Skip to content
CodeQuay

Security and compliance

Secure by design, provable in practice

How security works in CodeQuay, what we log and how we protect your data. No vague wording: if something isn't there yet, you won't find it written here.

Example of the CodeQuay audit log: for each event, the time, user, action, target, IP address and outcome, including denied attempts such as a rejected push and a failed sign-in.

Principles

  • The server decides

    Every rule is enforced on the server, on every push and every request. No check depends on the user's machine.

  • No exceptions

    Owners and admins are bound by the same protections. If an exception is needed, it is configured explicitly and stays on record.

  • When in doubt, reject

    If a check cannot be completed, because of an error or missing data, the push is rejected and logged.

Audit log

A log that can only grow

The audit log is append-only at the database level: rows can be added, never changed or deleted, not even with the application's own database user. It also records denied attempts, which are often the most interesting ones.

Who
the authenticated user, or the attempted username for a failed sign-in
What
the action (push, sign-in, changes to roles, protections and policies) and its target
When
date and time with time zone
Where from
the client's IP address
Outcome
allowed, denied or error, with the rule that decided it

For GDPR and NIS2. Traceability of access and changes, evidence of rejected attempts, a log that cannot be altered: these are the first things an auditor asks for. CodeQuay provides them with no extra setup.

Illustration: the audit log only accepts new rows. An attempt to change a row directly in the database is rejected with the error "audit_events is append-only".

Isolation

What isn't yours doesn't exist

People who aren't members of a project can't see its repositories: they don't show up in lists or searches, and the direct URL returns 404, the same error as a repository that doesn't exist. Not even the name leaks.

  • A clear hierarchy: organization, project, repository, with inherited roles and per-user restrictions.
  • The same check applies to the console, the API and the git protocol.
  • Verified by a dedicated automated test suite that tries every combination of role and resource.
Project isolation: a member of the Portal project sees its repositories; the Payroll project, which they don't belong to, doesn't exist for them: it doesn't appear in lists, searches or the API, and the direct URL returns 404.

Backup

An untested backup isn't a backup

A backup is only as good as the last successful restore. That's why we actually test the restore, automatically, every week.

  1. Every night 01

    Full backup

    A database dump, a git bundle of every repository and SHA-256 checksum files to verify their integrity.

  2. Every night 02

    Repository maintenance

    Git repacking and index updates, to keep performance steady over time.

  3. Every week 03

    Automated restore test

    The latest backup is restored to a separate environment: database, migrations, repository clones and a full check with git fsck.

  4. Always 04

    Documented results

    Every test produces a report kept for 90 days. If the restore fails, an alert goes off.

Alerts and system status

If something's wrong, you're the first to know

A watchdog checks the instance every 5 minutes. Admins see everything on one page and get an email when a check fails or a scheduled job doesn't complete.

  • Services and readiness

    Database, API, web and git over SSH up and reachable.

  • Resources

    Disk space and memory kept in check, before they become a problem.

  • TLS certificates

    Days until each certificate expires, with advance warning.

  • Backup and restore

    Result of the latest backup and the latest restore test.

  • Email alerts

    Sent to active admins, with a searchable event history.

Example of the CodeQuay console, system status: all clear, last watchdog check 2 minutes ago; backup succeeded last night, restore test succeeded 2 days ago, certificates valid and service checks passing.

Data and sovereignty

Data in Europe, accountability in Italy

CodeQuay is built in Italy by arimaslab srl. Instances run in data centers in the European Union, and neither the website nor the platform uses third-party tracking services.

  • EU instances

    Repositories, databases and backups stay in data centers in the European Union.

  • Italian company

    Designed and built in Italy by arimaslab srl.

  • Zero trackers

    Not on the website, not in the platform: no third-party analytics or ads.

  • No lock-in

    Standard git format: take your repositories with you using git clone --mirror.

Infrastructure

The defenses you don't see

Technical measures active on every CodeQuay instance.

  • Modern TLS

    TLS 1.2 and 1.3 only, with AEAD ciphers, HSTS and no mixed content.

  • Isolated services

    Unprivileged containers, read-only file systems where possible, and a database that isn't exposed to the internet.

  • Secrets kept out of the code

    Instance passwords and keys live in separate files with restricted permissions, never inside images.

  • Brute-force protection

    Rate limits on the API and on sign-ins, with a temporary lockout after repeated failed attempts.

  • Strong credentials

    Passwords stored with argon2id, tokens stored only as a cryptographic hash, passkeys and 2FA for accounts.

  • No tracking

    No profiling cookies, no third-party analytics, no fonts or scripts loaded from third parties.

Vulnerability management

Found a security issue?

Email us at security@codequay.it. We'll confirm we received it and keep you updated on the analysis and the fix. Good-faith reports are welcome.

  • Describe the issue and the steps to reproduce it.
  • Don't access other people's data or degrade the service.
  • Give us time to fix it before publishing details.

Responsible disclosure

Our contacts are also published in the standard security.txt file.

Email the security team

Security you can see in practice, not in promises.

Create your account and start free. For a dedicated instance or a custom contract, contact us: the people who build CodeQuay will get back to you.