Security for the code you entrust to us.
Farion analyses source code, dependencies and running applications. This page summarises how we run the platform, how we protect your data and how to report a vulnerability to us.
How we protect your data.
The complete technical and organisational measures are Annex 2 of our data processing agreement. These are the essentials.
Run in German data centres
Source code, derived analysis data and scan results are processed and stored exclusively in German data centres. Enterprise customers can arrange dedicated deployments within the EU or on-premises.
Encrypted in transit and at rest
External connections use TLS only; volumes, object storage and backups are encrypted server-side. Credentials for your repositories are additionally encrypted asymmetrically before they are stored and decrypted only for the duration of a scan.
Access and permissions
Sign-in via single sign-on (OIDC) or email and password, role-based permissions per workspace, and multi-factor authentication for every administrative access to the infrastructure. An API gateway checks each request before it reaches an internal service.
Tenant isolation
Each customer works in its own workspace, and every access is authorised server-side against workspace membership. Test, staging and production environments are kept apart.
Our own security AI, no training on customer data
AI-assisted assessment runs primarily on infrastructure operated by Farion itself, with any supplementary inference likewise confined to German data centres. Source code, scan context and results are never used to train or fine-tune models, and no third-party public LLM APIs are used for customer data.
Deletion after analysis
Source code archives are deleted once the analysis is complete. When usage ends, customer data is deleted or returned as set out in the DPA, including the complete deletion of a workspace.
Availability and recovery
Highly available databases across several availability zones, continuous backups with point-in-time recovery, and regularly rehearsed restores.
Traceability
Security-relevant operations are logged with a timestamp and the triggering identity. Infrastructure and configuration are rolled out from versioned Git and every change is reviewed. We run monitoring and telemetry ourselves, with no external provider.
Farion scans Farion
Our own codebase is scanned with Farion in every pipeline, dependencies and container images included.
Found a security issue in Farion?
Write to security@farion.ai. The same contact details are published in machine-readable form in our security.txt (RFC 9116). We confirm receipt of your report and let you know once the issue is fixed.
Affected component
The URL, endpoint or module where you found the issue.
Steps to reproduce
Ideally with a sample request or proof of concept.
Impact
Your assessment of what an attacker could achieve with it.
How to reach you
An address we can use for questions and to report back.
Please access only data that belongs to you, do not modify or delete anyone else's data, do not run load or denial-of-service tests, and give us time to fix the issue before publishing details.
Further reading
Questions about security or compliance?
Our team answers questions about how the platform is run, data protection, and the evidence you need for a vendor assessment.