Who controls your data
The organization operating your PatchProof deployment is the controller of account and workspace data. Self-hosted runner operators remain responsible for the repositories, environments, and infrastructure they connect.
Data PatchProof stores
The cloud stores account names and emails, workspace memberships and invitations, project and runner metadata, verification plans, statuses, deterministic risk findings, redacted logs, artifact metadata and selected artifact contents, security timestamps, and hashed credentials. PatchProof does not need full repository source in the control plane.
How data is used
Data is used to authenticate operators, isolate workspaces, route jobs to compatible runners, produce verification evidence, retain reports, deliver account email, prevent abuse, and operate the service.
Execution and source code
Repository cloning and command execution occur on self-hosted runners. Job payloads necessarily include the repository location, commands, and configured metadata required for that runner to perform the requested verification. The cloud must never execute that payload.
Retention and deletion
Run reports remain until the workspace operator removes the containing workspace data. Artifacts follow their configured retention period and scheduled pruning. Invitations expire automatically. Account deletion removes personal API tokens and memberships but is blocked when it would leave a workspace without an owner.
Service providers and transfers
The deployment operator chooses infrastructure, database, cache, mail, queue, and artifact-storage providers and is responsible for their data-processing terms and regions. PatchProof does not send source code to an external AI provider by default.
Your choices
Operators can update profile data, revoke personal API tokens, leave workspaces when another owner remains, and delete their account. Workspace owners control member roles, invitations, runner access, project lifecycle, and evidence retention.
Security
PatchProof uses verified accounts, role and tenant checks, hashed credentials, scoped tokens, throttling, secure response headers, log redaction, and bounded artifact handling. No system can guarantee absolute security; deployment operators must protect infrastructure and rotate exposed credentials.
Changes
Material changes should be published with a new effective date before they apply. Deployment operators are responsible for providing any additional jurisdiction-specific notice required for their users.