Skip to content

Security

How we handle your code and your account, and how to report a problem

Last updated 18 September 2026. We will post any material change on this page and, where it affects how we handle your data, tell account owners by email before it takes effect.

Monterva reviews other people's source code, so how we handle that code is the first question anyone should ask us. This page answers it, describes how your account is protected, and tells you how to report a problem you have found.

Reporting a security problem

Write to hello@monterva.com with “Security” in the subject line. Tell us what you found, where, and the steps to reproduce it. We read every report and will reply to you.

While you look, please:

  • only use accounts and workspaces that are yours, and stop as soon as you can see data that belongs to someone else;
  • not run anything that degrades the service for other people, such as load or volume testing;
  • give us a reasonable chance to fix the problem before you describe it publicly.

There is no paid bug bounty. The same contact details are published in machine-readable form at /.well-known/security.txt.

Your source code

  • We never run your code or install its dependencies. The review is static: the tools read your files, and lockfiles are parsed rather than installed.
  • Each review runs in a throwaway sandbox with no network access, no credentials in its environment, and hard limits on CPU, memory, time and output.
  • Your source is not kept. The copy is deleted when the review ends, whether it succeeded or failed. We keep findings and short evidence excerpts — never whole files, never an archive.
  • Read-only access. The GitHub App asks for read access to repository contents and metadata, only on the repositories you choose. It cannot push, open pull requests or change settings.

How it works describes each of these in more detail.

AI-written explanations

Findings come from deterministic scanners. A language model writes explanations of findings that already exist; it has no tools, cannot add or remove a finding, and cannot change a severity. Text in a report that was written this way is labelled as such.

Your account and workspace

  • Two-factor authentication is available in your account settings. Once you turn it on, your workspace data cannot be read by a session that has not completed the second step.
  • Workspaces are isolated in the database. Every table that holds repositories, reviews or findings has row-level access rules, and automated tests that try to read another workspace's data run on every change.
  • Shared report links show a summary only — no findings, file paths or evidence. The link itself is not stored, only a hash of it, and every link expires within 90 days and can be revoked at any time.

Payments

Paid plans are not available yet. When they are, payment is taken by Stripe on Stripe's own checkout page, so your card details never reach Monterva. A plan changes only when Stripe tells us it has, in a message whose signature we check before acting on it.

Where your data is

Account and review data is stored in the European Union. The privacy policy lists everyone who processes it.

What we do not claim

Monterva has no security certification and has not been assessed by an independent firm. An automated review finds a defined set of problems; it is not a substitute for a manual assessment by a person, and no review can show that code has no problems at all.

Service status

Current availability is on our status page.