So the honest thing is to say exactly what that involves. This page is written to be forwarded to your security team without a call.
Dicast holds read access to the repositories you select, and write access limited to review comments and status checks. It has no permission to push commits, merge, modify workflows, or read repositories you did not select.
A review runs in a single-use container with no persistent volume and no inbound network access. The clone is destroyed when the container exits.
Your code is sent to the model vendors seated on your panel, and nowhere else.
| Subprocessor | Purpose | Data |
|---|---|---|
| Anthropic | Juror seat | Diff and review context |
| OpenAI | Juror seat | Diff and review context |
| Juror seat | Diff and review context | |
| Google Cloud | Hosting and storage | Findings, votes, account data |
| Stripe | Payments | Billing details; no code |
Our agreements with each model vendor carry zero-retention terms for the API traffic Dicast generates, and none of them may train on it. On the Scale plan you can seat the panel with your own vendor accounts, in which case the terms are the ones you signed.
We give 30 days’ notice before adding a subprocessor. Subscribe at security@dicast.dev to be told.
| Data | Retained |
|---|---|
| Repository clone | Duration of the review; never written to persistent storage |
| Diff sent to vendors | Duration of the request |
| Findings, votes and reasoning | 14 days on Solo, 90 on Team, indefinitely on Scale |
| Account and billing records | As long as the account exists, then 7 years where tax law requires it |
Deleting a workspace removes findings and repository metadata within 30 days.
TLS 1.3 in transit. AES-256 at rest. Secrets are held in a managed key store with per-workspace envelope encryption.
We are honest about where we are rather than implying more:
| Standard | Status |
|---|---|
| GDPR | Data processing agreement available on request |
| SOC 2 Type II | Audit in progress; report expected Q4 2026 |
| ISO 27001 | Not certified |
| Data residency | EU-only processing available on Scale |
Teams that cannot send source outside their own network should use the self-hosted runner, where only verdict metadata leaves your infrastructure.
Email security@dicast.dev. We acknowledge within one business day and aim to give a remediation timeline within five. Please do not open a public issue.
We do not currently run a paid bug bounty, but we credit reporters who want it and we will not pursue anyone acting in good faith within the scope of their own account.
If your process needs a completed security questionnaire, send it to security@dicast.dev. We would rather answer yours than ask you to accept ours.