Skip to content

Security at Nuowei

Nuowei accesses your repositories read-only by default and analyses code in ephemeral, isolated environments without storing source code permanently. The platform runs on EU infrastructure with tenant isolation, short-lived credentials and audit logging.

Last updated:

Principles

  • Read-only by default: Nuowei connects to GitHub with read-only access.
  • Ephemeral, isolated analysis: each analysis runs in an isolated environment that is discarded afterwards.
  • No permanent source-code storage: we keep findings and metadata, not your code.
  • EU infrastructure: data is processed and stored in the EU.
  • Tenant isolation: customer data is separated per tenant.
  • Short-lived credentials: access tokens are scoped and expire quickly.
  • Audit logging: security-relevant actions are logged.

Reporting a vulnerability

If you believe you have found a security vulnerability in Nuowei, please email moin@hafencity.dev. Our contact details are also published in security.txt. Please give us reasonable time to fix the issue before public disclosure.

Questions about security? Contact us.

Join the waitlist

We launch in November. Be the first to get access.