SECURITY & TRUST

Your evidence stays protected.

CIRT applies different handling rules to source code, SOC 2 reports, penetration-test summaries, and security questionnaires. Here is what it retains, deletes, encrypts, and sends to service providers.

01 / DATA LIFECYCLE

Different evidence,
different retention.

Code analysis minimizes retained source. Vendor documents can remain with an assessment for continuity, and customers control whether they do.

Source code reviews

Source code files are not retained after processing. CIRT retains cryptographic file hashes and the underlying file-level results indefinitely by default. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and file-level results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. A file-level result is primarily a generated summary of the file's purpose and its associated security findings. In rare circumstances it may include a small code snippet. It cannot identify or reconstruct the submitted source file.

Vendor assessments

Vendor documents are retained by default so the evidence remains available with the assessment. Document retention can be disabled. Customers can delete the vendor assessment and any documents retained with it at any time.

Encryption

Submitted material and assessment data are encrypted in transit and at rest. No system can guarantee absolute security, so customers remain responsible for confirming they are authorized to submit each item.

Deletion and control

Customers can delete the customer-facing code review assessment. Its underlying file hashes and file-level results remain indefinitely by default unless the initial-scan sensitive-codebase option applies to unique files first seen in that repository. Customers can delete vendor assessments and retained vendor documents when they are no longer needed. Limited security, diagnostic, billing, or legal records may also remain where required for fraud prevention, legal compliance, financial records, or system integrity.

02 / AI PROCESSING

No AI model training
by default.

All-inclusive and BYOK plans use the same CIRT workflow, but the Anthropic account and contractual boundary differ.

WE PROVIDE THE AI

All-inclusive processing

Submitted content is processed through Anthropic commercial API access that does not use it to train general models. CIRT supplies and manages the provider access.

Predictable subscription billing
USE YOUR ANTHROPIC ACCOUNT

Bring Your Own Key processing

Processing follows your Anthropic account settings and contract. If AI model training is enabled on that account, your Anthropic terms control that use.

Direct provider control and billing

What BYOK does and does not protect: BYOK is primarily a cost-control option. It can also carry the benefit of your own negotiated Anthropic terms or DPA. It does not bypass CIRT infrastructure, metadata handling, report storage, authentication, monitoring, or application processing.

03 / PROCESSING BOUNDARY

Where data moves.

CIRT application data is processed and stored in the United States. Service providers may operate their own support and infrastructure footprints under their respective agreements.

Railway

Application and database hosting.

Clerk

Authentication and account identity.

Cloudflare

Network delivery, performance, and security.

Sentry

Error monitoring and diagnostics.

Paddle

Billing and subscription management.

Anthropic

AI processing for submitted evidence and analysis context.

04 / PRODUCT BOUNDARIES

Know what is supported before you submit.

Repository analysis is designed primarily for open-source software. Direct private-repository connections are not currently supported. Customers may upload an authorized source ZIP when they have the legal right to do so.

Can I Run That? has not completed a SOC 2 examination and does not currently provide a SOC 2 report. We are evaluating independent assurance options and can discuss security review requirements with Tier 3 customers. Current data handling, subprocessors, and encryption practices are documented on this page.

CIRT is decision support, not a certification authority, secure code escrow, or substitute for professional judgment.

CURRENT TRUST OPTIONSAVAILABLE
  • Assessment record deletionCustomer controlled
  • Code file-level resultsRetained indefinitely by default
  • Sensitive-codebase optionInitial scan only
  • Vendor document retentionCan be disabled
  • Tier 3 DPAAvailable for discussion
  • SSO add-on$75 / month
  • Open API integrationsTier 3
  • Private repo connectionRoadmap

Need a DPA or security review?

Tier 3 customers can discuss DPA requirements, SSO, API integration, and current control needs before purchase.

Create your account