Security & data handling

Installing Passmuster ships your private source through a third party. That is the highest-trust thing we ask. Here is exactly what happens.

What leaves your infrastructure, and to whom

When a pull request is processed, your PR diff and the linked ticket's text are sent to Anthropic to generate the plan. That is the data that leaves your infrastructure, and Anthropic is who receives it.

We don't train on your code

We don't train on your code. The Anthropic account is configured for no-training and limited-or-zero data retention; your diffs and tickets are used to generate your plan and nothing else.

The access we request, and why

What we keep, and for how long

Ask us to delete your data and we purge your diffs, generated plans, and derived data within 7 days. Uninstall the GitHub App and your repositories go inactive immediately, with a 30-day recoverable grace before the same purge. We retain only the minimal billing/invoice records the law requires and audit-log entries that record what happened — never your source.

What we don't claim

We are not SOC2-certified and we don't offer an audit/compliance export. What we keep is a durable, queryable record of what was verified, and a Data Processing Agreement on request.

DPA on request

We sign a Data Processing Agreement on request. Email security@passmuster.io and we'll send one.

Subprocessors

The third parties we share data with are listed, with what each receives, on the subprocessors page.

Reporting a vulnerability

Email security@passmuster.io (also in /.well-known/security.txt). We read every report.