1. Definitions
- Customer Data: Release governance metadata, CI evidence (test results, vulnerability scan summaries and reports), and audit logs uploaded to LaneSync by Customer.
- Processor: LaneSync (the SaaS provider).
- Controller: The Customer organization using LaneSync.
2. Processing scope
LaneSync processes Customer Data solely to provide release governance, quality tracking, and SDLC enforcement services as described in the LaneSync Terms of Service. LaneSync does not process Customer application source code.3. Security measures
Processor implements:- Envelope encryption (AES-256-GCM) with per-tenant key context
- Row Level Security for multi-tenant isolation
- TLS 1.3 in transit, KMS encryption at rest
- Least-privilege database access (
sdlc_approle) - Audit logging of sensitive data access