Security

Reviewing code means reading it.

So the honest thing is to say exactly what that involves. This page is written to be forwarded to your security team without a call.

Last updated 14 August 2026

What Dicast can and cannot do

Dicast holds read access to the repositories you select, and write access limited to review comments and status checks. It has no permission to push commits, merge, modify workflows, or read repositories you did not select.

A review runs in a single-use container with no persistent volume and no inbound network access. The clone is destroyed when the container exits.

Subprocessors

Your code is sent to the model vendors seated on your panel, and nowhere else.

SubprocessorPurposeData
AnthropicJuror seatDiff and review context
OpenAIJuror seatDiff and review context
GoogleJuror seatDiff and review context
Google CloudHosting and storageFindings, votes, account data
StripePaymentsBilling details; no code

Our agreements with each model vendor carry zero-retention terms for the API traffic Dicast generates, and none of them may train on it. On the Scale plan you can seat the panel with your own vendor accounts, in which case the terms are the ones you signed.

We give 30 days’ notice before adding a subprocessor. Subscribe at security@dicast.dev to be told.

Retention

DataRetained
Repository cloneDuration of the review; never written to persistent storage
Diff sent to vendorsDuration of the request
Findings, votes and reasoning14 days on Solo, 90 on Team, indefinitely on Scale
Account and billing recordsAs long as the account exists, then 7 years where tax law requires it

Deleting a workspace removes findings and repository metadata within 30 days.

Internal access

Encryption

TLS 1.3 in transit. AES-256 at rest. Secrets are held in a managed key store with per-workspace envelope encryption.

Compliance

We are honest about where we are rather than implying more:

StandardStatus
GDPRData processing agreement available on request
SOC 2 Type IIAudit in progress; report expected Q4 2026
ISO 27001Not certified
Data residencyEU-only processing available on Scale

Teams that cannot send source outside their own network should use the self-hosted runner, where only verdict metadata leaves your infrastructure.

Reporting a vulnerability

Email security@dicast.dev. We acknowledge within one business day and aim to give a remediation timeline within five. Please do not open a public issue.

We do not currently run a paid bug bounty, but we credit reporters who want it and we will not pursue anyone acting in good faith within the scope of their own account.

Questionnaires

If your process needs a completed security questionnaire, send it to security@dicast.dev. We would rather answer yours than ask you to accept ours.