CalendarSource of meeting times, durations and attendee responses from the calendars you connect. Never event titles, descriptions, locations or meeting links.Read-only connector
Calendar feed (.ics)Source of meeting times, durations and attendee responses from the calendar feeds you publish or the exports you upload. Never event titles, descriptions, locations or meeting links.Read-only connector
CI providers (e.g. GitHub Actions)Source of workflow/deploy run metadata, read through your code-host connection.Read-only connector

Questions, reports, disclosures

Security questionnaires, NDA’d report requests, or a vulnerability to report: support@busfactor.tech. We read everything.