Security and data handling

A practical overview of the report data BugFixes handles and the protections in place.

What we store

BugFixes stores crash reports and the information needed to group repeat crashes, show reports, and deliver configured notifications and tickets. This can include an error message, stack frames, runtime and application context, and timestamps.

We also store account and project settings, agent credentials, integration configuration, and the safe results needed to show report status and any AI analysis you request.

What we remove or avoid storing

Before analysis, incoming reports are sanitized to remove common secrets, request and session identifiers, URLs, network addresses, and other volatile identifiers. Raw and sanitized payload versions are encrypted in the analysis service while retained; retention and deletion settings determine when payloads are removed.

AI prompts, full source files, provider responses, and proposed patches are not stored as analysis results. A bounded suggested change may be retained for you to review. BugFixes does not create branches, commits, or pull requests on your behalf.

Encryption for retained payloads

The analysis service encrypts retained raw and sanitized report payloads with AES-256-GCM. A service master key derives separate encryption keys for each account and project using HKDF-SHA256. Authenticated metadata binds ciphertext to its account, project, payload, and kind, so ciphertext cannot be silently moved between records.

Encryption keys are configured as service secrets and are not stored with the payloads. Other credentials are held by the service that needs them; access is restricted to authenticated internal service paths.

How we use your data

We use customer data to provide BugFixes, maintain its security and reliability, and support you. We do not sell customer data.