# Security - Practical Controls for Agent Workflows

URL: https://www.changebot.ai/product/security/
Description: Changebot is built with security in mind. Read-only access, scoped permissions, encryption, audit logging, and human review for customer-facing updates.

Security

# Security Controls  
Without the Ceremony

We are keeping the security work: read-only access, scoped permissions, encryption, audit logs, and review gates. Our posture is based on the controls we operate, not just a badge.

In short

Changebot reads source repositories read-only, with scoped permissions, encryption in transit and at rest, audit logging, and a human review gate before any customer-facing update publishes. Changebot supports security vendor reviews on every plan, including the free one, and SAML/OIDC single sign-on is coming.

[Get Started for Free](https://app.changebot.ai/signup)

## Security Posture

Controls

### Security Work Continues

We keep operating with practical controls: least-privilege access, encryption, audit trails, access review, and human approval before publishing.

Google

### Google Sign-In

Teams sign in with Google to create a workspace. No separate password to manage, and only basic profile information is requested.

SSO

### SAML / OIDC SSO

Coming Soon

SAML 2.0 and OIDC so your team logs in through Okta, Azure AD, or another identity provider. This is not on the free plan today.

## Minimal Permissions

We only ask for read access to what we need. We never write to your repos.

### Read-Only Access

We never write to your repos. We read commits, PRs, and issues—that's it.

### Scoped Permissions

Only the repositories you explicitly authorize. No organization-wide access required.

### Easy Revocation

Pull the plug any time through your provider's settings. Takes effect immediately.

### Audit Logging

Full audit trail of everything we access. You can see exactly what we read and when.

## Infrastructure Security

### Encrypted at Rest

All data encrypted using AES-256 encryption at rest.

### Encrypted in Transit

TLS 1.3 for all data in transit. No exceptions.

### Cloud Infrastructure

Runs on established cloud infrastructure with availability monitoring and operational safeguards.

### Regular Backups

Automated backups with point-in-time recovery. Your data is safe.

### DDoS Protection

Edge-level DDoS mitigation keeps things running when others go down.

### Penetration Testing

Regular third-party penetration testing and vulnerability assessments.

## Security FAQ

What access does Changebot need to my code?

Read-only, scoped access to the repositories you explicitly connect. Changebot reads commits, pull requests, and release metadata to draft updates. It never writes to your repositories, and connecting a repository is optional because free publishing requires no code access at all.

Can I control what Changebot reads, and revoke access?

Yes. Permissions are scoped to the repositories you connect, with branch selection and commit skip patterns to narrow it further, and a full audit trail of what was read and when. Access can be revoked at any time through your provider's settings and takes effect immediately.

Can Changebot publish something without a human approving it?

Updates enter a draft and review workflow by default, and a person approves before anything reaches customers. Automated recaps are generated on a schedule, but the publish step remains under your control.

How is data protected?

AES-256 encryption at rest, TLS 1.3 in transit, automated backups with point-in-time recovery, edge-level DDoS mitigation, and regular third-party penetration testing. Teams sign in with Google today, and SAML 2.0 and OIDC SSO are coming.

## Questions About Security?

Get started for free and we'll share docs, or email us if you need a security review.

[Get Started for Free](https://app.changebot.ai/signup)
