Data handling & repository security
How your code is received, processed, and permanently deleted.
Your code is never kept.
All repository data — clones, extracted files, analysis artifacts, and intermediate outputs — is permanently deleted within 24 hours of report delivery. We retain only the SHA-256 hash manifest (no source code) as a tamper-evidence record. No source code appears in any deliverable.
9-step repository lifecycle
Every engagement follows the same repeatable, auditable sequence — from access request to confirmed deletion.
Access request
You provide a read-only access token or temporary credential via a TLS-encrypted form. No credentials are stored beyond the review period.
Isolation
The repository is cloned into an isolated, single-use analysis environment.
Evidence freeze
SHA-256 hash computed for every file; a baseline tamper-evidence manifest is created and locked.
Read-only analysis
The automated evidence sweep runs across the 7 verification layers. No code is modified, executed, compiled, or deployed.
Analyst review
P0/P1 findings are reviewed manually. No data extraction beyond the automated sweep.
Report assembly
Deliverables are packaged. No raw source code is included — only file references and short excerpts cited as evidence.
Secure delivery
The report package is delivered to your corporate email via TLS-secured transfer.
Access revocation
You revoke the access token; we confirm revocation in writing.
Permanent deletion
All repository data, clones, and artifacts are permanently deleted within 24h of delivery. Deletion confirmation available on request within 5 business days.
What we do / what we do not do
WE DO
- ✓Clone your repository read-only into an isolated environment
- ✓Hash every file on first access (tamper-evidence)
- ✓Run automated evidence analysis across the 7 verification layers
- ✓Delete all repository data within 24h of delivery
- ✓Sign a mutual NDA before accessing any code (on request)
- ✓Provide deletion confirmation on request
WE DO NOT
- ✗Execute, compile, or deploy any code
- ✗Store source code beyond the review window
- ✗Share your code with third parties under any circumstances
- ✗Use your code to train AI or machine-learning models
- ✗Use your code for any purpose other than the requested review
- ✗Retain any repository data after the deletion window
Analysis environment security
Isolated, single-use
Each engagement gets its own environment — never shared between clients or reused.
Network-restricted
Outbound access is restricted during the active analysis phase.
Analyst-restricted access
Access is limited to the assigned analyst; no cross-engagement visibility.
Audit logging
Analyst actions are logged and auditable; logs available on request.
NDA process
Mutual NDA execution is complimentary and adds no time to your review clock.
Request an NDA in the Request Verification form — tick the NDA option at submission.
We send a mutual NDA (Abu Dhabi governing law) within 4 business hours.
Both parties sign via secure digital signing.
Repository access is shared only after the NDA is fully executed (when one is requested).
The review clock begins at first repository access — the NDA step adds no time.
Retention schedule
A clear record of what we hold, for how long, and on what basis. This schedule matches our Privacy Policy.
| Data type | Retention period | Basis |
|---|---|---|
| Repository data (clone, files, artifacts) | Deleted within 24h of delivery | Zero-retention policy |
| SHA-256 hash manifest | Retained indefinitely | Tamper-evidence reference (no source code) |
| Contact / request form submissions | 90 days | Service delivery + follow-up |
| Invoice & receipt records | 7 years | UAE Commercial Transactions Law |
| NDA records | 5 years from execution | Contractual obligation |
Regulatory alignment
Data-handling practices are designed to align with the following frameworks and standards.
UAE Federal PDPL — Law No. 45 of 2021
Data minimisation, purpose limitation, and retention limits applied across all engagement data.
CBUAE technology risk management guidance
Secure handling of third-party technology assets — access control, isolation, and audit trails.
ISO 27001 control principles (reference)
Access control, asset management, and information-handling principles applied as reference standards.
Proceed with an NDA included.
Request verification with a complimentary NDA — no delay to your review clock.