Skip to main content
This agreement explains how Codepure (the “Processor”) handles data for you (the “Client” / “Controller”).

1. Data Protection Compliance

This agreement is designed to help you meet privacy and data protection obligations in your region, including frameworks such as the GDPR (EU/EEA) and regional laws across the Middle East and Gulf Cooperation Council (GCC) member states.

2. What Data We Process

  • Purpose: Scanning your software for security vulnerabilities.
  • What we scan: Code metadata and user account details.

3. Security Protections

  • Encryption: Data is encrypted while stored (AES-256) and while moving across the internet (TLS 1.2+).
  • Access Control: We use Multi-Factor Authentication (MFA) and strict role-based access limits.

4. Data Residency

Codepure SaaS is hosted in the United States by default. For customers with specific data-sovereignty obligations, GCC / Middle East data residency is available on request to help satisfy the requirements of government, financial, and enterprise institutions.