Security and data
What we store
SecurityWorkspace admins6 min read
This page lists every kind of data Groundrule keeps for a workspace, what each holds, and how long it is kept. All of it is separated by workspace in the database, as How Groundrule protects your code describes. For what is sent to AI, see AI and your data.
What is never stored
Section titled “What is never stored”- Your source code. Scans run on your computer or CI runner and upload results, not files. The most code Groundrule keeps is up to 3 one-line snippets of at most 200 characters per rule, with secrets redacted, and none for security rules.
--no-snippetsturns them off. - Whole agent files. A scan uploads each agent file’s path, line count and a hash of its contents, plus the instructions found in it, with secrets redacted.
- Uploaded files. A document is read into text passages, and the file itself is discarded.
- Document text after reading. Passages are deleted when reading ends, whatever the outcome.
- Raw secrets. Passwords are stored only as scrypt hashes; sessions, email links and API tokens only as SHA-256 hashes; connected-app tokens only encrypted.
Everything Groundrule keeps
Section titled “Everything Groundrule keeps”| Data | What is in it | How long it is kept |
|---|---|---|
| Your account | Name, email, whether it is verified, the role you described in onboarding, a password hash, and your GitHub identity if you connected it | While the account exists |
| Your workspace | Name, URL name, company name, team size, stack, coding agents, code host; members and their roles; invitations | While the workspace exists |
| The rulebook | Your own standards with every version and change note; which packs are on; rollout settings per organization, team and repository; teams, owners and repositories | While the workspace exists |
| Scan reports | Repository name, branch, commit, file count; stack and tools; agent file paths, line counts and hashes; per rule: outcome, counts, up to 3 examples (file, line, message, optional redacted snippet); who uploaded it, with which token | The latest 20 scans per repository; older ones are removed when a new one is uploaded |
| Imported documents | The import’s record: name, title, kind, size, pages, passage count, cost estimate and cost, status, who imported it, and the source link for a connected app | The record is kept |
| Document passages | The text, with secrets redacted, and each passage’s location | Until reading ends. An import nobody confirms is cancelled after a day; a reading interrupted for 30 minutes is stopped. Either way the passages are deleted |
| Proposals | The proposal’s text (redacted), its kind, category, strength, similar rules, AI’s draft and confidence; sources (repository, file, lines); citations (document, location, and a quote of up to 600 characters); for proposed rules, who proposed it, the reason and example; decisions with who, when and why | Kept. A proposal from a scan leaves the open list once no repository contains it anymore |
| Connected apps | The app, the account name, its access and refresh tokens encrypted with AES-256-GCM, status, who connected it, when it was last used | Until an admin chooses Disconnect, which deletes the tokens |
| GitHub installations | The GitHub account, whether it covers all or selected repositories, who installed it | Until it is disconnected in Groundrule or uninstalled on GitHub |
| GitHub webhook deliveries | The delivery ID, to handle each one once | 7 days |
| API tokens | Name, SHA-256 hash, the first 12 characters, permissions, expiry, when it was last used, and whether and by whom it was revoked | Kept after expiry or revocation, so the list shows its history; a revoked or expired token never works again |
| CLI sign-in requests | A hash of the device code, the code shown, the computer’s name, and the IP address of the request | Removed a day after they expire |
| Sessions | A SHA-256 hash of the session token, your browser’s user agent, when it started and was last used | 30 days, or until you sign out. Changing or resetting your password ends your other sessions |
| Email links | A hash of the link’s token, its purpose, and the email | Removed 7 days after they expire |
| Rate-limit counters | A key (such as an email or IP address) and a count | Removed after a day |
| Audit log | Who did what and when, for administrative actions: workspace and AI settings, packs, standards, rule adoptions and promotions, teams, owners, repositories, members and invitations, API tokens and CLI approvals, connections and GitHub, proposals, and document imports. Details are IDs, names and counts | Kept; it can’t be changed or deleted |
| AI usage ledger | Feature, person, time, model, prompt version, token counts, cost, status, attempts, number of redactions, duration. Never what was sent or returned | Kept; it can’t be changed or deleted |
| AI answer cache | The model’s answer (such as a drafted standard or the rules found in a document), keyed by a hash of what was sent | 30 days. Never with Zero retention; choosing it deletes the cache |
Deleting data
Section titled “Deleting data”You can delete or end some data yourself:
| What | How |
|---|---|
| A connected app’s tokens | Settings → Connections, the bin icon, Disconnect |
| A GitHub installation | Settings → Connections, the bin icon, and uninstall the app on GitHub |
| An API token | Settings → API tokens, revoke |
| Your other sessions | Change your password in Settings → Your account |
| An import’s text before reading | Cancel import in the estimate dialog |
| Cached AI answers | Choose Zero retention in Settings → AI |
| Snippets in future scans | npx @groundrule/cli scan --upload --no-snippets |
Deleting a whole account or workspace from the dashboard isn’t available yet.