How We Protect Your Data

Security at every layer

Data Handling

What we collect — and what we don't

DevStats only accesses metadata from your development tools. We analyze patterns in your workflow, not the content of your code.

What we collect:

  • PR metadata
  • Commit timestamps
  • Review timelines
  • Sprint data
  • Deployment events

What we never access:

  • Source code
  • File contents
  • Secrets / credentials
  • Personal messages
Data Flow
Your ToolsGitHub, GitLab, Jira, and other integrations
Metadata ExtractionSource code and file contents are stripped. Only timestamps, counts, and activity data pass through.
Encrypted StoreAES-256 encryption at rest, isolated per customer
Your DashboardAggregated insights delivered over TLS 1.3
Encryption

Protected at every layer

Every byte is encrypted from the moment it leaves your tools to when it reaches your dashboard.

Encryption Specs
In TransitTLS 1.3
At RestAES-256
Key ManagementHSM Vault
Cert RotationAutomatic
Access Control

Enterprise authentication

Control who sees what with role-based access, single sign-on, and two-factor authentication.

  • SSO / SAML support
  • Two-factor authentication
  • Role-based access control
  • Audit logging
  • Session management
Compliance

Independently verified

Our security practices are independently audited and verified. We maintain compliance with industry-leading standards.

SOC 2 Type IIAudited security controls for data handling and protection
Annual Pen TestingThird-party penetration testing by certified professionals
99.9% Uptime SLAEnterprise-grade reliability backed by service level agreements

Want to learn more about our security practices?

Visit our Trust Center →

See DevStats in action.

We'll show you the product, skip the 50-slide circus, and answer your questions straight up. No slides. No fluff. Just the product.