Skip to content
octic.ai

Trust center

Security at Octic

Security is not a feature we added — it is foundational to how Octic is built and operated. Every layer of the platform, from encryption and access control to infrastructure and network isolation, is designed to protect your data by default.

How we protect your data

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption keys are managed through a dedicated key management service with automatic rotation and strict access controls.

Data residency

Octic Cloud runs on Octic-managed infrastructure. When your data has to stay in your own environment, self-hosted and hybrid deployment keep it there. They are part of a higher tier, available through sales.

Infrastructure

Octic runs on high-availability infrastructure. All infrastructure is defined as code, version-controlled, and peer-reviewed, and security patches are applied automatically.

Access control

Role-based access control governs every action in the platform. SSO integration supports your existing identity provider. Every access event is logged in an audit trail. The principle of least privilege is enforced by default — users and service accounts receive only the permissions they need, nothing more.

Network security

All workloads run in isolated VPCs with private endpoints. Public attack surface is minimized by default, and DDoS protection is active at the edge.

Secure development

Security is embedded in the development lifecycle, not bolted on at the end. Every code change goes through automated static analysis, dependency scanning, and peer review. Secrets are never stored in source code. Deployments are immutable and reproducible.

Responsible disclosure

If you discover a security vulnerability, we want to hear about it. Please report it responsibly by contacting security@octic.ai. We will acknowledge your report within 48 hours and work with you to understand and resolve the issue.

See what's running, what it costs, and who owns it.

Sign up and install a sensor to see coding-agent sessions and spend, or book a demo for a walkthrough of the full control plane.