Account  /  Security and data handling

Security and data handling

Reviewing code means reading it. This page states exactly what that involves, so you can answer your security team without a call.

What is sent where

DataGoes toRetained
Diff and surrounding contextYour configured model vendorsDuration of the review only
Repository metadataDicastWhile the repository is enabled
Findings and votesDicastPer your plan’s retention window
Full repository cloneNowhere persistentEphemeral; destroyed with the review container

Training

We do not train models on customer code, and our vendor agreements carry zero-retention terms for the API traffic Dicast generates. With your own keys, the terms are the ones you signed with each vendor.

Access controls

Infrastructure

Reviews run in single-use containers with no persistent volume and no inbound network. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Teams that need code to stay inside their perimeter entirely should use the self-hosted runner.

Reporting a vulnerability

Email security@dicast.dev. We acknowledge within one business day. Please do not open a public issue. Our full security posture, subprocessor list and compliance status are on the security page.