Skip to main content

Trust Center

Code:Sniper is built by greenhats GmbH, a German offensive-security company. Security is not just our product - it is our operational standard. This page provides transparency into our infrastructure, data handling, subprocessors, security testing, and incident response procedures.

Accessibility: Our interface supports keyboard navigation, screen readers, and follows WCAG 2.1 AA guidelines - so everyone can secure their code.

Data Flow

Follow your code through the Code:Sniper analysis pipeline. Each step runs in isolated containers within German data centers. Uploaded source code is encrypted in transit, processed exclusively for analysis, and permanently deleted immediately after scan completion.

  1. 1

    User Login

    Authenticate via GitHub, Google, or Microsoft

  2. 2

    Code Ingest

    Zip upload, CI/CD pipeline, webhook, or API integration

  3. 3

    Extraction

    Safely unpack and validate uploaded files

  4. 4

    SAST & Dependency Scan

    20+ deterministic security tools run entirely on local infrastructure

  5. 5

    AI Agent Analysis

    Language specialists, crypto and auth agents, and business logic agents review every finding

  6. 6

    Cross-Validation

    Independent agents verify, de-duplicate, and filter false positives

  7. 7

    Report Generation

    AI-supported remediation instructions with copy-pasteable fixes

  8. 8

    Export & Integrate

    Download as PDF, Markdown, SARIF, or push directly into your pipeline

Subprocessors

We carefully select and vet every third-party service that processes data on our behalf. All infrastructure runs in German data centers. AI model access is configured for zero data retention (ZDR).

ProcessorPurposeData LocationCompliance
hosting.deInfrastructure & HostingGermany (DE only)ISO 27001(opens in new tab)
OpenRouterAI AnalysisGlobalZero Data Retention only
Google Gemini (GCP)AI AnalysisEurope onlyZero Data Retention · Europe region lock(opens in new tab)
StripePayment ProcessingGlobalPCI DSS Level 1(opens in new tab)
GitHub / Google / MicrosoftOAuth AuthenticationGlobalSOC 2 / ISO 27001

Penetration Testing & Attestations

Code:Sniper is built and operated by certified offensive-security professionals (OSEE, OSCE³). Our infrastructure undergoes regular internal penetration tests conducted by the same team that delivers enterprise security assessments to our clients. Our hosting provider (hosting.de) maintains ISO 27001 certification for the underlying infrastructure. Google Cloud Platform provides SOC 1/2/3, ISO 27001, and additional compliance certifications for AI services running in European data centers. We are actively working toward independent SOC 2 Type II certification for the Code:Sniper platform itself. Enterprise customers may request our security whitepaper and pentest summary under NDA by contacting us directly.

Uptime & System Status

We monitor Code:Sniper 24/7 and publish real-time system status publicly. Planned maintenance windows are announced in advance. In the event of an outage, updates are posted to our status page.

View System Status(opens in new tab)

Incident Response Policy

We treat security incidents with the highest priority. This policy describes how we detect, respond to, and communicate about security events affecting the Code:Sniper platform.

Reporting a Security Incident

If you discover a security vulnerability in Code:Sniper or suspect a breach, please report it immediately. We follow a responsible disclosure process and commit to acknowledging your report within 24 hours. Do not publicly disclose the issue until we have had reasonable time to address it.

Our Response

Upon receiving a report, our security team triages the issue within 4 hours. Critical incidents trigger our incident response plan: containment within 2 hours, root-cause analysis within 24 hours, and remediation deployed as soon as a fix is available. Affected users are notified without undue delay, and a post-mortem is published for significant incidents.

Communication

During an active incident, we communicate via email to affected users and post real-time updates to our status page. After resolution, we publish a post-mortem within 5 business days detailing the timeline, root cause, impact, and measures taken to prevent recurrence.

Security Contact

For security-related inquiries, vulnerability reports, or incident notifications:

admin@greenhats.com

PGP key available upon request.