Security overview
Your sessions are private to your account, and you choose how much of them Branchmore collects. We make money from paid plans, not from your data. This page covers how we keep your sessions safe, and Data ingestion has every detail of what we collect.
#What Branchmore collects
Branchmore works from the session logs your coding agents already write to disk. bmor runs on your machine when a session starts and ends. It never sits between your agent and its AI provider, so your agent talks to Anthropic, OpenAI, or Cursor exactly as before.
You choose how much we collect. Full Mode, the default, collects your conversations, with the bulky and sensitive parts taken out on your machine first. Stats Mode works mainly as an advanced token tracker and collects none of your conversation text. Full Mode and Stats Mode explains the difference.
Before a transcript leaves your machine, bmor scans it for secrets and replaces each one it finds with [REDACTED]. It uses the rules from the open-source gitleaks scanner, plus its own checks for private keys, access tokens, and passwords in URLs.
You can switch to Stats Mode at any time, or exclude specific projects so we don't collect their transcripts.
#Infrastructure security
Your data is stored on Amazon Web Services (AWS) in us-east-1 (Northern Virginia). It's encrypted on the way there and at rest.
- Uploads are encrypted in transit. They go over HTTPS to our API, never straight to storage.
- Transcripts are encrypted at rest. They're stored in Amazon S3, encrypted with AES-256, with all public access blocked.
- Our database is private. What we parse from transcripts lives in a Postgres database that's encrypted and can't be reached from the internet.
- Servers are closed to SSH. Our servers accept no SSH connections from the internet.
- Secrets stay out of our code. Passwords and API keys live in vaults, never in our source code.
#Access control
- Your sessions are private. No one else can see them unless you choose to share them.
- We may occasionally review your sessions for quality purposes. We keep it to a minimum: when we can't fix a problem without seeing your data, including one you report, or when you've let us include your sessions in a specific product improvement. Only authorized staff can reach production, they sign in with multi-factor authentication, and their network access expires automatically.
- You choose whether we review your sessions. To keep improving Branchmore, we review samples of sessions and usage data, mostly from our own team's use. We ask during onboarding, and yours can be included unless you opt out.
#AI processing
- No one trains AI models on your data. We don't, and neither do the AI providers we use.
- In Full Mode, AI writes your session titles and summaries. An AI inference provider writes them from text that's already been stripped and scanned for secrets.
- In Stats Mode, nothing goes to AI. None of your session data is sent to an AI provider.
AI processing covers how we use AI in detail, including the coding agents we build Branchmore with.
#Retention and deletion
- Your plan sets how long we keep your data. Keeping it is a feature, not a side effect: your history is what lets you compare your trends over months and years. Data retention shows how long we keep each kind of data on each plan.
- You can delete your account at any time. Send us a request, and we'll confirm it from your account's email, then delete your account within 30 days.
- Uninstalling doesn't delete your data. Neither does switching to Stats Mode. To remove what you've already uploaded, ask us to delete your account.
- A few copies take longer to clear. After we delete your account, copies can stay in database backups for up to 7 days, and in server logs, which can include your user ID and email, for up to 1 year. Session excerpts already sent to OpenAI's batch API stay there until we add deletion.
#Privacy and business model
Branchmore is independent and bootstrapped, with no investors. We make money from paid plans, not from your data. We don't sell your information or give it to anyone else to use.
Branchmore is built by its founder, Andrew Shu, and Anes Sprecic, a senior engineer who contracts through Elixirator. Andrew has spent 16 years as an engineer and engineering leader at Permiso Security, Cisco Meraki, and Printivity, and at Permiso, he was one of the primary implementers of its SOC 2 program. More about us.
See Vendors for every outside service that handles your data. For the legal details, see our Privacy Policy and Terms & Conditions.
#Security practices
Here's how we keep Branchmore itself secure:
- Every change is reviewed. Changes to the web app, the API, and
bmorgo through a pull request, reviewed automatically by CodeRabbit and scanned for security issues by Semgrep. - Two-factor authentication is required. Everyone in our GitHub organization must use it.
- New dependency releases wait a week. We hold routine dependency updates for 7 days, so a compromised package release can be caught before it reaches us.
- Production is isolated and monitored. It runs in its own AWS account, managed with Terraform and watched by AWS GuardDuty, AWS Inspector, and a daily Prowler audit.
- You can verify every release. Each
bmorrelease is built in CI and published with SHA-256 checksums, so you can check that your download matches.
Found a vulnerability? Here's how to report it.
#Related
bmor, verify a release, and uninstall it.
FAQ
Quick answers about security, your data, your dashboard, and pricing.