Security
How dlogs protects your team's decisions and the code-host data behind them. What is read and where it goes is on Data handling.
- Each workspace is isolated from every other at the database level, with row-level security.
- Secrets are redacted from any text before it is sent to OpenAI. The contents of .env, key, certificate and credential files are never sent.
- You sign in with a one-time code sent to your work email. The code expires in 15 minutes.
- Each engineer's coding agent uses a personal key, which can be revoked on its own in Settings.
- A workspace can accept agent requests only from the repositories it has selected.
- Webhook deliveries from your code host are signature-verified before they are processed.
- Bitbucket tokens are encrypted at rest.
- A decision is never edited or deleted in place. A new decision replaces it, and the old one stays readable.
What we do not claim
dlogs is in beta. We do not hold SOC 2 or any other compliance certification.
Questions about security, or a vendor review? Contact hello@dlogs.app.