+ data handling
We work close to sensitive parts of your stack.
Here is what we touch, where it lives, who else is in the loop, and how to reach us when something is wrong. No marketing language.
Repository contents (workflows, Terraform) and PR diffs. That is all. No live AWS API calls. CI Guard does not assume AWS roles or require AWS credentials.
Not an IAM platform, not an SSO/SCIM/access-review tool, not a cloud posture product. CI Guard guards one path: how GitHub Actions authenticates to AWS.
Single managed deployment on Render, US-East. Backups, retention, and on-call documented internally.
Render, Stripe, GitHub, Postmark. We list them publicly and update 30 days before changes.
SOC 2 Type I in progress, scoped to CI Guard. We do not claim SOC 2 completion until a signed report exists.
[email protected]. We respond within one working day, fix, and credit.
We do not resell, train on, or warehouse customer code beyond what is needed to compute findings.
the loop
Who else touches the data.
changes posted 30 days in advance · last update 2026-04-15
One working day to first response. We fix, then credit. PGP key on request.