by Winch Labs

Security

Built to be trusted
with the keys it never holds.

Never applies — structurally

No code path in Deltz runs terraform apply or performs any write against your cloud, and Deltz never stores or touches your Terraform state files — it reads source, not state. This is not a policy or a permission setting: it's an invariant enforced in our own CI, and a build fails if a cloud-write call is introduced. Everything Deltz produces is a commit or a pull request that a human reviews and merges. Deltz holds no cloud credentials because it has no use for them.

What we read, what we store

Deltz reads the infrastructure code in repositories you explicitly connect, via a GitHub App with least-privilege scopes (GitLab support is code-complete behind the same provider seam, not yet run against a live GitLab project). From it we derive and store facts: parsed resources, conventions with file-and-line evidence, findings, and review history. We do not resell, train on, or share your code or derived data. Disconnecting a repository stops all processing; you can request full deletion at any time.

Your AI key, your data path

On the free Starter plan, AI features (Fix with Deltz, Forge) run on your own Claude API key — model traffic goes through your Anthropic account, billed to you at cost. Individual and Team include Claude usage on our keys — no setup, one bill. Enterprise is your choice: your keys or ours. The deterministic review gate — parsing, conventions, findings, cost deltas, merge checks — uses no AI at all and works with no key configured, on every plan.

Findings carry control tags — receipts carry proof

Gate findings are tagged, conservatively, with CIS AWS Foundations Benchmark v5.0.0 and SOC 2 control mappings in SARIF and JSON output — a rule with no defensible mapping ships untagged rather than stretched. That's evidence toward a control an auditor already cares about; it is not a certification, and we don't describe it as one.

Every review and merge also writes a hash-chained receipt — what was checked, what was found, who approved — verifiable inside the product and exportable as an evidence bundle for any period you choose. Where an operator configures a signing key, receipts are ed25519-signed and the public key is served at a well-known URL, so verifying one never has to take Deltz's word for it. Where none is configured they are written unsigned, and the product reports them as consistent rather than verified — the two are different claims and it never collapses them.

Tenancy, identity, single sign-on

Every row of data is scoped to your organization — tenant isolation is enforced at the database layer, not the UI. Role-based access control decides who can curate conventions, trigger fixes and manage members, with an audit log of administrative actions, CSV-exportable over any time range for access reviews; self-hosted installs can additionally opt into a retention window, and a sweep records what it removed in the org's own audit trail.

Team and Enterprise organizations connect their own OIDC identity provider, per organization: domains are verified with a DNS TXT ownership proof before anyone on them is routed to that provider, sign-in is email-first so each person lands on the right workspace automatically, an enforce-SSO switch ships with an owner break-glass path, and client secrets are sealed with envelope encryption rather than stored in the clear. Full detail on the pricing page.

API access, scoped and rate-limited

API tokens are read-only and rate-limited by design — a leaked CI token can read your review data, never mutate it, trigger a fix, or change a setting.

Run it yourself

Deltz is a single Go binary plus Postgres, built to self-host from day one, packaged as a Helm chart with every credential passed by reference rather than as a plain value. If your compliance posture requires that code never leaves your network, an Enterprise self-hosted or single-tenant install gives you the entire system inside your own boundary — with no phone-home: a self-hosted instance does not call back to Winch Labs to operate.

Certifications — honestly

Winch Labs does not currently hold SOC 2, ISO 27001, or any other formal certification as a company. We say so plainly rather than imply otherwise. The CIS and SOC 2 control tags above describe what individual findings map to, evidence you can hand an auditor — they are a different claim, and neither is a substitute for your own audit of us.

Questions or disclosures

Security questions, questionnaires, or vulnerability reports: hello@winchlabs.io. We respond to good-faith vulnerability reports and will never take legal action against good-faith research.

See the gate on your own repo

The deterministic review gate runs free on a real repository — no cloud credentials, no state files, ever. Or have us walk you through it live.