
CodSpeed runs inside your CI, which puts it in scope for your security review. An independent third-party auditor has now examined how CodSpeed handles your data, and CodSpeed is SOC 2 Type II compliant: the controls were tested across an observation window, not just confirmed at a single point in time.
The Trust Center gives a detailed overview of CodSpeed's security practices, policies, and controls, including the subprocessors that process customer data. It is the fastest way to answer a security questionnaire without waiting on a reply.
To request a copy of the SOC 2 Type II report, contact security@codspeed.io. What CodSpeed stores and what it never retains, including source code, is documented on the security page.