Narrow repository scope
Administrators select the organizations, repositories, and branches available to CutoverGrid. Access can be removed at the source-control provider.
Security by system design
CutoverGrid protects source access, analysis workloads, evidence, credentials, and administrative actions across the full assessment lifecycle.
Access control
CutoverGrid requests the minimum permissions required for repository discovery and analysis. Actions that write to work-management systems use separate permission grants.
Administrators select the organizations, repositories, and branches available to CutoverGrid. Access can be removed at the source-control provider.
Access tokens are short lived where provider support allows. Stored credentials are encrypted and isolated from general application workloads.
Repository analysis never requires source-code write access. Issue creation and workflow synchronization are explicitly authorized as distinct actions.
Analysis isolation
Analysis workers are ephemeral, tenant isolated, resource constrained, and separated from long-running application services.
Data lifecycle
Retention settings align analysis with organizational policy, from managed evidence history to zero-retention source processing.
Set source-code retention by workspace and deployment policy while preserving the evidence required for migration traceability.
Process source in ephemeral workers and retain structured findings without keeping repository contents after analysis completes.
Authorized administrators can remove assessments, evidence records, integration credentials, and workspace data.
Record access changes, repository connections, scans, exports, deletions, permissions, and administrative actions.
Enterprise controls
Identity, authorization, deployment, and retention controls support high-trust engineering environments.
Security questions
No. Repository discovery and analysis use read-only access by default. Write permissions for issue creation are separate and explicit.
Yes. Zero-retention analysis processes repository content in an ephemeral worker, persists structured findings, and removes source content when the job completes.
No package lifecycle scripts run by default. This prevents repository-defined installation hooks from executing inside the analysis environment.
Tenant-aware authorization controls access at the application layer, while isolated analysis jobs and scoped storage boundaries separate workloads and data.
Audit logs record repository connections, scans, exports, access changes, deletions, and administrative actions for authorized review.
Evaluate with your security team
Bring your source-control, identity, retention, and isolation requirements to a technical security session.