Security
Your code is read, not kept
EnsureFix needs your repository to do its job and needs your credentials to push the result. Everything below is how those two facts are contained.
- Cloneephemeral disk
- Workmemory
- Pushyour forge
- Destroynothing left
AES-256
Credentials at rest, GCM mode
TLS 1.2+
Every connection in transit
7 yr
Tamper-evident audit retention
Zero
Source files stored at rest
The boundary
What crosses, and what comes back
A run is a loan, not a transfer. Context goes out for as long as the work takes; a branch comes back; the workspace that held the code stops existing.
Leaves your infrastructure
Ranked file context for the change being made, and the ticket text. Held in memory for the duration of the run.
Comes back to you
A branch, a pull request with the reasoning trace attached, and the scan and test results behind it.
Never persists anywhere
Source files, clones, build artefacts and the workspace itself. Nothing survives the run.
Defence in depth
Six control domains
No single control is load-bearing. Each domain below assumes the one before it has already failed.
01
Encryption
Credentials are the most valuable thing the deployment holds, so they are the most heavily protected.
- In transit
- VCS credentials at rest
- Passwords
- Key handling
02
Authentication and access
One compromised session should never become access to a second organisation's data.
- Session tokens
- Revocation
- Roles
- Organisation isolation
- Lockout
03
Application security
The scanners EnsureFix runs against your code are the same class of checks we hold ourselves to.
- SQL injection
- SSRF
- Command injection
- XSS
- Rate limiting
- Error handling
04
Audit logging
An autonomous agent that touches production code has to be answerable for every action it took.
- What is recorded
- Tamper evidence
- Write protection
- Retention
05
Webhook security
A webhook is an unauthenticated door into the pipeline unless every delivery is proven.
- GitHub
- GitLab
- Replay protection
- Routing
06
AI processing
The model provider is part of your supply chain — and in a self-hosted deployment, it is your account and your contract with them.
- Transport
- Training
- Validation
- Human gate
Where it runs
Inside your perimeter, and what crosses it
EnsureFix is deployed on your own infrastructure. That settles most of this page — but not all of it, and the part it does not settle is the part worth reading.
Stays inside your network
Every component runs on your servers: the dashboard, the worker, and every database. Repository clones happen inside your perimeter and the working directories are yours.
- Databases, audit logs and evidence
- Repository clones and workspaces
- VCS and model credentials, encrypted at rest
- Licence and trial state — verified locally
Crosses it, because you configured it
The work needs a model and a forge. EnsureFix calls the AI provider and the VCS you configure, using credentials you own, and that traffic carries the code being worked on.
- Outbound HTTPS to your AI provider
- Outbound HTTPS to your VCS
- Nothing to EnsureFix — no telemetry requirement
- No licence server to reach, ever
Questions
What reviewers ask first
The six questions that come up in every vendor assessment, answered without hedging.
found something
Responsible disclosure
Found something? Report it to security@ensurefix.com. We acknowledge receipt within two business days and keep you posted through remediation. Please give us reasonable time to ship a fix before disclosing publicly.
Bring it to your security review
Run it on your own repository
We will walk your team through the boundary, the audit trail and the self-hosted path on a live run.