Trust
Security
ChangeGraph is built so secrets never leak into models or logs, and correlation stays inspectable.
- 01
Webhook integrity
HMAC verification on GitHub, Sentry, and Vercel webhooks. Reject unknown installations and projects before upsert.
- 02
Idempotent ingestion
Claim delivery IDs so retries never double-apply. Natural keys (tenant + provider ids) keep the graph consistent.
- 03
Secret isolation
Secrets live in env / integration_secrets ciphertext only. Never logged. Never joined into scorer inputs or LLM prompts.
- 04
Sanitized LLM path
Models receive only the evidence package. Output validated: invented PRs/files dropped; absolute causation softened.
- 05
Tenant boundaries
All domain tables carry tenant_id. Queries are scoped. No cross-tenant admin path in MVP.
- 06
Read-only MCP
MVP MCP tools list/get incidents and evidence packages. No arbitrary SQL. Mutations (if ever) need explicit human approval.
Engineering checklist: docs/SECURITY.md. Vulnerability reporting: SECURITY.md. Also see LLM providers.