Trust Center
We’re a security company. Hold us to it.
You’re considering letting us look at your source code — the most sensitive thing you own. That instinct to be careful is correct, and it’s the constraint we designed around. Here is exactly how your code is handled, who touches it, and how to report an issue with our own systems.
How we handle your code
Read-only, always
We only ever read your code. Connections are read-only by construction — the GitHub App requests Contents + Metadata read scopes and nothing else, and you can revoke it in one click.
Ephemeral by default
Each scan runs in an isolated, sandboxed working copy that is deleted as soon as the scan finishes. Clone credentials are stripped immediately after checkout.
We store findings, not your source
Your source code is never persisted. We keep the audit findings (the vulnerability, the fix, where it was) so you have a report — not a copy of your repository.
No training on your code
Your code is never used to train models — not ours, and not our AI provider’s, under our commercial API terms. It is used only to produce your audit.
Secrets stay server-side
The AI model key and our API tokens live only on our servers, never in the browser and never in your report. We do not store repository access tokens in plaintext.
Isolated per customer
The platform is multi-tenant with database row-level security: every read is scoped to your organisation. One customer can never see another’s scans or findings.
Where your code goes (and doesn’t)
A single audit, end to end. Your source touches an ephemeral sandbox and is deleted; only the findings persist.
How you grant access
Ranked by how little we ask of you:
- GitHub App (read-only) — recommended. Install, pick the specific repositories, done. Least-privilege, one-click revocable, and only a repo admin can install it — so the install itself is your authorization. We store an installation reference, never a token.
- Archive upload. Prefer to grant no live access at all? Upload a snapshot; we never connect to your systems.
- Run-in-your-CI (planned). For teams whose code may never leave their perimeter — the engine runs inside your pipeline and only findings come back.
Platform security
- All traffic over HTTPS/TLS. The audit engine is reachable only with a server-side credential.
- Database row-level security enforces organisation isolation on every read.
- The AI model key and platform tokens are server-side only — never shipped to the browser, never written into your report. The report is Glober’s; the underlying model is not named in it.
- Archive uploads are extracted with path-traversal protection; scans run in sandboxed working directories cleaned up on completion.
Subprocessors
| Provider | Purpose | Region |
|---|---|---|
| Railway | Application hosting (engine + platform) | EU (eu-west) |
| Supabase | Database & authentication | EU (eu-west) |
| GitHub | Read-only source access — only for repositories you connect | Global |
| Frontier AI model provider | The audit reasoning (server-side). No training on your code. | US · identity available under NDA |
Compliance
We’re early, and we’d rather be precise than impressive:
- GDPR-aligned data handling — EU-hosted data, data minimisation (findings, not source), and the commitments above are how we operate today.
- SOC 2 — on our roadmap, not yet started. We’ll show status here honestly as it progresses, rather than claim a badge we haven’t earned.
- NIS2 / DORA aware — the same regimes we help clients meet inform how we run our own shop.
Responsible disclosure
Found a security issue in our systems? Thank you — please tell us.
- Email info@glober-security.com with steps to reproduce. Our security.txt lists the same contact.
- Safe harbour: we won’t pursue or support legal action against good-faith research that respects the rules below and gives us reasonable time to fix before public disclosure.
- Please don’t: access or modify other users’ data, run denial-of-service or spam tests, or use social engineering / physical attacks. Test only against your own account.
- We aim to acknowledge reports within a few business days.
Contact
Security or privacy questions, a subprocessor NDA request, or a due-diligence questionnaire: info@glober-security.com.
This page describes our current practices and will evolve as the product does. It is informational and not a contract; specific commitments are set out in your agreement with us.