Security

Your code stays
where you decide.

GitMir runs in three deployment modes, and they differ in exactly one thing that matters: which boundary your source code crosses, and which it does not. This page states that plainly, mode by mode, without adjectives.

Data boundary

What crosses which boundary.

WhatCloudPrivate SourceEnterprise
Repository source codeRead by GitMir LabStays in your environmentStays in your environment
Processing of that sourceGitMir LabGitMir Local Connector, inside your infrastructureYour private GitMir deployment
Derived intelligenceHosted by GitMir LabSynchronized to GitMir LabStays inside your boundary
MCP endpointGitMir LabGitMir LabPrivate MCP, inside your boundary
Questions your team asksAnswered by GitMir LabAnswered by GitMir LabAnswered inside your boundary
We do not claim that nothing leaves your environment

In Private Source your source code stays with you, but derived intelligence is synchronized to GitMir Lab so that your team and agents can query it. That is a real transfer and we name it, because a security page that overstates its guarantee is worth less than one that states a smaller guarantee accurately. If nothing at all may leave, the mode you want is Enterprise.

The three modes

Pick the boundary first.
Everything else follows from it.

Cloud

Fastest start

You authorize a repository and GitMir Lab reads it directly. Suitable when the code is already hosted with a third party you trust and the speed of getting started matters more than isolation.

Private Source

Source code stays in your environment

The GitMir Local Connector runs inside your infrastructure and processes only the sources you permit. Your code is never transmitted; the intelligence derived from it is synchronized to GitMir Lab.

Enterprise

Everything inside your boundary

A private GitMir deployment with a private MCP endpoint, in your VPC, on-premises or in an isolated environment. Nothing traverses a GitMir-operated service.

IF YOUR POLICY NAMES A BOUNDARY, START THE CONVERSATION THERE — THE MODE IS A PROCUREMENT DECISION, NOT A PRICING TIER.

Commitments

What we do not do
with what you connect.

We do not train on your code or your intelligence

Nothing you connect is used to train models, and nothing derived from it is used to improve the service for anyone else.

We do not sell or share it

Your sources and the intelligence derived from them are not sold, licensed or shared with third parties.

An Enterprise deployment is yours

It runs inside your boundary and it is owned by you.

Single sign-on and role-based access

SSO and RBAC are available on Enterprise deployments.

THESE ARE CONTRACTUAL COMMITMENTS, NOT MARKETING LINES — THEY BELONG IN YOUR AGREEMENT, AND WE WILL PUT THEM THERE.

Security pack

The operational detail,
in a reviewed document.

Hosting, encryption, retention, sub-processors and continuity are the questions your security team will ask in writing, and they deserve an answer in writing — reviewed, dated and specific to the mode you are deploying. We send that rather than paraphrase it on a marketing page.

Hosting and regions

Where the service runs and where data is stored.

Encryption

In transit and at rest, with the specifics rather than the adjective.

Retention and deletion

What is kept, for how long, and what disconnecting a repository removes.

Sub-processors

The current list, and how changes to it are notified.

Access control

Who inside GitMir can reach customer data, under what approval, and how it is logged.

Business continuity

Backups, recovery objectives and incident response.

Certifications

What we hold,
and what we do not.

Status pending publication

We will not list a certification we do not hold, and we will not leave the question unanswered either. Ask us directly and you will get the current status in writing, including what is in progress and what is not planned. It is published here as soon as there is something true to publish.

Report an issue

Found something?
Tell us before you tell anyone else.

Write to [email protected] with the details and how to reproduce it. We will acknowledge, keep you updated while it is being fixed, and credit you if you want to be credited. Please give us a reasonable window to fix an issue before disclosing it publicly.

ENTITY GITMIR LTDCO. REG. NO. 15860347JURISDICTION ENGLAND AND WALES

Start where your policy allows.

Cloud to try it today, Private Source if the code cannot leave, Enterprise if nothing may.