Security at Nuowei
Nuowei accesses your repositories read-only by default and analyses code in ephemeral, isolated environments without storing source code permanently. The platform runs on EU infrastructure with tenant isolation, short-lived credentials and audit logging.
Last updated:
Principles
- Read-only by default: Nuowei connects to GitHub with read-only access.
- Ephemeral, isolated analysis: each analysis runs in an isolated environment that is discarded afterwards.
- No permanent source-code storage: we keep findings and metadata, not your code.
- EU infrastructure: data is processed and stored in the EU.
- Tenant isolation: customer data is separated per tenant.
- Short-lived credentials: access tokens are scoped and expire quickly.
- Audit logging: security-relevant actions are logged.
Reporting a vulnerability
If you believe you have found a security vulnerability in Nuowei, please email moin@hafencity.dev. Our contact details are also published in security.txt. Please give us reasonable time to fix the issue before public disclosure.
Questions about security? Contact us.