← DevEval Security & deployment

Diff in. Scores out.

Your repository stays the source of truth. DevEval connects through read-only integrations and turns engineering activity into scores, findings, and delivery insights — without becoming another code hosting platform.

Data boundary

What gets stored — and what doesn't.

Every integration is scoped to the minimum it needs. DevEval stores analysis results and selected delivery metadata needed for reporting, but does not retain repository checkouts or source files as product content.

IN · READ-ONLY

What DevEval reads

PR metadata
Title, description, author, reviewers, timings, review iterations.
Code changes
The diff — and, for larger changes, the repository context needed to judge them fairly. Used for the analysis, not retained.
Issues & estimates
Title, labels, worklogs.
Review comments
The discussion and how it was resolved.
Static-analysis signals
Complexity, lint counts.
NOT STORED

What DevEval does not store

Repository copies
Repository checkouts and source files are used only while an analysis runs, then removed — they are not retained as product content.
Secrets & config files
Not part of the analysis, never retained.
Your end-users' application data
Out of scope by design.
Your data as training data
We do not use your data to train models. AI processing uses commercial API services under terms that exclude customer inputs from model training.

Integrations are read-only — DevEval does not request write access to your repositories or issue trackers. In self-hosted deployments, repository processing runs in your environment and AI routing follows the agreed architecture.

Deployment

Run it your way.

Cloud and self-hosted deployments use the same scoring model. Self-hosting is available with Enterprise and scoped together with our team.

CLOUD

Cloud, EU

Hosted by us, data resident in the EU

Hosted in the EU with EU data residency. GDPR-compliant, with a Polish legal entity behind the contract and standard VAT invoices.

EU data residencyGDPRVAT invoices
SELF-HOSTED

Self-hosted · Enterprise

Your infrastructure, your perimeter

Docker Compose or Kubernetes in your environment. Deployment architecture, AI endpoints, integrations, and support are scoped together with our team. Contact us to discuss requirements and rollout.

Docker ComposeKubernetesEnterprise deploymentScoped rollout
Access control

Access control that assumes an auditor.

Least privilege is the default configuration, not a hardening guide. Every read has a scope; every sensitive number has a gate.

Capability-based RBAC No blanket “admin” — every action is gated by an explicit capability with a scope: self, team, or org.
Financial masking Rates, costs, and ROI figures are visible only with the finance capability — including in AI chat answers, which return nothing rather than guess.
Tenant isolation Every query is scoped to the organization at the data layer. Software houses get per-client workspaces.
Enterprise Self-hosted deployment, custom limits, tailored rollout, and a support model scoped to your organization.
Trial

30-day cloud trial. No credit card.

Connect supported read-only integrations, evaluate DevEval with your team, and disconnect at any time. Self-hosted deployments are available separately with Enterprise.

TRIAL
30 days
EU-hosted cloud
CREDIT CARD
None
not asked for, not stored
DAY 1
Read-only
connect integrations, see results
EXIT
Any time
disconnect — no repository copy retained

Bring the perimeter question to your security team.

Read-only integrations, transparent data boundaries, and Enterprise self-hosting when your requirements call for it.

Start free trial
30 days · no card · cancel anytime
Private beta · early access

Self-service launches soon

We're prioritising enterprise rollouts right now. Leave your email and we'll let you know the moment self-service is open.

We'll only use this to reach out about DevEval. No newsletter, no sharing with third parties.