Paladeon
Security

We hold our own to the bar we set for you.

Paladeon reads source code and connects to production systems, so trust isn't optional — it's the product. Here's how we protect what you give us.

Encrypted everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Secrets are stored in a dedicated, access-controlled vault — never in logs or plaintext.

Isolated analysis

Every review runs in an ephemeral, per-tenant sandbox that is destroyed after the run. Your code is never shared across customers or used to train shared models.

Least privilege access

Integrations request the minimum scopes needed. Internal access is role-based, audited, and gated behind SSO and mandatory MFA.

Auditability

Actions against your data are logged and traceable. You control retention, and you can export or delete your analysis artifacts at any time.

Found a vulnerability?

We run a responsible disclosure program and won't pursue good-faith research. Tell us what you found and we'll get on it.

Disclosure policy