What happens to your code.
Engineering teams ask us the same questions before they start. Here are the answers, based on how our service actually works.
The path your code takes
- 1. GitHubA pull request is opened or updated in a repository where our app is installed and enabled.
- 2. Duosien review serviceOur service runs on Cloudflare's network. Its queue holds only the repository name, pull request number and commit. When the job runs, it fetches the changes from GitHub into memory.
- 3. Claude on Amazon BedrockThe changes are sent to Claude in Duosien's AWS account in us-east-1 (N. Virginia), or in your own AWS account and region if you choose. This endpoint does not route requests to other regions.
- 4. Back to GitHubThe review is posted on the pull request. Nothing from the code is kept on our side.
What we keep, and for how long
| Data | How long we keep it |
|---|---|
| Your source code and diffs | Not stored. Held in memory only while a review runs. |
| Review comments | Stored in GitHub. We do not keep a copy. |
| Code pasted into the online review | Not stored. Held in memory only while the review runs. |
| Monthly usage per organization: number of reviews and token counts | 13 months, for reports and invoices |
| Record that a commit was reviewed: repository, pull request number, commit | 30 days, to avoid duplicate reviews |
| Installations not yet enabled: GitHub account name and installation ID | 90 days |
| Online review: IP address with a daily counter | 48 hours, to enforce the daily limit |
| Service logs: event type, repository name, pull request number, token counts. No code. | Kept by Cloudflare for a short, fixed period |
| Contracts and invoices | 7 years |
| Verification records, such as company documents and sanctions screening | 5 years after our contract ends |
Model and training
Reviews use Claude Sonnet 5 on Amazon Bedrock. Amazon states that Bedrock does not store prompts and outputs, does not use them to train models, and does not share them with model providers. See Amazon Bedrock security. We do not use your code to train any model.
AWS states that for certain models it keeps all requests for up to 30 days to detect abuse (it currently lists Claude Fable 5 and 5.1). Our service is configured to refuse those models. If that changes, we will tell you first. See Bedrock abuse detection.
GitHub permissions
| Permission | Why |
|---|---|
| Contents: read | Read the changed code in a pull request |
| Pull requests: read and write | Read the pull request and post the review |
| Checks: read and write | Show the review status. The result is always neutral. |
| Metadata: read | Required by GitHub for every app |
The app cannot merge, push or change code, and it reads only the repositories you select.
Access
- Duosien staff do not read your code. There is no copy of it for anyone to read.
- Access to our production systems is limited to named engineers, protected by multi-factor sign-in.
- Data is encrypted in transit.
When you leave
Uninstall the GitHub app and our access ends at once. Within 30 days we delete the usage records we hold about you, except records we must keep by law, and confirm in writing.
Providers we use
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Website, review service, job queue and settings storage. Code passes through in memory. | Global network |
| Amazon Web Services | Claude models on Amazon Bedrock | us-east-1, or your own account and region |
| GitHub | Where your code and review comments live | Per your GitHub settings |
| Stripe | Subscription payments and invoices. Stripe does not receive your code. | United States |
| Resend | Delivers website form messages to our mailbox | United States |
| Google Workspace | Company email | United States |
Data processing agreement
We sign a data processing agreement (DPA) with every customer. For EU customers it includes the standard contractual clauses. Write to hello@duosien.com.