Security boundary
Your implementation environment stays yours.
ADapptive is designed to carry feedback signal and deployment metadata without receiving customer source code.
Data that crosses the boundary
- Zone configuration, feedback, votes, tester identity, and reward records.
- Implementation metadata such as status, branch, commit, PR, test result, and log text.
- Optional screenshots uploaded through authenticated, private storage.
Data that stays with the customer
Customer source code, local files, repository credentials, and AI provider keys remain in the customer environment. The customer-side MCP server uses the customer's secret key to exchange feedback metadata with the API; ADapptive does not execute that agent or inspect its workspace.
Account and access controls
- Dashboard and tester access use Authentik OIDC sessions.
- Publishable and secret API keys have separate capabilities.
- Tester pool permissions and vote weights are enforced server-side.
- Platform administration is restricted by a server-only email allowlist.
Report a concern
Report a security issue through the private beta operator or the contact path on this site. Please do not include customer secrets or source code in a report.