Skip to content

Security

  1. We never store your source code.

    Docdrift reads your code in memory while it analyzes a change and deletes it when the job ends. We keep what we derive from it: file paths, symbol names, signatures and decorators, imports and references between files, routes and other entry points, data model fields, dependency names and versions, environment variable and configuration key names, and calls to your own hosts (your app's domains, private addresses and the API hosts you declare in Settings). Calls to any other host are never stored. We also keep the doc statements we check, pull request titles with a short excerpt of their description, issues you import as requests, your Docdrift Docs pages, the plain-language and technical texts Docdrift writes, and numeric embeddings of these texts. Text your team writes in Docdrift (requests, questions, notes and Docdrift Docs pages) and issues you import are kept as written, even if they include code; from pull request descriptions we keep a short excerpt, and from your other docs only the statements we check. Secrets we detect are removed before anything is saved.

  2. Analysis runs in the EU (Google Cloud).

    Your code is analyzed on Google Cloud Vertex AI in the European Union, with zero data retention: data caching is off, checked at every deployment, and it is never used to train models. Our website and app are served through Cloudflare, which decrypts that traffic in its network, possibly outside the EU; that includes code excerpts you open in the app.

  3. Least-privilege GitHub access.

    The Docdrift GitHub App can read code, publish a check and post one comment per pull request. It can't push code, merge or create issues. GitHub's pull request permission would also let Docdrift review, edit or close pull requests. Docdrift never does, and its code blocks those calls. Writing (opening doc pull requests, keeping a Docdrift section in AGENTS.md and CLAUDE.md through pull requests, creating issues) needs a separate app that you install only if you turn those features on. Branches it pushes run your GitHub Actions like any other push.

  4. Nothing changes without a person.

    Docdrift never edits your docs, Notion pages or code on its own. Every change is a pull request, an issue or an edit a person approves.

  5. Disconnect and your code data is gone.

    When you disconnect a repository, we delete everything derived from its code, and everything our AI wrote about it, within 1 hour. What your team wrote or imported (decisions, requests, notes, questions and history) stays in a trash for 30 days so you can reconnect, unless the Owner empties it sooner. Deleted data leaves our backups within 84 days. Our database backups are encrypted, but the key is kept on the same server; the copy taken before each update is encrypted the same way and deleted after 7 days; our hosting provider keeps daily images of the whole server for 7 days; and emails we already sent stay with our email provider for 30 days.

  6. Your workspace is isolated.

    Every record belongs to one workspace, and every request and job is checked against it, in Docdrift's code and again in the database with row-level security. Workspaces share the same database; the separation is tested on every change.

  7. Credentials are encrypted.

    Tokens for Notion and Google are encrypted with a key per workspace. Tokens we issue to your agents and chat assistants are stored only as hashes.

  8. Private by default.

    Nothing about your project is public unless the Owner publishes it, and "Make private" takes it down within seconds. In a public repository, what Docdrift writes (its AGENTS.md section, doc pull requests and issues) only covers that repository and never quotes your private docs or repositories, and the AGENTS.md section is added only after someone on your team previews and confirms it.

  9. No per-person metrics.

    Docdrift never ranks, scores or reports on individual people.

Docdrift

PermissionAccessDocdrift uses it toIt also allows (Docdrift never does this)It doesn't allow
MetadataReadRead the repository's name and default branch, check your permission on it, and receive repository events.Read collaborators and their permission level, contributors, languages, license, tags, topics, statistics, rulesets, forks and commit comments.Read or change code.
ContentsReadRead your code at a commit to index it and check pull requests. We don't store it.Read commits, branches, tags, releases and comparisons, download archives, and comment on commits.Create, change or delete files, branches or tags, or merge.
ChecksRead and writePublish the Docdrift check on pull requests and pushes.Create and update check suites, re-run its own checks, change this repository's check suite preferences, and read other apps' checks.Re-run other apps' checks, make a check required, or write commit statuses.
Pull requestsRead and writeRead pull requests and keep one Docdrift comment up to date.Open pull requests; edit their title, body and state; submit and dismiss reviews and write review comments; request reviewers; manage labels, milestones and assignees; lock conversations.Merge pull requests, update a pull request's branch, or create issues.
IssuesReadRead issues linked to pull requests and import issues as requests.Read every issue and comment in the repositories you choose, including pull request conversations.Create, edit, close or comment on issues.
Merge queuesReadReceive the event when a merge queue asks for checks, and report the Docdrift check there.Receive other merge queue events, which Docdrift ignores.Add or remove pull requests from a queue.

Docdrift Write

PermissionAccessDocdrift uses it toIt also allows (Docdrift never does this)It doesn't allow
MetadataReadRead the repository's name and default branch, check your permission on it, and receive repository events.Read collaborators and their permission level, contributors, languages, license, tags, topics, statistics, rulesets, forks and commit comments.Read or change code.
ContentsRead and writePush a new branch with a doc fix you approved, or with Docdrift's section in AGENTS.md and CLAUDE.md, and update that branch while its pull request is open.Create, move, rename and delete branches and tags; create commits; create, edit and delete files; merge pull requests; create releases; send repository dispatch events.Edit GitHub Actions workflow files or change repository settings.
Pull requestsRead and writeOpen the pull request with that change, keep its title and description up to date, and comment on it.Edit, review, approve, close or reopen any pull request.Bypass branch protection rules, unless you add Docdrift Write to a ruleset's bypass list.
IssuesRead and writeCreate the issue you asked for and comment on it.Create, edit, close and lock issues; comment and delete comments; manage labels, assignees, milestones, sub-issues and dependencies.Delete issues.

Branches pushed by Docdrift Write run your GitHub Actions workflows like any other push, with the secrets those workflows use.

GitHub grants permissions per app, not per feature. Docdrift's code only makes the calls listed in "Docdrift uses it to"; anything else is blocked before it leaves our servers.

Subprocessors

The companies that process data for Docdrift, what each one does and where, are listed on our Subprocessors page.

See subprocessors · Data Processing Agreement (DPA)

Report a vulnerability

Responsible disclosure · security.txt