security & data access

What we touch.
What we keep.

Telemetry access is read-only. Perfloop reads metrics, log aggregates, and profiles within the scope you connect, and some sources can return limited log text. On code, writes are limited to approved branches and pull requests. Perfloop cannot merge, approve, or deploy a change.

connection reads and writes are bounded by your grants and visible in provider audit logs where supported

The data contract.

You choose the repositories and exact telemetry resources. Each connection guide explains the permissions it needs and the data it can read.

Data access by category
categorywhat crosses the boundarywhat perfloop keepsretention
telemetry · metrics & logsread-onlymetadata, metric series, log aggregates, and limited log text, including labels and grouping valuesconnection scope, queries and their results, and derived evidencewhile the customer account is active
telemetry · profilesread-onlysampled profiles, including function and file names, labels, and build identifiers; Google Cloud Profiler access covers the selected projectcapture records and selected profiles, kept as evidencewhile the customer account is active
source coderead + pr writecode in repositories you connect; writes are approved branches and pull requests, never a merge or deploymentrepository metadata, session transcripts, tool records, proposed changes, and evidencewhile the customer account is active

current retention · active product records remain while the customer account is active · an authorized account deletion stops access and removes live data after a recovery period of up to 30 days · after deletion, backups and recovery copies are kept for a limited period and then expire · operational logs and traces are kept up to 365 days, also after deletion · security and audit logs may be kept longer where needed for security, legal or compliance reasons

not requested as separate inputs

  • unbounded telemetry row accessPerfloop reads aggregates, not unbounded raw rows; some sources can return limited log text. Labels, grouping values, log text, and profiles can contain sensitive values, so scope the source before you connect it.
  • automatic resource expansionYou name or select each connected resource, and selecting one does not connect others. Google Cloud Profiler access covers the selected project.
  • upstream provider credentialsThe agent's sandbox holds no credentials for code hosts, telemetry sources, or model providers. Connected code can still contain secrets.
  • merge or deployment authorityPerfloop cannot merge, approve, or deploy a change.

Connections and residency.

What you connect and where Perfloop runs are separate, independent choices. Each connection is its own grant and can be revoked at its provider. Revocation stops new provider reads; product-data deletion is separate. Nothing is connected by default.

what you connect

  1. code host

    Read access and limited writes on repositories you select: approved branches, pull requests, and comments. Perfloop cannot merge or approve.

    benchmarks run in perfloop's sandbox · every write is bound to the approved branch or pull request

  2. telemetry source

    Read access to resources you name or select: metadata, metric series, log aggregates, and profiles. Google Cloud Profiler access covers the selected project.

    your read-only grant and the resources you select set what perfloop can read

where perfloop runs

  1. our cloud

    One workspace per customer on shared infrastructure.

    the default · product data is stored in our gcp deployment · selected model context goes to the providers below

  2. your cloud

    Product storage can run in a project you provision. Approved inference providers still receive selected model context.

    not generally available · requires a separate agreement

the soc 2 type ii report is not issued · the current observation status is below

Agent containment.

The agent runs your code and reads your telemetry, so the architecture treats it as compromised and contains it.

the agent is treated as compromised

  • sandboxed sessionsEvery session runs in its own isolated, short-lived sandbox, destroyed when the session ends. The sandbox cannot reach the infrastructure it runs on.
  • upstream secrets stay outsideThe sandbox holds no credentials for GitHub, model providers, or your telemetry. A proxy adds them only after its checks pass.
  • one path outThe sandbox can open network connections only through the proxy.
  • permissions enforced in the proxyAllowed destinations and per-session permissions are checked outside the model. Code-host writes are limited to the approved branch and pull request; merge and approval are denied.

The control plane.

Containing the agent is half of it. The platform that holds your derived data is itself least-privilege.

least privilege by default

  • private databaseThe product database has no public address and accepts only encrypted connections from inside our private network.
  • encrypted at restAll stored data is encrypted at rest with platform-managed keys.
  • scoped credentialsThird-party credentials are held only by the service that uses them, never by the agent. Code-host access uses short-lived tokens scoped to approved repositories.
  • least privilege between servicesInternal services are deny-by-default on the network and have only the permissions they need.
  • managed secret storeService secrets and keys live in a managed secret store. Customer connection credentials are stored encrypted, and the agent never receives them.
  • audit recordsAudit records are kept for security and compliance. Account deletion removes the account's audit records and keeps one summary record of the deletion, without customer content.

The questions your security team will ask.

Answered up front, against ground truth.

  1. 01

    Does our raw data ever reach an LLM?

    Yes. Connected source code, prompts, and tool results can enter model context, including metrics and labels, log aggregates, limited log text, and profiles. Model inference uses OpenAI and Google Vertex AI, and their own retention terms apply. Perfloop does not use customer content to train models.

  2. 02

    What happens if your agent is prompt-injected?

    Assume it happens; the architecture does. The session holds no upstream provider credentials and has one network path: the proxy, which checks destinations and permissions outside the model. A hijacked agent gains no provider credentials, no new destinations, and no way to merge anything.

  3. 03

    Who are the subprocessors?

    The main ones are Google Cloud (hosting and model inference), OpenAI (model inference), WorkOS (authentication), and Axiom (logs and monitoring). See the Privacy Policy for provider information.

  4. 04

    Can Perfloop employees see our data?

    Authorized Perfloop personnel can access customer data when needed to operate, secure, diagnose, or support the Service. Provider grants remain bounded by the scope you gave Perfloop.

  5. 05

    What happens when we revoke?

    Remove repositories from the GitHub App or uninstall it to stop GitHub access. Revoke a telemetry grant at its provider to stop new reads. Neither deletes records Perfloop already stored; an authorized account deletion removes those as described above.

  6. 06

    How do you know what data you need before seeing our telemetry?

    You name or select each resource before you connect it. Setup may list resources visible to your grant. After that, Perfloop reads only the resources you connected and does not add others on its own. Google Cloud Profiler access covers the selected project.

Status.

This page documents what Perfloop accesses and how that access is controlled, in claims you can verify today. Formal attestations are in progress; their status is below.

architecture review
available now
This page, the full data-access specification, and a founder walkthrough with your security team.
soc 2 type ii
observation period
Type II observation is in progress. The report is not issued.
dpa
in preparation
We are preparing a standard Data Processing Addendum.
byoc
not generally available
Requires a separate enterprise agreement.

Report a vulnerability.

If you find a security vulnerability in Perfloop, email security@perfloop.ai. Include enough detail for us to reproduce it.

We review every report and reply. Test only with your own account and data, and keep the details private until we have released a correction.

For your
security team.

full specification + security questions: security@perfloop.ai →