• HOME
  • ON-DEMAND
  • Continuous
  • Adversarial Research
  • Blog
  • About
Log in
Book a demo
Log in

How we protect your code

Last modified: September 14, 2026

Octane reads your source code to find the vulnerabilities in it. That work only exists because companies trust us with what they build. These are the practices we hold ourselves to in return.

Organizational security

  • Information security program. We run an information security program built on the criteria of the SOC 2 framework and communicate it across the company. Every team member reviews and accepts our security policies.
  • Independent review. Independent third parties review our security and compliance controls.
  • Security training. Every team member completes security awareness training covering phishing, password management, and secure handling of customer data.
  • Confidentiality. Team members sign a confidentiality agreement before their first day.
  • Background checks. We run background checks on new hires in accordance with local law.

Cloud and data security

  • Infrastructure. Octane runs on enterprise cloud infrastructure whose provider maintains an extensive set of security certifications of its own.
  • Data location. Customer data lives in data centers in the United States.
  • Encryption. We encrypt data at rest in every datastore and in transit with TLS.
  • Vulnerability management. We look for our own weaknesses the way we look for yours: we scan our code, dependencies, and infrastructure for vulnerabilities.
  • We run Octane on Octane. Our own repositories go through the same analysis we sell.
  • Monitoring. We log and monitor our cloud services and alert the team on failures that affect users.
  • Backups and continuity. Managed backups protect customer data against loss from hardware failure.
  • Incident response. A documented process covers escalation, mitigation, and communication when a security event occurs.

How we handle your source code

  • You choose what we see. Octane connects through a GitHub or GitLab app with scoped permissions. You select the repositories.
  • Isolated analysis. Each analysis runs in an isolated environment.
  • No training on your code. We do not use your source code to train models.
  • Restricted internal access. Employee access to customer code is limited to the people who need it to operate the service.

Access control

  • Least privilege. Access to infrastructure and sensitive tools is limited to the people whose role requires it.
  • SSO and MFA. We protect cloud services with single sign-on, multi-factor authentication, and strong password policies.
  • Access reviews. We review who holds access to sensitive systems and remove access that no longer has a reason to exist.
  • Password managers. Company laptops ship with a password manager.

Vendor and risk management

  • Risk assessments. We assess our risks, including fraud scenarios, and treat what we find.
  • Vendor review. New vendors go through a risk review before we authorize them.

Report a security issue

Questions, concerns, or a vulnerability to report: security@octane.security. We read every report.

Protect your next PR with Octane

Test Octane on Your Code Now
  • Platforms
  • Solutions
  • Case Studies
  • Resources
Stay up to date
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Copyright © 2025  Octane. All Rights Reserved.
  • Privacy
  • terms
  • Security
Find the exploits your pentests and manual reviews miss
4 CVEs
CHROMIUM, VIRTUALBOX x2, QEMU
97.4%
TRUE POSITIVE RATE
$186B+
in customer assets under analysis
‍

Octane delivered findings on par with a world-class security researcher.

Lucas ManueL
Head of Smart Contracts, Phoenix Labs (Spark)
[success]
Thanks! Redirecting you to book your meeting...

If you are not redirected automatically, click the button below.

Book a demo
Oops! Something went wrong while submitting the form.