Security and compliance

The controls we operate, and the obligations that stay with you.

This page describes the controls we operate and the ones that stay yours. If you are running a security review, ask us for the current evidence material as well. This page describes the model, not the audit status.

How access is controlled

AreaHow it works
Sign-inBrowser-based sign-in tied to your organization. gh0stcli never handles your password.
PermissionsEvery action is checked against your role and your account's limits before it runs.
SecretsSecret values are stored outside Git and referenced by name. gh0stcli can write a secret without the value appearing in your conversation.
GuardrailsWhat your workloads may do at runtime is bounded by platform rules you cannot silently exceed.
DeploymentsApplication changes are versioned in Git and applied from there, not applied by hand.
TraceabilityGit history, portal state, and request records show what changed and when.

What is ours and what is yours

Areagh0stserviceYou
Operating the platformOurs-
Patching and upgrading the platformOurs-
Guardrails and account limitsOurs to define and enforceYours to review, and to request changes to
Your application code-Yours
Your application's dependencies and images-Yours, unless a managed scope says otherwise
Secret valuesWe provide the mechanismYou own the values and how you handle them
Operating your applicationDepends on your modelDepends on your model

For security reviews and audits

The data processing agreement, including the sub-processor list and the technical and organisational measures, is published under data processing. Where the infrastructure is located and how we handle access requests from authorities outside the EU is described under switching providers. Ask us directly for further security documentation. A documentation page is not the right place to state audit status or testing cadence, because it cannot be kept accurate enough to rely on.

Your contract and data-processing agreement are what bind us.