Skip to content
GLOBER SECURITY
Who we serve Services Free tools Trust Sign in Book a call

Trust Center

We’re a security company. Hold us to it.

You’re considering letting us look at your source code — the most sensitive thing you own. That instinct to be careful is correct, and it’s the constraint we designed around. Here is exactly how your code is handled, who touches it, and how to report an issue with our own systems.

How we handle your code

Read-only, always

We only ever read your code. Connections are read-only by construction — the GitHub App requests Contents + Metadata read scopes and nothing else, and you can revoke it in one click.

Ephemeral by default

Each scan runs in an isolated, sandboxed working copy that is deleted as soon as the scan finishes. Clone credentials are stripped immediately after checkout.

We store findings, not your source

Your source code is never persisted. We keep the audit findings (the vulnerability, the fix, where it was) so you have a report — not a copy of your repository.

No training on your code

Your code is never used to train models — not ours, and not our AI provider’s, under our commercial API terms. It is used only to produce your audit.

Secrets stay server-side

The AI model key and our API tokens live only on our servers, never in the browser and never in your report. We do not store repository access tokens in plaintext.

Isolated per customer

The platform is multi-tenant with database row-level security: every read is scoped to your organisation. One customer can never see another’s scans or findings.

Where your code goes (and doesn’t)

A single audit, end to end. Your source touches an ephemeral sandbox and is deleted; only the findings persist.

Your repository read-only access Ephemeral sandbox audit runs here AI reasoning · server-side deleted after scan Findings only encrypted · EU · org-isolated Your dashboard source code is never persisted no training on your code · secrets never leave our servers

How you grant access

Ranked by how little we ask of you:

  1. GitHub App (read-only) — recommended. Install, pick the specific repositories, done. Least-privilege, one-click revocable, and only a repo admin can install it — so the install itself is your authorization. We store an installation reference, never a token.
  2. Archive upload. Prefer to grant no live access at all? Upload a snapshot; we never connect to your systems.
  3. Run-in-your-CI (planned). For teams whose code may never leave their perimeter — the engine runs inside your pipeline and only findings come back.

Platform security

  • All traffic over HTTPS/TLS. The audit engine is reachable only with a server-side credential.
  • Database row-level security enforces organisation isolation on every read.
  • The AI model key and platform tokens are server-side only — never shipped to the browser, never written into your report. The report is Glober’s; the underlying model is not named in it.
  • Archive uploads are extracted with path-traversal protection; scans run in sandboxed working directories cleaned up on completion.

Subprocessors

Provider Purpose Region
Railway Application hosting (engine + platform) EU (eu-west)
Supabase Database & authentication EU (eu-west)
GitHub Read-only source access — only for repositories you connect Global
Frontier AI model provider The audit reasoning (server-side). No training on your code. US · identity available under NDA

Compliance

We’re early, and we’d rather be precise than impressive:

  • GDPR-aligned data handling — EU-hosted data, data minimisation (findings, not source), and the commitments above are how we operate today.
  • SOC 2 — on our roadmap, not yet started. We’ll show status here honestly as it progresses, rather than claim a badge we haven’t earned.
  • NIS2 / DORA aware — the same regimes we help clients meet inform how we run our own shop.

Responsible disclosure

Found a security issue in our systems? Thank you — please tell us.

  • Email info@glober-security.com with steps to reproduce. Our security.txt lists the same contact.
  • Safe harbour: we won’t pursue or support legal action against good-faith research that respects the rules below and gives us reasonable time to fix before public disclosure.
  • Please don’t: access or modify other users’ data, run denial-of-service or spam tests, or use social engineering / physical attacks. Test only against your own account.
  • We aim to acknowledge reports within a few business days.

Contact

Security or privacy questions, a subprocessor NDA request, or a due-diligence questionnaire: info@glober-security.com.

This page describes our current practices and will evolve as the product does. It is informational and not a contract; specific commitments are set out in your agreement with us.

GLOBER SECURITY

Verified security testing, one-click remediation and continuous monitoring.

Product

How it works Services Sign in

Trust

Trust Center Responsible disclosure security.txt

Legal

Terms of Service Privacy Policy
© 2026 Glober Security. All rights reserved. United States · info@glober-security.com