Skip to content
  • Docs
  • Pricing
  • FAQ
Run Free Audit Log In

repod Trust Pack

A concise summary for buyers reviewing repod for a pilot or subscription.

This Trust Pack describes the current operating posture. It should be read with the Security page, DPA, Privacy Policy, Cookie And Storage Notice, and Subprocessors page.

What repod Does

repod helps teams review and manage GitHub repository access using organization metadata, repository names and metadata, teams, members, direct collaborator access, and repo-team permission state.

What repod Does Not Do In Normal Operation

  • Does not clone repositories.
  • Does not process source code contents.
  • Does not retrieve repository contents, commit diffs, issue or pull-request body text, Actions logs, or build artifacts in normal operation.
  • Does not require Repository Contents permission for core sync, reporting, repo-to-team apply, or repository metadata workflows.
  • Does not require write permissions for the public access health check or audit/read mode.

What repod Does Not Prevent

  • repod is not endpoint security. A compromised workstation, IDE extension, browser session, or stolen GitHub credential can still abuse the GitHub access that credential already has.
  • repod helps reduce blast radius by making broad access, direct grants, stale permissions, and team-model drift easier to review and fix.

GitHub Permission Modes

repod supports two connection models: fine-grained GitHub PAT auth and GitHub App beta. For PAT auth, submitted tokens must begin with github_pat_. GitHub App beta uses encrypted app credentials and short-lived installation tokens.

  • Audit/read mode: read-oriented access for org settings, repository metadata, members, teams, direct collaborator access, and repo-team permission state.
  • Write mode: additional permissions only when repod applies repo-team permission changes, repository metadata changes, repository renames, or team-management actions.

Core workflows do not require Organization Members write, so they do not have the GitHub permission needed to create organization invitations. Optional Team management is the exception: it requires Organization Members write and should not be granted where the buyer needs organization-invitation capability to be technically impossible from the repod GitHub credential. Repository Administration write may still allow direct repository collaborator changes where a customer enables apply/direct-access workflows.

Security Controls

  • Fine-grained GitHub PATs only for PAT-auth submitted tokens.
  • PATs and GitHub App private keys encrypted at rest and never logged in plaintext.
  • GitHub App beta mints short-lived installation tokens when calling GitHub APIs.
  • Account-scoped data model and role-based access controls.
  • Audit logs for org lifecycle, token rotation, sync, account, and access-change events.

Vendor Review Links

  • Security overview
  • Subprocessors
  • Data Processing Addendum
  • Privacy Policy
  • Cookie And Storage Notice
  • Terms of Service
  • Vulnerability Disclosure

Compliance Status

repod does not currently hold SOC 2, ISO 27001, or Cyber Essentials accreditation. Formal external attestation is planned for a later stage; the current trust pages document the security posture, controls, and operating model available for vendor review.

Customers with formal procurement requirements can request current security, subprocessor, retention, and legal-version evidence through support@repod.dev.

© 2026 Data Demon Systems Limited. repod.dev is a business SaaS product for GitHub access operations.
Docs Pricing Contact Terms DPA Privacy Cookies Subprocessors Security Vulnerability Disclosure Data Demon Systems LinkedIn

Data Demon Systems Limited is registered in England and Wales with company number 16158110.

Help improve repod Allow session analytics so we can understand which workflows are useful. Optional analytics begins only after consent in production. Sensitive GitHub data is never sent. Privacy details