Loading...
Understand which repositories FlagShark can access, which artifacts a workflow retains, and how review and publication are controlled. Migration previews can contain source; confirm the applicable controls before connecting a pilot repository.
Repository analysis reads source. Migration assessments and exact previews can retain source-bearing artifacts with expiry controls. Confirm the applicable retention and deletion terms when scoping your pilot.
Repository contents and pull-request write permissions support admitted migration and cleanup PRs. Review the actual installation permission screen and select the repositories you intend to connect.
Workspace and repository identities are checked before admitted operations. Review the applicable access controls, processing boundaries and operational evidence when scoping a pilot.
All data is encrypted using AES-256 at rest and TLS in transit. We use AWS-managed encryption for storage and AWS KMS for application secrets.
We request only the permissions required to analyse your code and open cleanup PRs. No access to secrets, environment variables, admin settings, billing, or organisation management.
What we DON'T access: secrets, environment variables, admin settings, billing, or organisation management.
Migration source and preview artifacts have workflow-specific expiry controls; operation summaries and receipts have different retention needs. Confirm the deployed retention and deletion process for your pilot by contacting joe@flagshark.com.
Happy to discuss security requirements, compliance needs, or custom enterprise configurations.