Security & data

It tests your app. Here's how we treat it.

Granting a tool access to your repository and your running app is a decision about trust. This page says how that access is handled, and where the detail is still being documented, it says that instead of guessing.

Repository access

SuperGorilla connects as a GitHub App. It reads the contents of the repositories you install it on, cloning each at the exact commit under test, plus the pull request’s details and comments. It writes check runs and the report: a comment, inline review comments and replies on the pull request. The exact permission list is shown on the GitHub consent screen when you install, and we’ll go through each scope with you on request.

Guardrails

Guardrails are rules you set in plain English: pages the agent stays out of, actions it never takes, data it never touches. The agent treats them as absolute: nothing in a pull request, a comment, a memory or a reply can override them, every run in their scope carries them, and they sit on top of the isolation the runs already execute in.

Environment variables

Everything your app needs to run, database URLs, API keys, and the test accounts the agent signs in with, lives as environment variables. Each value is encrypted with AES-256-GCM before it reaches our database, decrypted by our run worker only while it sets up a run’s sandbox, and written to a file that only that sandbox can read. Once saved, a value is never shown again in SuperGorilla’s interface. Use dedicated test accounts rather than real ones, and keep them in an environment of their own.

Isolated environments

Each repository in a project can have as many environments as it needs, each with its own variables, and every trigger names the environment it runs in. Environments never inherit or share variables, and every run gets a fresh sandbox that is destroyed when it ends.

Recordings and screenshots

Video and screenshots exist so you can see what happened; they belong to you. They’re retained for your team’s use, you can delete any run with its video and screenshots from the dashboard, and we purge anything else on request.

What memory retains

SuperGorilla keeps what it learns about running your app (how it starts, working test data, the quirks, what broke before) at the organisation, project, repository, branch and pull-request level. What exactly is stored, for how long, and the controls you have over it are covered during onboarding, where we’ll answer anything about it directly.

Model providers and your data

Testing runs on Anthropic’s Claude models, reached through Vercel’s AI Gateway. The data a run needs (your instructions, the code and change under test, and what the agent sees in your app) is sent to the model provider under its API terms. We choose the models, and the privacy policy lists every processor involved.

Compliance

We won’t claim certifications we don’t hold. If your evaluation needs specific answers (data residency, a questionnaire, a DPA), ask, and you’ll get a direct answer from an engineer.

Reporting a vulnerability

Found something? support@supergorilla.ai reaches the team directly. We read everything and reply.

Send the gorillas in.

Get started

Free to start, no card needed. Your first organisation gets $10 of credits.