Security
Review how SlopBuster handles pull-request data, which controls are available, and which deployment option fits your environment.
SOC 2 Type II Compliance
SlopBuster maintains SOC 2 Type II certification with regular third-party audits and penetration testing. Our security controls cover data encryption, access management, incident response, and change management.
Data Handling
Review lifecycle
See how pull-request context moves from GitHub into a review and back. The privacy policy has the current data-handling details.
Repository context
Connectory evaluates each pull request against the policies and patterns configured for that repository.
Encrypted in transit and at rest
All data is encrypted using TLS 1.3 in transit and AES-256 at rest. API keys and tokens are stored in isolated vaults.
Self-Hosted Option
On Interstellar plans, you can run SlopBuster entirely within your own infrastructure. No code ever leaves your network. This provides full data sovereignty and compliance with the strictest regulatory requirements.
GitHub App Permissions
SlopBuster requests the minimum permissions needed to function:
No write access to code is requested. SlopBuster cannot push commits or modify your repository contents.
For a full overview of our security controls, compliance frameworks, data flow architecture, and deployment options, visit our Security & Compliance page.