Security and Data Handling
Effective date: 2026-10-04
This overview is for security, privacy and procurement reviews of ParetoOps. It describes the software as distributed by ParetoOps.
Data handling
- Runs where you run it. ParetoOps runs as a native binary on your developer machines and CI runners, or as a container image in your CI. Evaluation results, prompts, model outputs and code are processed locally and never sent to ParetoOps.
- No telemetry. The software does not collect or transmit usage data, crash reports or analytics.
- Offline licensing. License keys are Ed25519-signed tokens verified against a public key built into the binary. Verification makes no network request. Keys can be bound to your GitHub organizations so that a leaked key does not work elsewhere.
- Network access only when you configure it.
pareto-ops cicalls the GitHub REST API with the token you provide, to create or update one comment on the pull request being checked.- The baseline commands use git against your own remotes and credentials, writing to a dedicated
branch (
pareto-ops/baselinesby default). They never rewrite history or touch your working tree. pricing --sync(Enterprise) downloads a signed pricing catalog from a URL you configure, and rejects it unless its signature verifies.
- Secrets. In GitHub Actions the license key is masked in logs before it is used. The software never prints a license key or token.
Because no customer data reaches ParetoOps, using the software does not make ParetoOps a processor of your personal data. The personal data we do process (interest list, license and billing contacts) is described in our Privacy Policy at https://paretoops.dev/legal/privacy.
Build and distribution
- One compiled engine. The CLI, the Python package and the container image are built from the same Rust code base and ship as compiled, stripped native code. Packages contain no engine source code.
- Reproducible pipeline. Releases are built and published by an automated pipeline from a protected branch, with tests on Linux, macOS and Windows before anything is published.
- Artifact checks. Every release artifact is scanned before publication to confirm it contains no source files, build-machine paths or test-only code paths.
- Official channels only. ParetoOps is distributed through npm (
pareto-ops, with@paretoops/cli-*platform packages), the Python Package Index (pareto-ops) and the GitHub Container Registry (ghcr.io/paretoops/pareto-ops). Packages from any other source are not ours. - Third-party components. Every release includes
THIRD_PARTY_NOTICES.md, listing each open-source component with its license. We monitor dependencies for security advisories and release fixes promptly. - Minimal container. The container image contains the ParetoOps binary, git and CA certificates on a minimal Alpine Linux base.
Supported versions
Security fixes are provided for the current minor release and, for paid subscriptions, the previous minor release for at least 12 months after its successor is released.
Reporting a vulnerability
Email [email protected] with a description, the affected version and steps to reproduce. Please do not open a public issue or disclose the vulnerability before we have released a fix.
- We acknowledge reports within 3 business days and give an initial assessment within 10 business days.
- We keep you informed while we work on a fix, and we credit reporters who want to be credited when we publish the fix.
- We will not pursue legal action against good-faith research that follows this policy, avoids privacy violations and service disruption, and does not access data that isn’t yours.
Contact
Security: [email protected] · General: [email protected]