Security·Last updated July 2026

Your data
stays yours.

Prelint is the decision ledger for your codebase. It records why every change merged.

To do that, it reads your code — so this page explains exactly what we store, send, log, and delete.

Trusted where audits are not optional
Open infrastructure
Industry alliance
Critical energy sector
Open source

Prelint matters most where a merge can break more than a build. In these industries, product alignment is a security, compliance, and communications requirement — not a preference.

Every pull request is checked against your specs and guardrails, and the decision is recorded. That is why these teams run Prelint on every change.

The control your AI coding workflows are missing

Prelint reviews every pull request against what your product intends, and its verdict lands as a check on the merge.

Every decision is recorded — who reviewed, what was found, how it was resolved, and when. When your auditor asks “show me oversight of AI-written code,” you export the record instead of reconstructing it.

  • A recorded, independent review on every pull request
  • Findings and resolutions retained per change
  • Timestamps that show when review happened
  • Exports for SOC 2 change-management evidence
Talk to us about audit evidence

Frequently asked questions

Does Prelint execute my code?

No.

Prelint reviews code. It never executes repository code, and there is no code-execution environment in the product.

Do you train AI models on my data?

No.

By contract, not by policy. Prelint never trains models on your data, and neither does our model provider. Prompts are discarded after each response.

Do you share my data with third parties?

We use your data for one purpose — providing the service.

Every subprocessor that touches it, Amazon included, is on our published list and bound by a data processing agreement. We never sell your data.

Do you store my source code?

Your code is processed on audited, isolated, encrypted infrastructure. Each organization gets its own storage access point, and your workers can only ever mount your code.

If you close your account, we delete your data and hand you the auditable deletion log.

Can your employees access my code?

No.

Nobody at Prelint opens your data unless you ask us to — not for debugging, not for curiosity. Every access is logged, and the log belongs to you.

Can another customer see my data?

No.

Your data is reachable only through your account. Your files sit behind a dedicated access point — physically separated from other organizations — and every record is scoped to your organization.

Where is Prelint hosted?

Exclusively in the United States, on AWS infrastructure audited by an independent AWS Partner.

Who operates the AI models?

AWS.

Reviews run exclusively on available models via AWS Bedrock, inside the same AWS environment that hosts Prelint. Your code does not leave AWS, and zero retention applies by contract.

Are you GDPR compliant?

Yes.

A data processing agreement is available on request, and our subprocessor list is published and dated.

Are you CCPA compliant?

Yes.

We do not sell personal information, and we honor access and deletion requests. The details live in our privacy policy.

Are you SOC 2 compliant?

A Type I audit is in progress. The report is expected in Q3 2026, with Type II observation following.

Can I exclude sensitive files?

Yes.

Add a .prelintignore file to your repository, or set exclusions in the interface. Anything listed is excluded from analysis and never sent to a model.

Do you support self-hosting?

Enterprise plans include options for dedicated infrastructure and data residency requirements. Talk to us about your setup.

What happens when we offboard?

Erasure jobs delete your organization’s data — repositories, review records, and external stores. Your code and your record leave with you.

StorageYour code is stored on isolated infrastructure: each organization gets its own access point, and your workers can only ever mount your code. Encrypted at rest, backed up daily.
PermissionsNo admin access. No account-level permissions. Exactly five scopes: repository metadata (read), contents (read, plus write used only for opt-in suggested-fix commits), pull requests (read/write for posting and dismissing reviews), checks (read/write for status), and org membership (read). Anything more is unused.
EncryptionTLS 1.2+ in transit. AES-256 at rest across database, file storage, and queues. Key management sits under a continuous, audit-driven hardening program.
WebhooksEvery inbound GitHub event is verified with HMAC-SHA256 signatures and constant-time comparison before a single byte is processed.

Can you access my code?

Only when you ask. Always on the record.

Access to your data is a governed operation: it starts with your request, it’s scoped to your ticket, and it closes with a receipt.

Every touch lands in an audit log built to SOC 2 evidence standards — and the log belongs to you. It ships with your workspace, exportable by your admins, line by line.

Ask your current vendor to show you their access log. We show you ours.

audit/access-log.jsonl
2026-07-03T14:12:08Z  access.requested
  actor: support@prelint.com
  reason: "ticket #4821 - review stuck on PR 1204"
  scope: org/acme · read-only

2026-07-03T14:12:41Z  access.approved
  approved_by: you@acme.com

2026-07-03T14:20:17Z  access.closed
  duration: 7m36s · records_touched: 3
  export: available to org admins

Questions about security?

We are happy to walk through our security architecture, answer your questionnaire, or discuss your specific compliance needs.

Talk to us
Security questionnaires available on request
Etched illustration of a safe