costzeraSECURITY
Security

We read metadata. Not your data.

Costzera is built on a simple principle: we analyze your agent’s behaviour without taking custody of your data. We never store your prompts, completions, tool payloads, or source code.

What we access

From your LangSmith traces we persist derived metadata only: durations, token counts, model names, costs, retry and tool-call structure, document counts, and one-way hashes used for duplicate detection. The content of your messages is read in flight during analysis and never written to our database.

What we never store

  • Prompts and completions (message content)
  • Tool-call payloads (inputs and outputs)
  • Your source code (no mirror, no clone at rest)

Data retention

No trace content and no code is retained. What we do store, scoped to your tenant: findings and recommendations (including the handful of code lines cited as evidence, visible to you in your own dashboard), aggregate cost metrics, and sync state. Connection secrets, like your LangSmith key, are encrypted at rest; Costzera API keys are stored only as hashes and shown once at creation.

Code analysis

Code access is read-only and scoped: the Costzera GitHub App fetches files on demand at a specific commit through a short-lived installation token that expires within the hour. Files are analyzed in memory and discarded. We hold no standing credentials to your repositories.

Isolation & transport

Every record is isolated per tenant, resolved server-side from your session or API key; tenant identity is never accepted from client input, and no query crosses tenants. All traffic runs over TLS, with strict security headers on every response.

Subprocessors

We use a small number of established cloud and model providers, all covered by the handling rules above. The current list is shared with customers and prospects under NDA as part of a security review.

Contact

Security questions, our subprocessor list, or a due-diligence review: founders@costzera.com