AWS production environment
Run production reviews and background workloads in Connectory's production AWS environment.
Use this page to review available controls, pull-request data flow, and deployment options with the teams responsible for engineering risk.
Code is processed in an isolated, stateless pipeline. Only review metadata is persisted, never your source code.
PR Created
GitHub webhook
Connectory Engine
In-memory processing
Policy Check
Rules & standards
AI Analysis
Isolated, stateless
Review Posted
PR comments
Audit Log
Metadata only
Enterprise-grade controls designed for teams shipping to production in regulated environments.
Independently audited with continuous monitoring across security, availability, and confidentiality trust service criteria.
All persisted data encrypted with AES-256. API keys and tokens stored in isolated, hardware-backed vaults.
All data transmitted over TLS 1.3 with forward secrecy. No plaintext communication at any layer.
See how pull-request context moves from GitHub into a review and back. The privacy policy has the current data-handling details.
Connectory evaluates each pull request against the policies and patterns configured for that repository.
Enterprise identity management with SAML 2.0 single sign-on and SCIM provisioning for automated user lifecycle.
Role-based access controls with principle of least privilege. Granular permissions per repository, team, and org.
Run Connectory entirely within your infrastructure. Full data sovereignty, no code ever leaves your network.
Connectory is designed to support your compliance posture across the major frameworks your legal and security teams care about.
Security (CC6)
Logical and physical access controls restrict unauthorized access to data and systems.
Availability (A1)
Availability commitments, monitoring responsibilities, and response paths are documented for the applicable plan.
Confidentiality (C1)
Confidential information is protected through encryption, access controls, and retention policies.
Processing Integrity (PI1)
System processing is complete, valid, and authorized, reviews are not altered in transit.
Privacy (P1)
Personal information is collected, used, retained, and disclosed in conformity with commitments.
Data minimization
Only the minimum personal data necessary is collected and processed for each purpose.
Right to erasure
Data subjects can request deletion of their personal data within the timelines mandated by Art. 17.
DPA available
A Data Processing Agreement is available for all enterprise customers who require it.
Breach notification 72h
Connectory commits to notifying affected controllers within 72 hours of discovering a personal data breach.
SCCs for transfers
Standard Contractual Clauses are in place for all international data transfers outside the EEA.
Right to know
Consumers can request disclosure of personal information collected, used, or disclosed about them.
Right to delete
Consumer deletion requests are honored within 45 days with verification processes in place.
No sale of PI
Connectory does not sell personal information to third parties under any circumstances.
Opt-out mechanisms
Clear opt-out mechanisms are provided for data collection beyond core service delivery.
Annual review
Privacy practices are reviewed annually to maintain compliance as regulations evolve.
A.8 Asset management
Information assets are inventoried, classified, and managed throughout their lifecycle.
A.9 Access control
Access to information and systems is restricted based on business and security requirements.
A.10 Cryptography
Cryptographic controls protect data confidentiality, integrity, and authenticity in transit and at rest.
A.12 Operations security
Operational procedures and responsibilities ensure secure information processing facilities.
A.14 System acquisition
Security requirements are integrated into the development lifecycle for all new systems.
AC, Access Control
Policy and procedures limit system access to authorized users, processes, and devices.
AU, Audit & Accountability
Audit records are created, reviewed, and protected to support accountability requirements.
SC, System & Comms Protection
Communications are monitored, controlled, and protected at external boundaries and key internal points.
SI, System & Info Integrity
Systems are protected against malicious code, flaws are identified and corrected in a timely manner.
RA, Risk Assessment
Risk assessments are conducted periodically and upon significant changes to the system environment.
Production on AWS
Connectory runs production reviews and background workloads on AWS. Enterprise customers define service targets, support response, and recovery responsibilities during contracting and onboarding.
Run production reviews and background workloads in Connectory's production AWS environment.
Track review execution and background work so support teams can investigate failed or delayed jobs.
Define the backup, restore, and recovery requirements that matter to your repositories and review process.
Document support contacts, response expectations, and incident ownership before launch.
Enterprise plans turn reliability requirements into clear operating responsibilities for launch and support.
Uptime targets
Set the service target for your Enterprise plan in the customer agreement.
Support response
Agree on severity levels, response expectations, and the people to contact.
Recovery ownership
Record who coordinates recovery across Connectory, GitHub, AWS, and your team.
A structured, time-bound process ensures every security event is handled consistently, from the first alert to the final post-mortem.
Automated monitoring surfaces anomalous behaviour across infrastructure, application, and security telemetry streams.
On-call engineers classify incident severity, notify relevant teams, and open a dedicated incident channel.
Affected systems are isolated to limit blast radius. Evidence is preserved for forensic analysis before remediation begins.
Root cause is identified, a targeted fix is developed and tested, then deployed through the standard change management pipeline.
A blameless retrospective documents timeline, root cause, and corrective actions. Findings feed back into process improvement.
Every integration surface is hardened with authentication, traffic controls, and cryptographic verification.
Industry-standard protocols protecting every API request from the first call.
Fair usage enforcement that protects platform stability for all tenants.
Every outbound event is signed and verified so your systems only accept authentic payloads.
// Verify incoming webhook signature
import { createHmac, timingSafeEqual } from "crypto"
function verifyWebhookSignature(
payload: string,
signature: string,
secret: string,
timestamp: string,
): boolean {
// Reject stale events (>5 min old)
const age = Date.now() / 1000 - parseInt(timestamp, 10)
if (age > 300) return false
const expected = createHmac("sha256", secret)
.update(`${timestamp}.${payload}`)
.digest("hex")
const sigBuffer = Buffer.from(signature.replace("sha256=", ""), "hex")
const expBuffer = Buffer.from(expected, "hex")
return timingSafeEqual(sigBuffer, expBuffer)
}Timing-safe comparison prevents length-based timing attacks. All webhook deliveries include a X-Connectory-Signature and X-Connectory-Timestamp header.
We welcome security researchers who help make Connectory safer. If you discover a potential vulnerability, please report it privately so we can investigate and remediate before any public disclosure.
In scope
Out of scope
Report
Email security@connectory.ai with a clear description, reproduction steps, and any proof-of-concept. PGP encryption available on request.
Acknowledge
We confirm receipt within 24 hours and assign a tracking reference so you always know the status of your report.
Investigate
Our security team triages and validates the finding. We may reach out for clarification and will keep you updated throughout.
Fix & Disclose
Once resolved, we coordinate disclosure timing with you and publish a summary (where appropriate). You are credited by name or alias.
Send vulnerability reports to security@connectory.ai. We support PGP-encrypted submissions, request our public key in your initial message and we will provide it promptly.
Please include: affected component, reproduction steps, impact assessment, and any supporting screenshots or PoC code.
We deeply appreciate the work of security researchers. Reporters of valid, in-scope vulnerabilities are publicly acknowledged in our security advisories, by full name, alias, or anonymously, according to your preference.
While we do not currently operate a paid bug-bounty programme, we recognise every researcher who helps us protect our customers.
We work with enterprise security teams through procurement. Request our SOC 2 report, penetration test results, or schedule an architecture review.