security & data access
Telemetry access is read-only. Perfloop reads metrics, log aggregates, and profiles within the scope you connect, and some sources can return limited log text. On code, writes are limited to approved branches and pull requests. Perfloop cannot merge, approve, or deploy a change.
connection reads and writes are bounded by your grants and visible in provider audit logs where supported
You choose the repositories and exact telemetry resources. Each connection guide explains the permissions it needs and the data it can read.
| category | what crosses the boundary | what perfloop keeps | retention |
|---|---|---|---|
| telemetry · metrics & logsread-only | metadata, metric series, log aggregates, and limited log text, including labels and grouping values | connection scope, queries and their results, and derived evidence | while the customer account is active |
| telemetry · profilesread-only | sampled profiles, including function and file names, labels, and build identifiers; Google Cloud Profiler access covers the selected project | capture records and selected profiles, kept as evidence | while the customer account is active |
| source coderead + pr write | code in repositories you connect; writes are approved branches and pull requests, never a merge or deployment | repository metadata, session transcripts, tool records, proposed changes, and evidence | while the customer account is active |
current retention · active product records remain while the customer account is active · an authorized account deletion stops access and removes live data after a recovery period of up to 30 days · after deletion, backups and recovery copies are kept for a limited period and then expire · operational logs and traces are kept up to 365 days, also after deletion · security and audit logs may be kept longer where needed for security, legal or compliance reasons
not requested as separate inputs
What you connect and where Perfloop runs are separate, independent choices. Each connection is its own grant and can be revoked at its provider. Revocation stops new provider reads; product-data deletion is separate. Nothing is connected by default.
Read access and limited writes on repositories you select: approved branches, pull requests, and comments. Perfloop cannot merge or approve.
benchmarks run in perfloop's sandbox · every write is bound to the approved branch or pull request
Read access to resources you name or select: metadata, metric series, log aggregates, and profiles. Google Cloud Profiler access covers the selected project.
your read-only grant and the resources you select set what perfloop can read
One workspace per customer on shared infrastructure.
the default · product data is stored in our gcp deployment · selected model context goes to the providers below
Product storage can run in a project you provision. Approved inference providers still receive selected model context.
not generally available · requires a separate agreement
the soc 2 type ii report is not issued · the current observation status is below
Use credentials with read-only access to the resources you want to connect. Perfloop cannot inspect every permission a credential holds, so remove broader roles before you connect. Each guide explains the permissions and data for that source.
The agent runs your code and reads your telemetry, so the architecture treats it as compromised and contains it.
the agent is treated as compromised
Containing the agent is half of it. The platform that holds your derived data is itself least-privilege.
least privilege by default
Answered up front, against ground truth.
Yes. Connected source code, prompts, and tool results can enter model context, including metrics and labels, log aggregates, limited log text, and profiles. Model inference uses OpenAI and Google Vertex AI, and their own retention terms apply. Perfloop does not use customer content to train models.
Assume it happens; the architecture does. The session holds no upstream provider credentials and has one network path: the proxy, which checks destinations and permissions outside the model. A hijacked agent gains no provider credentials, no new destinations, and no way to merge anything.
The main ones are Google Cloud (hosting and model inference), OpenAI (model inference), WorkOS (authentication), and Axiom (logs and monitoring). See the Privacy Policy for provider information.
Authorized Perfloop personnel can access customer data when needed to operate, secure, diagnose, or support the Service. Provider grants remain bounded by the scope you gave Perfloop.
Remove repositories from the GitHub App or uninstall it to stop GitHub access. Revoke a telemetry grant at its provider to stop new reads. Neither deletes records Perfloop already stored; an authorized account deletion removes those as described above.
You name or select each resource before you connect it. Setup may list resources visible to your grant. After that, Perfloop reads only the resources you connected and does not add others on its own. Google Cloud Profiler access covers the selected project.
This page documents what Perfloop accesses and how that access is controlled, in claims you can verify today. Formal attestations are in progress; their status is below.
If you find a security vulnerability in Perfloop, email security@perfloop.ai. Include enough detail for us to reproduce it.
We review every report and reply. Test only with your own account and data, and keep the details private until we have released a correction.
full specification + security questions: security@perfloop.ai →