Private by default. We never store your code.
We never store your source code. Content is processed to create semantic indexes, then discarded.
TLS 1.3 for all connections. HTTPS only. Certificate pinning for SDKs.
AES-256 encryption for all stored data. Keys managed via AWS KMS.
Complete data isolation between accounts. No cross-tenant access possible.
When you connect a private repository:
Embeddings cannot be reversed to recreate source code.
In progress. Expected Q2 2025.
Compliant. DPA available on request.
Data Processing Agreement available for Team+ plans.
Found a security issue? We appreciate responsible disclosure.
Report Vulnerabilitysecurity@sotadocs.com | PGP key available
No. SotaDocs processes content to create semantic indexes but never stores raw source code on its servers. We only retain metadata and semantic embeddings.
We use temporary, isolated workers to index private content. Once the index is built, the worker is destroyed and raw code is immediately purged from the system.
Yes. All data is encrypted at rest using AES-256 and in transit using TLS 1.3, ensuring your documentation context remains private.
Only authenticated users with the appropriate repository permissions can access the context via MCP tools or our secure REST API.
SOC2 Type II compliance is currently on our 2026 roadmap. We already adhere to SOC2 security and privacy principles in our current data handling workflows.