Security

Built to be trusted with your code and access.

An autonomous builder touches your data model, your codebase, and your deployment. Here is how that is handled - stated plainly, with no overclaiming.

Generated code and data handling

We store what a build needs to run and what you need to keep working - your project spec, the generated codebase, and build history. Your source is retained while your project is active and removed on request when you delete a project. Access is scoped to your account and the people you invite into a shared workspace.

Encryption in transit and at rest

Traffic between you and PIRAPLEX is encrypted in transit using current TLS. Stored project data and generated code are encrypted at rest. Secrets generated during a build are stored as configuration values, never written into the source that gets committed.

Deployment credential handling

When a build deploys, it uses scoped credentials for the specific target - never broad access to your accounts. PIRAPLEX can provision and deploy the resources a project needs; it does not read unrelated data or reach into infrastructure outside the project it is building. On Team plans with custom targets, you control exactly what access is granted.

Compliance posture, stated honestly

We would rather tell you where we actually are than imply more than is true. Our posture reflects current status, and it moves forward deliberately as the product matures.

  • We state our current status only - we do not claim certifications we do not hold.
  • Security is treated as part of the build, not a checkbox bolted on afterward.
  • Credential scope is minimized to what a given build actually requires.
  • If you have a specific requirement for a Team deployment, we will talk it through before you commit.

Have a specific security requirement?

If your deployment has constraints we should know about, Contact us before you start.