Trust
Where can users read the security and privacy documentation?
Users can request AppTruth's current security and privacy documentation through signed-in support or by emailing uriel@apptruth.io.
Reviewed by Uriel from AppTruth · Updated · 3 min read
Direct answer to “Where can users read the security and privacy documentation?”
Users can request AppTruth’s current security and privacy documentation through the signed-in support area or by emailing uriel@apptruth.io. Public policy links should be treated as authoritative once they are published on apptruth.io.
Key points: Where can users read the security and privacy documentation?
- Use in-product support for an account-linked request.
- Email uriel@apptruth.io for security, privacy, or vendor-review material.
- Confirm current terms before sharing regulated or highly sensitive source code.
How to request the current documents
Signed-in users can open AppTruth’s support area and create a case describing the documentation they need. Prospective users and vendor-review teams can email uriel@apptruth.io. Include whether the request concerns privacy, security controls, subprocessors, data retention, deletion, AI processing, or procurement so the correct material can be provided.
What to review before connecting a repository
At minimum, organizations should understand repository permissions, categories of stored data, source-artifact retention, AI-provider processing, encryption, access control, incident communication, account deletion, and any contractual restrictions on sensitive data.
- Approve only the GitHub repositories intended for analysis.
- Remove secrets and regulated data from source control.
- Confirm retention and deletion requirements with AppTruth.
- Use the current signed agreement when it differs from general website copy.
Documentation status
This article explains where to request documentation; it is not itself a privacy policy, security certification, or contractual commitment. Until dedicated public policy pages are linked on apptruth.io, the materials supplied directly by AppTruth and any signed customer agreement are the appropriate sources for a formal review.
Which AppTruth document to request for each review
| Review need | Request | Confirm |
|---|---|---|
| Privacy review | Privacy terms and subprocessor information | Data categories, purpose, location, and deletion |
| Security review | Security controls and incident process | Access, encryption, monitoring, and notification |
| Procurement | Order form and applicable agreement | Entity, pricing, liability, and commitments |
| Sensitive-source approval | Repository and AI-processing details | Permissions, retention, and provider handling |
The SAFE Repository Review
A pre-connection documentation check for teams with security, privacy, or procurement requirements.
- Scope: Classify the repository and remove secrets or regulated data from source control.
- Access: Review GitHub permissions and repository selection.
- Flow: Understand storage, AI processing, subprocessors, and data locations.
- Exit: Confirm revocation, retention, deletion, and contractual termination paths.
Trusted sources that inform this guide
These independent sources support the surrounding verification practices. AppTruth-specific product statements are product guidance and should be confirmed against current account or contractual documentation when formal assurance is required.
- NIST Privacy Framework — NIST. Provides a risk-based structure for identifying and managing privacy risk.
- Choosing permissions for a GitHub App — GitHub Docs. Explains how GitHub App permissions should be selected and limited to the access an integration needs.
- Secure Software Development Framework (SSDF) — NIST. Defines outcome-based secure software development practices, including verification and release preparation.
Related questions about “Where can users read the security and privacy documentation?”
Where should a vendor-review team request AppTruth documents?
Email uriel@apptruth.io with the required privacy, security, subprocessor, retention, AI-processing, or procurement topics.
Should regulated source be connected before the review is complete?
No. Teams should first confirm that current documentation and contractual terms satisfy their requirements.