CIPatch

Security

CIPatch is given read access to private CI data, so the security posture is deliberately narrow: least privilege, short-lived credentials, and no access to the things it does not need.

Design principles

Data handling

Reporting a vulnerability

Use the contact form with the details and, if possible, a reproduction, or email security@releasedge.com. Please do not open a public issue. We acknowledge within two business days, and we will not pursue anyone who reports in good faith and avoids privacy violations, data destruction and service disruption.

Scope of this page

This describes the system as built, in plain language. It is not a certification and not a substitute for your own review. Enterprise security questionnaires and bespoke DPAs are out of scope for the self-service plans.