Trust Center
Code:Sniper is built by greenhats GmbH, a German offensive-security company. Security is not just our product - it is our operational standard. This page provides transparency into our infrastructure, data handling, subprocessors, security testing, and incident response procedures.
Data Flow
Follow your code through the Code:Sniper analysis pipeline. Each step runs in isolated containers within German data centers. Uploaded source code is encrypted in transit, processed exclusively for analysis, and permanently deleted immediately after scan completion.
- 1
User Login
Authenticate via GitHub, Google, or Microsoft
- 2
Code Ingest
Zip upload, CI/CD pipeline, webhook, or API integration
- 3
Extraction
Safely unpack and validate uploaded files
- 4
SAST & Dependency Scan
20+ deterministic security tools run entirely on local infrastructure
- 5
AI Agent Analysis
Language specialists, crypto and auth agents, and business logic agents review every finding
- 6
Cross-Validation
Independent agents verify, de-duplicate, and filter false positives
- 7
Report Generation
AI-supported remediation instructions with copy-pasteable fixes
- 8
Export & Integrate
Download as PDF, Markdown, SARIF, or push directly into your pipeline
Subprocessors
We carefully select and vet every third-party service that processes data on our behalf. All infrastructure runs in German data centers. AI model access is configured for zero data retention (ZDR).
| Processor | Purpose | Data Location | Compliance |
|---|---|---|---|
| hosting.de | Infrastructure & Hosting | Germany (DE only) | ISO 27001(opens in new tab) |
| OpenRouter | AI Analysis | Global | Zero Data Retention only |
| Google Gemini (GCP) | AI Analysis | Europe only | Zero Data Retention · Europe region lock(opens in new tab) |
| Stripe | Payment Processing | Global | PCI DSS Level 1(opens in new tab) |
| GitHub / Google / Microsoft | OAuth Authentication | Global | SOC 2 / ISO 27001 |
Penetration Testing & Attestations
Code:Sniper is built and operated by certified offensive-security professionals (OSEE, OSCE³). Our infrastructure undergoes regular internal penetration tests conducted by the same team that delivers enterprise security assessments to our clients. Our hosting provider (hosting.de) maintains ISO 27001 certification for the underlying infrastructure. Google Cloud Platform provides SOC 1/2/3, ISO 27001, and additional compliance certifications for AI services running in European data centers. We are actively working toward independent SOC 2 Type II certification for the Code:Sniper platform itself. Enterprise customers may request our security whitepaper and pentest summary under NDA by contacting us directly.
Uptime & System Status
We monitor Code:Sniper 24/7 and publish real-time system status publicly. Planned maintenance windows are announced in advance. In the event of an outage, updates are posted to our status page.
View System Status(opens in new tab)Incident Response Policy
We treat security incidents with the highest priority. This policy describes how we detect, respond to, and communicate about security events affecting the Code:Sniper platform.
Reporting a Security Incident
If you discover a security vulnerability in Code:Sniper or suspect a breach, please report it immediately. We follow a responsible disclosure process and commit to acknowledging your report within 24 hours. Do not publicly disclose the issue until we have had reasonable time to address it.
Our Response
Upon receiving a report, our security team triages the issue within 4 hours. Critical incidents trigger our incident response plan: containment within 2 hours, root-cause analysis within 24 hours, and remediation deployed as soon as a fix is available. Affected users are notified without undue delay, and a post-mortem is published for significant incidents.
Communication
During an active incident, we communicate via email to affected users and post real-time updates to our status page. After resolution, we publish a post-mortem within 5 business days detailing the timeline, root cause, impact, and measures taken to prevent recurrence.
Security Contact
For security-related inquiries, vulnerability reports, or incident notifications:
admin@greenhats.comPGP key available upon request.