This page covers the hosted platform at repowise.dev: how it handles your code and account data. For self-hosted Repowise, where code never leaves your machines, see Security and data handling (self-hosted). The scanning product that runs on Hosted is the Security suite, and the free scan in the open-source engine is Security signals.
Where Hosted runs
Hosted is a managed service that Repowise operates on third-party cloud providers. Those providers are named as sub-processors in the privacy policy, which is the authoritative list.
If your code cannot leave your own network, Hosted is the wrong fit. Run self-hosted Repowise on your machines, or talk to us about a customer-managed deployment.
What happens to your source code
- Indexing runs in an isolated, short-lived container. Your repository is cloned into a temporary directory inside it.
- The pipeline parses the code and reads git history to build the index.
- The clone is deleted at the end of every run, including runs that fail.
Git credentials are passed to the clone in a way that keeps them out of logs. Private repositories are read through a read-only GitHub App install.
What is stored after indexing
Raw source is not kept. Only data derived from it persists:
- Documentation pages
- The dependency graph
- Git metadata such as hotspots and ownership
- Architectural decisions
- Code-health findings
- Embeddings for semantic search
Private repository data is isolated per account with row-level access controls tied to the signed-in user. Large artifacts for public repositories go to a separate public artifact store, and private repository data is never written there.
For secret detection, only a fingerprint and a redacted preview of each finding are stored, never the secret value.
When a model sees your code
The dependency graph, git analysis, code health, dead code and security scanning do not call a model.
Model features, such as AI-written documentation and chat, call OpenAI or Google Gemini models through Repowise's business API accounts. When you use them, code excerpts and context derived from your repository are sent to that provider to produce the answer.
Two other outbound paths carry no code:
- Dependency vulnerability matching sends package URLs (purls) to OSV.dev, never source code.
- Security alert webhooks and emails carry metadata only: rule ids, file paths and counts. Never code snippets or secret values.
Access control
- Sign-in is with GitHub or an email link.
- Indexes of public repositories are public. Access to a private repository's index is gated on the signed-in user's ownership of it. Workspaces and Teams add explicit membership, and a team has owner, admin and member roles.
- API keys for the hosted MCP endpoint are shown to you once at creation. Only a one-way hash is stored.
- On the Teams plan, security actions such as viewing findings, exports and status changes are recorded in an insert-only audit trail. It covers the security surface only and is not a full account audit log.
Retention and deletion
Indexed data is kept while your account is active. You can delete a repository, a workspace or the whole account from Settings.
Account deletion starts a 7-day grace period, during which you can cancel. After that the account is hard-deleted, and the records tied to it are deleted with it. Two kinds of record are de-identified instead of deleted: billing ledger entries and public documentation pages. The privacy policy states that deleted data is purged from backups within 90 days.
Usage telemetry events are kept for about 90 days and product analytics events for about 180 days, then removed by a scheduled job.
Sub-processors
The current list, and what each one is used for, is in the privacy policy.
What Hosted does not have yet
- Security certifications. Repowise holds no SOC 2, ISO 27001 or other audited attestation. The compliance reports in the Security suite are control-coverage signals for your code, not a certification of Repowise.
- SSO. SAML / OIDC single sign-on and SCIM provisioning are not generally available. The Enterprise status table shows where each one stands.
Reporting a vulnerability
Email security@repowise.dev with reproduction steps.
Security review
Bring your questionnaire and a representative repository to a call.
Book a security review