Security & privacy

Your code stays yours.

Git Listener is a code-access tool, so we hold ourselves to a high bar: read only what's needed, never clone source, and encrypt everything end to end.

We never clone your code

Only commit, branch and pull-request metadata is read through provider APIs. Your source is never cloned, copied or stored.

Encrypted end to end

TLS for everything in transit and AES-256 for everything at rest, including credentials held in an encrypted secret store.

Least-privilege by design

You connect with scoped access tokens you control, and the app is continuously security-scanned.

What we read — and what we never touch

Git Listener connects to your provider with a scoped access token and reads only the metadata required to link development activity to your issues. The contents of your repositories never leave your provider.

  • We read commit messages, branch names and PR titles/status
  • We match them to issues by key, then display them in your tracker
  • We never clone repositories or store file contents
  • You choose exactly which repositories to connect

Repository data flow

Provider API Metadata only Your issue
Source code — never cloned or stored

Encryption & credential handling

Every connection runs over TLS, and everything we persist is encrypted at rest with AES-256. The access tokens you provide are kept in an encrypted secret store and used only to read the data you've authorised.

  • TLS for all data in transit
  • AES-256 for all data at rest
  • Tokens stored in an encrypted secret store
  • Least-privilege, scoped access tokens

At a glance

In transit TLS
At rest AES-256
Source code stored Never
Token storage Encrypted vault
Hosting Resilient cloud

Continuously assessed

As an Atlassian Marketplace app, Git Listener is held to Atlassian's security standards and is continuously assessed — not just at launch, but on every release.

  • Listed on the Atlassian Marketplace
  • Scoped, least-privilege access tokens
  • Continuous automated security scanning
  • Resilient hosting with disaster recovery

Security posture

Source code stored Never
Access tokens Scoped & encrypted
Automated scanning Continuous
Availability DR in place

Questions about security?

We're happy to walk security and procurement teams through our data handling, hosting and compliance.