Security
Built to be trusted with your most sensitive systems.
Decimal works with your code, logs, and customer data — so it's built with least-privilege access, encryption, tenant isolation, and rigorous data handling from the ground up.
Designed to meet enterprise security standards
The controls your security team already asks for, built in from day one.
Access controls
SSO, RBAC, and least-privilege permissions—so the right teams see the right data.
Encryption
Encrypted in transit and at rest to protect sensitive data end-to-end.
Retention
Configurable retention policies, including zero-retention modes where required.
Isolation
Tenant isolation with segregated processing to keep customer data separated.
Auditability
Audit logs for access and actions to support governance and reviews.
Private options
Customer-managed storage and private components for sensitive environments.
Compliance & certifications
We hold ourselves to the standards your security team already asks for.
Your questions, answered
Do you store source code?
No. Decimal does not store or copy your source code. It connects to your repositories in read-only mode and generates semantic embeddings used for search and reasoning. Raw source files are never persisted. All code context is processed in memory and discarded after resolution. Embeddings are stored in your organization's isolated data partition and can be deleted on request.
What access is required?
Decimal needs read-only access to your code repositories (GitHub or GitLab), issue tracking and helpdesk tools (Zendesk, Salesforce, Jira), and optionally your logs and config systems.
What does deployment look like?
Most teams are live within one week. You connect your helpdesk and code repository through guided OAuth flows — no infrastructure changes, no agents to install. Decimal begins indexing your codebase and historical tickets immediately. For enterprise customers, we support private VPC deployment, customer-managed encryption keys, and dedicated onboarding with a rollout plan tailored to your team's workflow.
What retention options exist?
You control how long Decimal retains investigation data. By default, ticket resolutions and reasoning traces are retained for the duration of your contract. You can request shorter retention windows, automatic purging schedules, or immediate deletion of specific data at any time. Enterprise customers can configure custom retention policies aligned with their internal compliance requirements.
Is our data used for training models?
No. Your source code, customer data, tickets, and logs are never used to train, fine-tune, or improve any foundation model. We maintain Zero Data Retention (ZDR) agreements with all of our AI providers, meaning your data is not stored, logged, or used for model training by any third party.
Can Decimal take actions or change our systems?
No. Decimal operates in read-only mode by default. It can investigate issues by reading code, logs, configs, and ticket data, but it cannot modify your systems, push code, change configurations, or take any write actions. Decimal delivers answers and evidence — your team decides what to do with them.
Need the details?
Our Trust Center has our full security posture, subprocessors, and documentation.