C:\> security
Codepanion gives your support team read access to your codebase and production database, so we hold ourselves to the bar that access demands. Here is how we handle your data, who our subprocessors are, and how to report a vulnerability.
Your code, your data, and your conversations are never used to train any AI model — ours or anyone else's. Codepanion uses your data only to answer the questions your team asks, within your own tenant.
The agent runs on Azure OpenAI (Azure AI Foundry). Microsoft is contractually committed to not using your prompts or the model's responses to train, retrain, or improve any of its models, and does not share them with other customers or with OpenAI. Azure OpenAI runs inside Microsoft's own Azure environment — your data is not sent to a third-party model provider.
We keep our supply chain small. Codepanion runs entirely on Microsoft Azure; we do not use a separate analytics, logging, or model vendor outside it.
| Subprocessor | Purpose |
|---|---|
| Microsoft Azure | Cloud hosting, compute, storage, and managed databases. The product runs entirely on Azure. |
| Azure OpenAI / Azure AI Foundry | The AI models behind the agent (chat completions and embeddings). Operated by Microsoft within Azure; contractually no-train. Deployed on Azure's Global Standard tier, so Microsoft may route individual model requests to Azure data centers in other regions under Microsoft's product terms; data at rest stays in the US. |
| Azure Communication Services | Transactional email (invites, welcome messages, notifications). |
If you believe you've found a security issue, please email security@codepanion.app rather than opening a public issue. We aim to acknowledge reports within two business days and will keep you updated through to a fix.
We operate in good faith with researchers: security testing carried out in line with our disclosure policy — avoiding privacy violations, service disruption, and access to other customers' data — is authorized, and we will not pursue legal action over it. The full policy and safe-harbor terms are published as SECURITY.md and as /.well-known/security.txt.
Running a vendor review or need more detail than this page covers? Email security@codepanion.app and we'll work through your questionnaire with you.