Secure by design.

SOC 2 Type II

Codegiant operates under SOC 2 Type II controls covering security, availability, and confidentiality. Reports and ongoing evidence are available through our Trust Center so your security and procurement teams can complete reviews without delay.

Security

Controls protect customer systems, code, and operational data throughout the platform.

Availability

Monitoring and recovery practices keep production workflows reliable for enterprise teams.

Confidentiality

Tenant boundaries, encryption, and access reviews limit exposure of sensitive information.

Change management

Production changes follow documented review, approval, and deployment controls.

Access controls

Role-based permissions, SSO, and audit trails govern access to critical systems.

Incident response

Defined escalation paths help teams identify, triage, and communicate security events.

GDPR Ready

Data processing commitments, a published DPA, and privacy controls aligned with GDPR - so your customer obligations carry through to Codegiant.

Published DPA

Customer-ready data processing addendum reflecting GDPR obligations.

Regional data residency

Choose where your data lives - US or EU regions with documented controls for each.

Lawful transfers

Standard contractual clauses and documented international transfer safeguards.

Retention & deletion

Configurable lifecycle and deletion to honor customer requests and policies.

Subprocessor list

Current subprocessor list maintained in the Trust Center with change notices.

AI data boundary

Customer code, prompts, and generated outputs stay inside your tenant boundary and are excluded from model training.

No training on your code

Customer source code is excluded from training underlying foundation models.

No training on your prompts

Prompts, completions, and intermediate outputs stay inside your tenant boundary.

Provider isolation

Inference runs against models with zero-retention agreements from underlying providers.

Customer-owned outputs

You retain ownership and rights to all code and artifacts the AI produces.

Everything your security review needs.

Access policies, subprocessors, and current compliance posture from the Codegiant Trust Center - the same place your security review starts.

Answers your security team is already looking for.

The questions that show up most often in procurement, legal, and security reviews - answered up front.

In your cloud. Applications built on Codegiant deploy directly into your own account across 10+ supported providers - AWS, GCP, Azure, Cloudflare, DigitalOcean, and more - so your data and traffic stay inside your perimeter, in the region you choose.

Access is scoped to your organization with SAML SSO, role-based controls, and full audit trails for sensitive actions.

No. Customer code, prompts, and outputs are excluded from training any underlying foundation models.

TLS 1.2+ in transit and AES-256 at rest, with managed keys across all storage tiers.

Yes - it's the default. One-click deploys push every application into your own cloud account or on-prem environment, so production data and traffic never leave your infrastructure.

Configurable lifecycle policies per workspace, plus on-request deletion supported by the published DPA.