Skip to main content
:::warning This is a template stub for procurement discussions. Have your legal counsel review and customize before signing. :::

1. Definitions

  • Customer Data: Release governance metadata, CI evidence (test results, vulnerability scan summaries and reports), and audit logs uploaded to LaneSync by Customer.
  • Processor: LaneSync (the SaaS provider).
  • Controller: The Customer organization using LaneSync.

2. Processing scope

LaneSync processes Customer Data solely to provide release governance, quality tracking, and SDLC enforcement services as described in the LaneSync Terms of Service. LaneSync does not process Customer application source code.

3. Security measures

Processor implements:
  • Envelope encryption (AES-256-GCM) with per-tenant key context
  • Row Level Security for multi-tenant isolation
  • TLS 1.3 in transit, KMS encryption at rest
  • Least-privilege database access (sdlc_app role)
  • Audit logging of sensitive data access
See Enterprise security for full details.

4. Subprocessors

Processor uses subprocessors listed at Subprocessors. Processor will notify Controller of material changes with 30 days notice.

5. Data retention and deletion

Upon termination, Customer Data is deleted within 30 days unless legal retention requirements apply. Customer may export quality reports via the dashboard before termination.

6. Data subject requests

Processor will assist Controller in responding to data subject requests to the extent Customer Data contains personal data (e.g., GitHub usernames in audit logs).

7. Contact

Data protection inquiries: security@lanesync.dev