Data & Security

Data handling & repository security

How your code is received, processed, and permanently deleted.

Our commitment

Your code is never kept.

All repository data — clones, extracted files, analysis artifacts, and intermediate outputs — is permanently deleted within 24 hours of report delivery. We retain only the SHA-256 hash manifest (no source code) as a tamper-evidence record. No source code appears in any deliverable.

Lifecycle

9-step repository lifecycle

Every engagement follows the same repeatable, auditable sequence — from access request to confirmed deletion.

1

Access request

You provide a read-only access token or temporary credential via a TLS-encrypted form. No credentials are stored beyond the review period.

2

Isolation

The repository is cloned into an isolated, single-use analysis environment.

3

Evidence freeze

SHA-256 hash computed for every file; a baseline tamper-evidence manifest is created and locked.

4

Read-only analysis

The automated evidence sweep runs across the 7 verification layers. No code is modified, executed, compiled, or deployed.

5

Analyst review

P0/P1 findings are reviewed manually. No data extraction beyond the automated sweep.

6

Report assembly

Deliverables are packaged. No raw source code is included — only file references and short excerpts cited as evidence.

7

Secure delivery

The report package is delivered to your corporate email via TLS-secured transfer.

8

Access revocation

You revoke the access token; we confirm revocation in writing.

9

Permanent deletion

All repository data, clones, and artifacts are permanently deleted within 24h of delivery. Deletion confirmation available on request within 5 business days.

Scope & limits

What we do / what we do not do

WE DO

  • Clone your repository read-only into an isolated environment
  • Hash every file on first access (tamper-evidence)
  • Run automated evidence analysis across the 7 verification layers
  • Delete all repository data within 24h of delivery
  • Sign a mutual NDA before accessing any code (on request)
  • Provide deletion confirmation on request

WE DO NOT

  • Execute, compile, or deploy any code
  • Store source code beyond the review window
  • Share your code with third parties under any circumstances
  • Use your code to train AI or machine-learning models
  • Use your code for any purpose other than the requested review
  • Retain any repository data after the deletion window
Environment

Analysis environment security

Isolated, single-use

Each engagement gets its own environment — never shared between clients or reused.

Network-restricted

Outbound access is restricted during the active analysis phase.

Analyst-restricted access

Access is limited to the assigned analyst; no cross-engagement visibility.

Audit logging

Analyst actions are logged and auditable; logs available on request.

NDA

NDA process

Mutual NDA execution is complimentary and adds no time to your review clock.

Request an NDA in the Request Verification form — tick the NDA option at submission.

We send a mutual NDA (Abu Dhabi governing law) within 4 business hours.

Both parties sign via secure digital signing.

Repository access is shared only after the NDA is fully executed (when one is requested).

The review clock begins at first repository access — the NDA step adds no time.

No extra cost. NDA execution is complimentary and adds no charge to your package.
Retention

Retention schedule

A clear record of what we hold, for how long, and on what basis. This schedule matches our Privacy Policy.

Data typeRetention periodBasis
Repository data (clone, files, artifacts)Deleted within 24h of deliveryZero-retention policy
SHA-256 hash manifestRetained indefinitelyTamper-evidence reference (no source code)
Contact / request form submissions90 daysService delivery + follow-up
Invoice & receipt records7 yearsUAE Commercial Transactions Law
NDA records5 years from executionContractual obligation
Alignment

Regulatory alignment

Data-handling practices are designed to align with the following frameworks and standards.

UAE Federal PDPL — Law No. 45 of 2021

Data minimisation, purpose limitation, and retention limits applied across all engagement data.

CBUAE technology risk management guidance

Secure handling of third-party technology assets — access control, isolation, and audit trails.

ISO 27001 control principles (reference)

Access control, asset management, and information-handling principles applied as reference standards.

These are statements of alignment intent, not certifications. VerifyCode is not ISO 27001 certified and is not a certification body.

Proceed with an NDA included.

Request verification with a complimentary NDA — no delay to your review clock.