Prelint is the decision ledger for your codebase. It records why every change merged.
To do that, it reads your code — so this page explains exactly what we store, send, log, and delete.
Prelint matters most where a merge can break more than a build. In these industries, product alignment is a security, compliance, and communications requirement — not a preference.
Every pull request is checked against your specs and guardrails, and the decision is recorded. That is why these teams run Prelint on every change.
Prelint reviews every pull request against what your product intends, and its verdict lands as a check on the merge.
Every decision is recorded — who reviewed, what was found, how it was resolved, and when. When your auditor asks “show me oversight of AI-written code,” you export the record instead of reconstructing it.
No.
Prelint reviews code. It never executes repository code, and there is no code-execution environment in the product.
No.
By contract, not by policy. Prelint never trains models on your data, and neither does our model provider. Prompts are discarded after each response.
We use your data for one purpose — providing the service.
Every subprocessor that touches it, Amazon included, is on our published list and bound by a data processing agreement. We never sell your data.
Your code is processed on audited, isolated, encrypted infrastructure. Each organization gets its own storage access point, and your workers can only ever mount your code.
If you close your account, we delete your data and hand you the auditable deletion log.
No.
Nobody at Prelint opens your data unless you ask us to — not for debugging, not for curiosity. Every access is logged, and the log belongs to you.
No.
Your data is reachable only through your account. Your files sit behind a dedicated access point — physically separated from other organizations — and every record is scoped to your organization.
Exclusively in the United States, on AWS infrastructure audited by an independent AWS Partner.
AWS.
Reviews run exclusively on available models via AWS Bedrock, inside the same AWS environment that hosts Prelint. Your code does not leave AWS, and zero retention applies by contract.
Yes.
A data processing agreement is available on request, and our subprocessor list is published and dated.
Yes.
We do not sell personal information, and we honor access and deletion requests. The details live in our privacy policy.
A Type I audit is in progress. The report is expected in Q3 2026, with Type II observation following.
Yes.
Add a .prelintignore file to your repository, or set exclusions in the interface. Anything listed is excluded from analysis and never sent to a model.
Enterprise plans include options for dedicated infrastructure and data residency requirements. Talk to us about your setup.
Erasure jobs delete your organization’s data — repositories, review records, and external stores. Your code and your record leave with you.
Only when you ask. Always on the record.
Access to your data is a governed operation: it starts with your request, it’s scoped to your ticket, and it closes with a receipt.
Every touch lands in an audit log built to SOC 2 evidence standards — and the log belongs to you. It ships with your workspace, exportable by your admins, line by line.
Ask your current vendor to show you their access log. We show you ours.
2026-07-03T14:12:08Z access.requested actor: support@prelint.com reason: "ticket #4821 - review stuck on PR 1204" scope: org/acme · read-only 2026-07-03T14:12:41Z access.approved approved_by: you@acme.com 2026-07-03T14:20:17Z access.closed duration: 7m36s · records_touched: 3 export: available to org admins
We are happy to walk through our security architecture, answer your questionnaire, or discuss your specific compliance needs.
Talk to us