Your source code is never stored
Each run is a short-lived job in a fresh container. It takes a shallow, sparse clone of the merge commit, limited to your docs folder where there is one, works on it, and ends. When the run ends, the container and the clone are gone.
- Your source code and code changes are never written to DocFit's database.
- PR descriptions and ticket text are read during the run and not kept.
- The run gets a GitHub token minted for that run, valid for under an hour, and nothing else from your account.
- Your own build and lint commands run in an isolated runner that holds no DocFit secrets.
What DocFit never does
- Never merges. It opens pull requests and posts comments. A person on your team decides what ships.
- Never writes outside your docs. The editing agent can only read and write inside the docs folder of its own branch. Absolute paths,
..and symlinks out of it are refused, and a final check drops any change outside it. - Never pushes outside its own branches. Every commit goes to a branch named
docfit/…. - Never deletes a page. The agent has no tool to remove files.
- Never changes a ticket's status. It posts one comment with the docs PR, and nothing else.
- Never reaches the network or runs shell commands from the agent. Its tools are scoped to your docs and DocFit's own checks.
Your code is never used to train models
- Models are called through Google Vertex AI (Gemini, and Claude as a managed model) and Anthropic, under API terms that exclude training on your data.
- Only what a run needs is sent: the change, its PR and ticket, and the docs pages it affects.
- Open-weight models are off unless an admin opts in, and are then served by Google on Vertex AI, so nothing reaches the model's vendor.
- Bring your own Anthropic, Vertex AI or OpenRouter key and model calls run on your own account.
Access only where you allow it
DocFit is a GitHub App, so access is per installation and per repository. You choose which repositories it can see, and every repository stays off until you turn it on.
| Permission | Access | Used for |
|---|---|---|
| Contents | Read and write | Reading the merged change and docs; committing to docfit/ branches |
| Pull requests | Read and write | Reading the merged PR; opening and updating docs PRs |
| Issues | Read and write | GitHub Issues as ticket context; one comment back |
| Checks | Write | The docs impact check on open PRs |
| Metadata | Read | Repository names and settings |
Jira Cloud connects with OAuth and only read:jira-work, write:jira-work and offline_access, limited to the projects you allow. Slack only posts to the channels you pick. Every webhook DocFit receives, from GitHub, Slack or payments, is signature-checked and de-duplicated.
Prompt-injection defence
Diffs, code comments, PR descriptions, tickets and docs are treated as untrusted input. DocFit fences them so they can't pose as instructions, gives the agent only docs-scoped tools with no shell and no network, and checks the final diff. A hostile instruction can at worst produce a docs PR that a human then reviews.
Secrets and isolation
- Tokens and API keys are never stored in plain text: they're encrypted with AES-256-GCM using a key held in Google Secret Manager.
- Tokens, keys and private keys are never written to logs.
- One workspace can never read another's data: every query goes through a layer that refuses to run without your workspace id.
- Nothing travels unencrypted: all traffic uses TLS.
Leave any time, and nothing stays
- Uninstall the GitHub App and DocFit's access stops immediately.
- Delete your workspace from Settings and everything is purged within 30 days; you can change your mind until then.
- Remove a repository, a rule or an integration whenever you like.
Subprocessors
| Provider | Purpose |
|---|---|
| Google Cloud | Hosting, job queue, secrets, Vertex AI models |
| MongoDB Atlas (on Google Cloud) | Database |
| Anthropic | Claude models |
| Resend | |
| Dodo Payments | Payments, merchant of record |
| Slack, Atlassian | Only if you connect them |
| OpenRouter | Only if you bring an OpenRouter key |
Compliance
DocFit is in early access and not yet SOC 2 certified; SOC 2 Type I is planned as the customer base grows. Security questionnaire answers are available on request.
Report a vulnerability
Email security@docfit.dev with the details and steps to reproduce. You'll hear back within two business days. Please give us reasonable time to fix an issue before you publish it, and don't access data that isn't yours while testing.