Your code stays yours.
Infersync connects to GitHub to coordinate engineering work, not to read it. Here is how we handle access and data, and an honest note on what we have not built yet.
We read metadata, not your source code
The GitHub App works with issues, pull requests, labels, assignees, and state. It does not request repository contents, and Infersync never reads or mirrors your source files.
Encryption in transit and at rest
All traffic is encrypted in transit, and data is encrypted at rest. LLM API keys you bring are stored encrypted and shown only as a masked last-four.
You control what agents can do
The autopilot proposes a plan; actions like assigning, labeling, and setting state run against GitHub only after you approve them, and every action lands in an audit log.
Authentication
Sign in with GitHub OAuth. Sessions are scoped to your workspace. SSO (SAML / OIDC) and SCIM provisioning are on the Enterprise roadmap, not yet shipped.
Your data, your call
Export your workspace data at any time. Request erasure, and delete a workspace to trigger a hard-delete within 30 days. We do not train models on your data.
Bring your own models
Connect your own LLM keys and your own agents over MCP or the API, run locally or on your own infrastructure. The model and the machine can stay yours.
Where we are, honestly
No certifications we haven't earned.
We are an early company and we say so. Infersync has not completed a SOC 2 or ISO 27001 audit, and we will not claim a badge we do not hold. Enterprise customers can request our current security posture, a DPA, and a security review, and we are happy to walk through exactly what is and isn't in place today.