Security and compliance
Secure by design, provable in practice
How security works in CodeQuay, what we log and how we protect your data. No vague wording: if something isn't there yet, you won't find it written here.
Principles
-
The server decides
Every rule is enforced on the server, on every push and every request. No check depends on the user's machine.
-
No exceptions
Owners and admins are bound by the same protections. If an exception is needed, it is configured explicitly and stays on record.
-
When in doubt, reject
If a check cannot be completed, because of an error or missing data, the push is rejected and logged.
Audit log
A log that can only grow
The audit log is append-only at the database level: rows can be added, never changed or deleted, not even with the application's own database user. It also records denied attempts, which are often the most interesting ones.
- Who
- the authenticated user, or the attempted username for a failed sign-in
- What
- the action (push, sign-in, changes to roles, protections and policies) and its target
- When
- date and time with time zone
- Where from
- the client's IP address
- Outcome
- allowed, denied or error, with the rule that decided it
For GDPR and NIS2. Traceability of access and changes, evidence of rejected attempts, a log that cannot be altered: these are the first things an auditor asks for. CodeQuay provides them with no extra setup.
Isolation
What isn't yours doesn't exist
People who aren't members of a project can't see its repositories: they don't show up in lists or searches, and the direct URL returns 404, the same error as a repository that doesn't exist. Not even the name leaks.
- A clear hierarchy: organization, project, repository, with inherited roles and per-user restrictions.
- The same check applies to the console, the API and the git protocol.
- Verified by a dedicated automated test suite that tries every combination of role and resource.
Backup
An untested backup isn't a backup
A backup is only as good as the last successful restore. That's why we actually test the restore, automatically, every week.
- Every night 01
Full backup
A database dump, a git bundle of every repository and SHA-256 checksum files to verify their integrity.
- Every night 02
Repository maintenance
Git repacking and index updates, to keep performance steady over time.
- Every week 03
Automated restore test
The latest backup is restored to a separate environment: database, migrations, repository clones and a full check with git fsck.
- Always 04
Documented results
Every test produces a report kept for 90 days. If the restore fails, an alert goes off.
Alerts and system status
If something's wrong, you're the first to know
A watchdog checks the instance every 5 minutes. Admins see everything on one page and get an email when a check fails or a scheduled job doesn't complete.
-
Services and readiness
Database, API, web and git over SSH up and reachable.
-
Resources
Disk space and memory kept in check, before they become a problem.
-
TLS certificates
Days until each certificate expires, with advance warning.
-
Backup and restore
Result of the latest backup and the latest restore test.
-
Email alerts
Sent to active admins, with a searchable event history.
Data and sovereignty
Data in Europe, accountability in Italy
CodeQuay is built in Italy by arimaslab srl. Instances run in data centers in the European Union, and neither the website nor the platform uses third-party tracking services.
-
EU instances
Repositories, databases and backups stay in data centers in the European Union.
-
Italian company
Designed and built in Italy by arimaslab srl.
-
Zero trackers
Not on the website, not in the platform: no third-party analytics or ads.
-
No lock-in
Standard git format: take your repositories with you using git clone --mirror.
Infrastructure
The defenses you don't see
Technical measures active on every CodeQuay instance.
-
Modern TLS
TLS 1.2 and 1.3 only, with AEAD ciphers, HSTS and no mixed content.
-
Isolated services
Unprivileged containers, read-only file systems where possible, and a database that isn't exposed to the internet.
-
Secrets kept out of the code
Instance passwords and keys live in separate files with restricted permissions, never inside images.
-
Brute-force protection
Rate limits on the API and on sign-ins, with a temporary lockout after repeated failed attempts.
-
Strong credentials
Passwords stored with argon2id, tokens stored only as a cryptographic hash, passkeys and 2FA for accounts.
-
No tracking
No profiling cookies, no third-party analytics, no fonts or scripts loaded from third parties.
Vulnerability management
Found a security issue?
Email us at security@codequay.it. We'll confirm we received it and keep you updated on the analysis and the fix. Good-faith reports are welcome.
- Describe the issue and the steps to reproduce it.
- Don't access other people's data or degrade the service.
- Give us time to fix it before publishing details.
Responsible disclosure
Our contacts are also published in the standard security.txt file.
Email the security teamWhy CodeQuay
More of what sets CodeQuay apart
Security you can see in practice, not in promises.
Create your account and start free. For a dedicated instance or a custom contract, contact us: the people who build CodeQuay will get back to you.