Skip to content
Open the dashboard
Security and data

What we store

SecurityWorkspace admins6 min read

This page lists every kind of data Groundrule keeps for a workspace, what each holds, and how long it is kept. All of it is separated by workspace in the database, as How Groundrule protects your code describes. For what is sent to AI, see AI and your data.

  • Your source code. Scans run on your computer or CI runner and upload results, not files. The most code Groundrule keeps is up to 3 one-line snippets of at most 200 characters per rule, with secrets redacted, and none for security rules. --no-snippets turns them off.
  • Whole agent files. A scan uploads each agent file’s path, line count and a hash of its contents, plus the instructions found in it, with secrets redacted.
  • Uploaded files. A document is read into text passages, and the file itself is discarded.
  • Document text after reading. Passages are deleted when reading ends, whatever the outcome.
  • Raw secrets. Passwords are stored only as scrypt hashes; sessions, email links and API tokens only as SHA-256 hashes; connected-app tokens only encrypted.
Data What is in it How long it is kept
Your account Name, email, whether it is verified, the role you described in onboarding, a password hash, and your GitHub identity if you connected it While the account exists
Your workspace Name, URL name, company name, team size, stack, coding agents, code host; members and their roles; invitations While the workspace exists
The rulebook Your own standards with every version and change note; which packs are on; rollout settings per organization, team and repository; teams, owners and repositories While the workspace exists
Scan reports Repository name, branch, commit, file count; stack and tools; agent file paths, line counts and hashes; per rule: outcome, counts, up to 3 examples (file, line, message, optional redacted snippet); who uploaded it, with which token The latest 20 scans per repository; older ones are removed when a new one is uploaded
Imported documents The import’s record: name, title, kind, size, pages, passage count, cost estimate and cost, status, who imported it, and the source link for a connected app The record is kept
Document passages The text, with secrets redacted, and each passage’s location Until reading ends. An import nobody confirms is cancelled after a day; a reading interrupted for 30 minutes is stopped. Either way the passages are deleted
Proposals The proposal’s text (redacted), its kind, category, strength, similar rules, AI’s draft and confidence; sources (repository, file, lines); citations (document, location, and a quote of up to 600 characters); for proposed rules, who proposed it, the reason and example; decisions with who, when and why Kept. A proposal from a scan leaves the open list once no repository contains it anymore
Connected apps The app, the account name, its access and refresh tokens encrypted with AES-256-GCM, status, who connected it, when it was last used Until an admin chooses Disconnect, which deletes the tokens
GitHub installations The GitHub account, whether it covers all or selected repositories, who installed it Until it is disconnected in Groundrule or uninstalled on GitHub
GitHub webhook deliveries The delivery ID, to handle each one once 7 days
API tokens Name, SHA-256 hash, the first 12 characters, permissions, expiry, when it was last used, and whether and by whom it was revoked Kept after expiry or revocation, so the list shows its history; a revoked or expired token never works again
CLI sign-in requests A hash of the device code, the code shown, the computer’s name, and the IP address of the request Removed a day after they expire
Sessions A SHA-256 hash of the session token, your browser’s user agent, when it started and was last used 30 days, or until you sign out. Changing or resetting your password ends your other sessions
Email links A hash of the link’s token, its purpose, and the email Removed 7 days after they expire
Rate-limit counters A key (such as an email or IP address) and a count Removed after a day
Audit log Who did what and when, for administrative actions: workspace and AI settings, packs, standards, rule adoptions and promotions, teams, owners, repositories, members and invitations, API tokens and CLI approvals, connections and GitHub, proposals, and document imports. Details are IDs, names and counts Kept; it can’t be changed or deleted
AI usage ledger Feature, person, time, model, prompt version, token counts, cost, status, attempts, number of redactions, duration. Never what was sent or returned Kept; it can’t be changed or deleted
AI answer cache The model’s answer (such as a drafted standard or the rules found in a document), keyed by a hash of what was sent 30 days. Never with Zero retention; choosing it deletes the cache

You can delete or end some data yourself:

What How
A connected app’s tokens Settings → Connections, the bin icon, Disconnect
A GitHub installation Settings → Connections, the bin icon, and uninstall the app on GitHub
An API token Settings → API tokens, revoke
Your other sessions Change your password in Settings → Your account
An import’s text before reading Cancel import in the estimate dialog
Cached AI answers Choose Zero retention in Settings → AI
Snippets in future scans npx @groundrule/cli scan --upload --no-snippets

Deleting a whole account or workspace from the dashboard isn’t available yet.