Security

We handle your code as if we wrote it ourselves.

Tenzai scans security-critical code. That responsibility shapes how we architect every system from first contact to ephemeral processing to encrypted storage.

Data handling

What we do with your source code

Your source code is a sensitive asset. We process it in ephemeral, isolated environments and do not retain it after a scan completes.

Ephemeral processing

Each scan runs in an isolated ephemeral environment that is destroyed when the scan finishes. Your code is never written to persistent storage during processing.

No model training on your code

We do not use your source code to train or fine-tune our models. Findings and fix proposals are generated from your code at scan time and discarded from the model pipeline immediately after.

Read-only authorization

OAuth and deploy key authorization is scoped to read access only on the repositories you select. Tenzai never requests write access to your repository host.

Architecture

How we protect findings and stored data

Encryption at rest and in transit

All finding data and account information is stored encrypted. All data in transit is encrypted using TLS 1.2 or higher.

Access controls

Tenzai employees do not have access to your findings or your code during processing. Internal access to customer data is restricted by role and logged.

Infrastructure isolation

Scan environments run in isolated containers with no network access. No scan can reach the internet or shared infrastructure during execution.

Data deletion

You can delete your account and all associated data at any time. Deletion requests are processed within 30 days. No residual data is retained.

Subprocessor transparency

We maintain a list of subprocessors with access to your data. We notify you before adding a new subprocessor and you may object to the change.

Audit logging

Team and Enterprise plans include audit logs of access events and configuration changes. Logs are tamper-evident and exportable for your own compliance records.

Responsible disclosure

Found a vulnerability in Tenzai?

We run a responsible disclosure program. If you find a security issue in our platform or infrastructure, report it and we will coordinate a fix with you before public disclosure.

Step 1

Submit your report

Email your finding to [email protected] with reproduction steps, impact assessment, and any supporting artifacts. We accept reports in English or Hebrew.

Step 2

We acknowledge within 72 hours

We confirm receipt and assign a severity rating within 72 hours of submission. For critical findings we aim to confirm within 24 hours.

Step 3

Coordinated fix and disclosure

We patch the issue and coordinate public disclosure timing with you. We credit security researchers in our release notes unless you prefer anonymity.

[email protected]