Security · Updated 2026-10-09

Security

How BuiltBrief protects your repositories and data, how to uninstall and delete, and how to report a vulnerability.

BuiltBrief reads your GitHub so it can brief you. We designed it to see as little as possible, keep less, and make it easy to leave.

We don't hold any third-party security certification, such as SOC 2 or ISO 27001. This page describes what we actually do.

Read-only GitHub access

BuiltBrief connects through a GitHub App that you install on the repositories you choose. Every permission is read-only, and BuiltBrief can't push code, comment, merge or change settings.

Permission Why we need it
Metadata (read) Required by GitHub for every app. Repository names, IDs and visibility
Pull requests (read) PR titles, descriptions, reviews, status and diffs, which are the core of each digest
Issues (read) Issues and comments, for what's planned, reported or blocked
Actions (read) Workflow run results, so briefs can report CI health
Deployments (read) Deployment status, so briefs can say what actually shipped

What we don't ask for:

You decide which repositories the App can see, and you can change that at any time in GitHub.

We don't store your code

For each run, BuiltBrief fetches PR text and diff excerpts into memory, sends them to our AI model provider to write digests, and then discards them. We don't write source code, diffs, or PR and issue text to our database.

We do store:

Our AI provider. We use Anthropic's Claude API. Under Anthropic's commercial terms, it may not train models on the content we send. By default, it deletes API inputs and outputs within 30 days.

Encryption

Short-lived tokens

BuiltBrief doesn't hold a long-lived key to your repositories. For each run, it requests a GitHub installation token that expires after one hour and only covers the repositories you selected. If you uninstall the App, GitHub stops issuing tokens straight away.

Signed webhooks

GitHub and Stripe send us events, such as "app installed" or "subscription renewed". We check each event's HMAC signature with a constant-time comparison and reject anything unsigned or invalid.

Sign-in and reader links

Built-in safety for AI

Isolation and access

Uninstall and delete

To stop BuiltBrief reading your repositories:

  1. In GitHub, go to Settings → Applications → Installed GitHub Apps (for an organization: Organization settings → GitHub Apps).
  2. Choose BuiltBrief → Configure.
  3. Remove repositories, or click Uninstall.

To delete your data: delete your workspace in BuiltBrief's account settings, or email hello@builtbrief.com from the owner's address.

After you uninstall or delete your account, we delete repository metadata, digests, briefs and account data within 30 days. Digests and briefs older than 13 months are deleted automatically. By default, our AI provider deletes its copies within 30 days of each run.

Reporting a vulnerability

Email security@builtbrief.com. Please include:

We'll acknowledge your report within 3 business days and keep you updated. We won't take legal action against good-faith research that:

Please don't run automated scanners against production or attempt social engineering. We don't currently run a paid bug bounty.

Sub-processors

Cloudflare (hosting, database, email), Anthropic (AI model), Stripe (payments) and GitHub (sign-in and repository data). See our Privacy Policy and DPA for details.