Data handling
What we do with your source code
Your source code is a sensitive asset. We process it in ephemeral, isolated environments and do not retain it after a scan completes.
Ephemeral processing
Each scan runs in an isolated ephemeral environment that is destroyed when the scan finishes. Your code is never written to persistent storage during processing.
No model training on your code
We do not use your source code to train or fine-tune our models. Findings and fix proposals are generated from your code at scan time and discarded from the model pipeline immediately after.
Read-only authorization
OAuth and deploy key authorization is scoped to read access only on the repositories you select. Tenzai never requests write access to your repository host.
Architecture
How we protect findings and stored data
Encryption at rest and in transit
All finding data and account information is stored encrypted. All data in transit is encrypted using TLS 1.2 or higher.
Access controls
Tenzai employees do not have access to your findings or your code during processing. Internal access to customer data is restricted by role and logged.
Infrastructure isolation
Scan environments run in isolated containers with no network access. No scan can reach the internet or shared infrastructure during execution.
Data deletion
You can delete your account and all associated data at any time. Deletion requests are processed within 30 days. No residual data is retained.
Subprocessor transparency
We maintain a list of subprocessors with access to your data. We notify you before adding a new subprocessor and you may object to the change.
Audit logging
Team and Enterprise plans include audit logs of access events and configuration changes. Logs are tamper-evident and exportable for your own compliance records.
Responsible disclosure
Found a vulnerability in Tenzai?
We run a responsible disclosure program. If you find a security issue in our platform or infrastructure, report it and we will coordinate a fix with you before public disclosure.
Step 1
Submit your report
Email your finding to [email protected] with reproduction steps, impact assessment, and any supporting artifacts. We accept reports in English or Hebrew.
Step 2
We acknowledge within 72 hours
We confirm receipt and assign a severity rating within 72 hours of submission. For critical findings we aim to confirm within 24 hours.
Step 3
Coordinated fix and disclosure
We patch the issue and coordinate public disclosure timing with you. We credit security researchers in our release notes unless you prefer anonymity.