Security

What we access and where your data goes.

Backlight works from metadata about your engineering work: commits, pull requests, issues, and AI tool usage. We never store source code or diffs.

What we read

Metadata from the systems you connect.

Source control

GitHub, GitLab, Bitbucket, and Azure DevOps

Repository names, commit SHAs and messages, author names and email addresses, timestamps, and lines added, lines deleted, and files changed. For pull requests: titles, states, labels, reviewer names and email addresses, review and comment counts, and open and merge times.

Issue trackers

Jira, Linear, and GitHub Issues

Issue titles, descriptions, types, statuses, priorities, assignees, and created and resolved dates.

AI tool admin APIs

GitHub Copilot and Cursor, with Claude Code and OpenAI in beta

Seat assignments, per-user daily usage counts such as suggestions, acceptances, and interactions, and spend where the vendor reports it. We do not store prompts, completions, or generated code.

Billing

Stripe

The status, invoices, and seat quantity of your Backlight subscription. You enter card details on Stripe Checkout, so card numbers never reach our servers.

What we never store

We never store source code or diffs.

We do not clone repositories. When a provider's API returns changed lines with a commit, we keep only the counts (lines added, lines deleted, and files changed). We do not store AI prompts, completions, or generated code.

Permissions

The access we request, by provider.

GitHub
  • Backlight GitHub App
Read-only access to repository contents, metadata, pull requests, issues, organization members, and Copilot metrics, plus read access to organization administration for Copilot billing. You choose which repositories the app can see.
Bitbucket
  • repository
  • pullrequest
  • webhook
repository and pullrequest are read-only. webhook lets Backlight add a webhook to the repositories you select, so they send us push and pull request events.
GitLab
  • read_api
Read-only API access.
Azure DevOps
  • .default
  • offline_access
Sign-in through Microsoft Entra ID. Backlight calls only read endpoints for your profile, projects, repositories, commits, and pull requests. offline_access keeps the connection active without signing in again.
Jira
  • read:jira-work
  • read:jira-user
  • offline_access
Read access to issues and projects, plus assignee names and email addresses. offline_access keeps the connection active without signing in again.
Linear
  • read
Linear's one read scope covers the whole workspace. Backlight reads issues, descriptions, labels, and assignees, and registers a webhook for issue and comment events on your public teams.
Slack
  • incoming-webhook
Posts alerts and digests to the one channel you pick. This scope cannot read messages.
AI tools
  • Admin API key
GitHub Copilot data comes through the GitHub App. Cursor, Claude Code, and OpenAI connect with an admin API key you create in the vendor's console.
AI processing

What we send to an LLM provider, and when.

Backlight uses an external LLM provider to classify bugs and to estimate whether commits and pull requests were AI-assisted.

On the Free plan, nothing is sent to the LLM provider. Commits and pull requests are classified inside Backlight.

On Team and Enterprise, including trials, it is on by default in Metadata only mode. An organization owner can switch modes under Settings, Data & Privacy, and each change is recorded as an audit event.

Disabled

Nothing is sent to the LLM provider. Commits and pull requests are classified inside Backlight, and bug classification stops.

Metadata only (default)

Bugs: title, priority, and status. Commits: commit time, lines added and deleted, files changed, and an author category (for example, bot or human) computed inside Backlight. Pull requests: open and merge times, review rounds, comment count, lines added and deleted, files changed, and the same author category.

Include descriptions and messages

Everything in Metadata only, plus the bug description (capped at 2 KB), the commit message, and the pull request title.

In every mode, we never send source code, diffs, file contents, or repository names, and we never attach author names or email addresses to what we send.

Before any text leaves Backlight, we redact email addresses, IP addresses, credentials inside URLs, co-author and sign-off lines, Anthropic and AWS API keys, JSON web tokens, and bearer tokens. Bug titles are capped at 512 bytes.

Protection

How we protect your data.

Tenant isolation
Each record of your data belongs to your organization. The app loads data only for organizations the signed-in user is a member of.
Staff access
Support access is off by default. Owners turn it on or off under Settings, Data & Privacy, and Backlight staff can sign in as one of your users only while it is on. Each session requires recent two-factor verification and a written reason, ends after 30 minutes, is recorded as an audit event, and emails that user and your organization's owners.
Encryption in transit
Backlight is served only over HTTPS. Plain HTTP requests are redirected.
Encrypted credentials
OAuth tokens, admin API keys, Slack webhook URLs, and webhook signing secrets are encrypted in our database with Rails Active Record encryption.
Two-factor sign-in
Any user can turn on two-factor sign-in with an authenticator app.
Audit events
Connecting a source control, issue tracker, or Slack integration, changing the AI data-sharing setting, changing support access, and requesting deletion are recorded as audit events. Owners and admins can view the audit log in-app on the Enterprise plan.
Retention and deletion

How long we keep data, and how to delete it.

Commit, pull request, and issue metadata
Kept while your organization exists
Incoming webhook payloads
Deleted after 7 days once processed, 30 days at most
Per-user AI tool usage
Deleted after 18 months (548 days)
Audit events
Deleted after 2 years

An organization owner can export your data, or delete the organization, under Settings, Data & Privacy. Deleting disconnects your integrations and revokes your Backlight API keys right away. Your data is permanently deleted after 30 days, and you can cancel during that window.

Our privacy policy covers backups and your privacy rights.

Sub-processors

Services that process your data for us.

Fly.io
Application hosting and database, in the United States.
Cloudflare
DNS for backlightapp.ai and the redirect from backlightapp.ai to www.
Stripe
Payments and invoicing.
Anthropic
AI classification on Team and Enterprise, unless an owner disables it.
Sentry
Error monitoring.
Google
Google Analytics for website and product analytics, and Gmail for outgoing email.

For security reviews and data processing questions, contact us.