Security & privacy, by design.
attribut.ai measures how engineering work happens across your AI coding tools — without ever collecting the work itself. Here’s exactly how we protect your data.
Your code never leaves your machine.
The collector runs locally and captures only metrics and metadata about a coding session. It never transmits your source, your prompts, or the model’s responses — and that isn’t a policy, it’s enforced in the code itself.
Published on GitHub under the PolyForm Shield license. Read exactly what it collects — and what it can’t — line by line, or run the privacy test yourself.
No servers of our own.
The entire stack runs on managed cloud providers, with a hardened edge in front and no public exposure behind it.
Certified providers only
Runs entirely on Google Cloud Platform and Cloudflare — independently certified to SOC 2, ISO 27001 and more. We operate no self-managed servers.
A hardened edge
Ingestion is handled by a Cloudflare edge that provides TLS, DDoS protection and request validation before any data is processed.
Nothing public behind it
Backend data processing runs on internal-only services with no public network exposure.
Encrypted in transit and at rest.
Standard encryption everywhere, with an extra layer wrapped around anything sensitive we hold on your behalf.
In transit
TLS 1.2+ on all endpoints and every service-to-service call.
At rest
All stored data is encrypted by default on Google Cloud.
Sensitive credentials, wrapped
Any third-party access tokens we hold for you are encrypted with a Google Cloud KMS key before storage — never kept in plaintext.
Collector tokens, hashed
Access tokens used by the collector are stored hashed on our side — never in plaintext — and sent only over authenticated HTTPS.
Your data is yours alone.
Every record is fenced to your organization, resolved server-side, and reachable by almost no one.
Per-tenant by default
Every record is scoped to your account and organization, resolved server-side from an authenticated token. Data is separated per tenant.
Modern authentication
Dashboard authentication is handled by Clerk, with modern session security and role-based access.
Integrations bound to you
Third-party integrations like GitHub are bound to your organization only. Unrecognized or unbound sources are rejected, not stored.
Need-to-know internally
Internal production access is limited to authorized personnel, on a need-to-know basis.
Nothing fails silently.
The system watches itself continuously, holds on to anything that fails, and tells you when it matters.
Always watching
Continuous automated monitoring and alerting on system health, errors and processing failures.
Nothing dropped
Failed data is captured in dead-letter queues for review and retry — never silently discarded.
Prompt response
We investigate security and availability incidents promptly, and notify affected customers without undue delay.
Export it. Or erase it completely.
You can take your data with you at any time — or have every trace of it removed, verifiably.
Export
Export your data at any time. Files are delivered through time-limited, expiring secure links.
Deletion, all the way down
Account deletion triggers a full cascade that removes your data across every store, with a 28-day grace period to cancel and a recorded audit trail of exactly what was removed.
Data minimization
We collect metrics about the work, not the work product. The less we hold, the less there is to protect.
Everyone who touches your data.
A complete, current list of the third parties in our stack — and what each one is for.