Security
Trust, infrastructure, and access
Factimonious is built for teams who connect production-adjacent systems. We treat repository content, tokens, and generated evidence as sensitive by default—and we publish the policies that bind how that data is used.
Authentication and GitHub access
Primary login is GitHub OAuth. Repository access is designed around durable, least-privilege GitHub App installations rather than long-lived broad user tokens, so scopes stay narrow and revocable by your organization.
Uninstalling the GitHub App or revoking OAuth access cuts off further repository access. Account closure and deletion requests are handled under our Privacy Policy retention rules.
Data we hold
Authorized repository contents are accessed transiently for analysis and are not retained after each session. What we keep for your account are Session Results—engineering-activity analysis, standups, retrospectives, and related change metadata linked to your tenant.
Session Results are account-linked service data (Path 1). They are not anonymized and are personal data under our Privacy Policy and DPA. Usage and log data are retained on a shorter rolling window; account and Session Result retention follow the periods in the Privacy Policy.
Payments are processed by Stripe. We do not store full payment card numbers. See the Payment Processing Policy.
AI and model training
Service delivery data for your account—including Session Results and repository content—is not used to train our AI/ML models. Models are trained and evaluated only on a separate, genuinely anonymized Path 2 dataset: aggregated signals with direct and reasonably reversible identifiers removed.
We do not use non-anonymized code content, individual user identifiers, payment data, or credentials for AI/ML training. Full commitments, anonymization standards, and the no-opt-out rule for Path 2 anonymized training are in the AI & ML Data Use Policy.
Infrastructure and controls
The product is hosted on AWS. We apply encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access with least privilege, secrets in a managed vault, and network isolation for workers that touch repository data. Marketing and app surfaces may live on separate subdomains with their own controls.
We maintain tenant isolation in the data layer, rate limiting at the edge, and structured audit logging for security-sensitive events. Detailed technical and organizational measures are documented in our TOMs, available at signup and for signed-in customers under Profile → Legal & compliance.
How to review us
Public policies live on the platform: Legal hub, Privacy, Cookies, AI/ML Data Use, and Terms. The DPA and TOMs are presented at signup and remain available in-account; they are not linked from the marketing footer.
Privacy requests: factimoniousprivacy@factimonious.ai. Enterprise DPA and security-pack inquiries: legal@factimonious.ai or Contact.
This page summarizes our security posture for buyers and is not a legal agreement. Contractual terms, the DPA, and TOMs control in the event of conflict.