Security by system design

Repository access designed around least privilege.

CutoverGrid protects source access, analysis workloads, evidence, credentials, and administrative actions across the full assessment lifecycle.

01Scoped accessSelected repositories and branches
02Ephemeral workerTenant-isolated analysis boundary
03Structured evidenceConfigurable source retention

Access control

Read-only source access is the default boundary.

CutoverGrid requests the minimum permissions required for repository discovery and analysis. Actions that write to work-management systems use separate permission grants.

01

Narrow repository scope

Administrators select the organizations, repositories, and branches available to CutoverGrid. Access can be removed at the source-control provider.

02

Short-lived credentials

Access tokens are short lived where provider support allows. Stored credentials are encrypted and isolated from general application workloads.

03

Separate write permissions

Repository analysis never requires source-code write access. Issue creation and workflow synchronization are explicitly authorized as distinct actions.

Analysis isolation

Every assessment runs inside controlled boundaries.

Analysis workers are ephemeral, tenant isolated, resource constrained, and separated from long-running application services.

  • Ephemeral analysis workers
  • CPU, memory, and execution-time limits
  • Restricted external network access
  • No package lifecycle scripts by default
  • Path-traversal and archive extraction protection
  • Secret and personal-data detection
Tenant boundary
Analysis workerNetwork restrictedResource limitedTemporary filesystem
Structured findingsNo executable repository output

Data lifecycle

Control what is retained and when it is deleted.

Retention settings align analysis with organizational policy, from managed evidence history to zero-retention source processing.

Configurable retention

Set source-code retention by workspace and deployment policy while preserving the evidence required for migration traceability.

Zero-retention analysis

Process source in ephemeral workers and retain structured findings without keeping repository contents after analysis completes.

Customer-controlled deletion

Authorized administrators can remove assessments, evidence records, integration credentials, and workspace data.

Complete audit logs

Record access changes, repository connections, scans, exports, deletions, permissions, and administrative actions.

Enterprise controls

Govern access at organizational scale.

Identity, authorization, deployment, and retention controls support high-trust engineering environments.

Identity and roles

  • Single sign-on
  • Role-based access control
  • Workspace and project roles
  • Administrative separation

Deployment control

  • Private deployment options
  • Restricted network paths
  • Customer-managed retention
  • Dedicated analysis boundaries

Operational assurance

  • Audit event export
  • Access review support
  • Credential revocation
  • Controlled data deletion

Security questions

Direct answers for engineering and security teams.

Does CutoverGrid need write access to source code?

No. Repository discovery and analysis use read-only access by default. Write permissions for issue creation are separate and explicit.

Can analysis operate without source retention?

Yes. Zero-retention analysis processes repository content in an ephemeral worker, persists structured findings, and removes source content when the job completes.

Does analysis run package installation scripts?

No package lifecycle scripts run by default. This prevents repository-defined installation hooks from executing inside the analysis environment.

How is tenant separation enforced?

Tenant-aware authorization controls access at the application layer, while isolated analysis jobs and scoped storage boundaries separate workloads and data.

How can customers review security-relevant activity?

Audit logs record repository connections, scans, exports, access changes, deletions, and administrative actions for authorized review.

Evaluate with your security team

Review the access and deployment model in detail.

Bring your source-control, identity, retention, and isolation requirements to a technical security session.