Infersync
Security

Your code stays yours.

Infersync connects to GitHub to coordinate engineering work, not to read it. Here is how we handle access and data, and an honest note on what we have not built yet.

We read metadata, not your source code

The GitHub App works with issues, pull requests, labels, assignees, and state. It does not request repository contents, and Infersync never reads or mirrors your source files.

Encryption in transit and at rest

All traffic is encrypted in transit, and data is encrypted at rest. LLM API keys you bring are stored encrypted and shown only as a masked last-four.

You control what agents can do

The autopilot proposes a plan; actions like assigning, labeling, and setting state run against GitHub only after you approve them, and every action lands in an audit log.

Authentication

Sign in with GitHub OAuth. Sessions are scoped to your workspace. SSO (SAML / OIDC) and SCIM provisioning are on the Enterprise roadmap, not yet shipped.

Your data, your call

Export your workspace data at any time. Request erasure, and delete a workspace to trigger a hard-delete within 30 days. We do not train models on your data.

Bring your own models

Connect your own LLM keys and your own agents over MCP or the API, run locally or on your own infrastructure. The model and the machine can stay yours.

Where we are, honestly

No certifications we haven't earned.

We are an early company and we say so. Infersync has not completed a SOC 2 or ISO 27001 audit, and we will not claim a badge we do not hold. Enterprise customers can request our current security posture, a DPA, and a security review, and we are happy to walk through exactly what is and isn't in place today.