DevLyTicks - GitHub Analytics Platform Logo
DevLyTicks
Features
PricingDocumentation
Sign InGet Started
Start
Back to Documentation
Beginner • 10 min read

Data Security

Learn how DevLyTicks protects your data and repositories with enterprise-grade security measures including encryption, secure infrastructure, and comprehensive backup procedures.

Security Overview

DevLyTicks implements industry-standard security practices to protect your code, analytics data, and team information. Your security is our top priority.

Core Security Principles:

  • • Zero Trust Architecture - Verify every request, never assume trust
  • • Least Privilege Access - Minimal permissions by default
  • • Defense in Depth - Multiple layers of security controls
  • • Encryption Everywhere - Data encrypted at rest and in transit
  • • Regular Audits - Continuous security monitoring and testing
Encryption

All data is encrypted using industry-standard encryption algorithms to ensure maximum security.

Encryption at Rest

All stored data is encrypted using AES-256 encryption, the same standard used by banks and government agencies.

  • • Database encryption: AES-256-GCM
  • • File storage encryption: AES-256
  • • Automated key rotation every 90 days
  • • Keys managed via server-side encryption

Encryption in Transit

All network communication uses TLS 1.3 with perfect forward secrecy.

  • • TLS 1.3 for all connections
  • • HTTPS enforced (HSTS enabled)
  • • Strong cipher suites only
  • • Certificate pinning for API calls
GitHub Token Security

Your GitHub access tokens are handled with extreme care and never exposed or logged.

Token Protection:

  • • Encrypted Storage - Tokens encrypted with unique per-customer keys
  • • Never Logged - Tokens excluded from all logging and monitoring
  • • Read-Only Access - DevLyTicks only requests read permissions
  • • Scoped Access - Minimum GitHub permissions requested
  • • Revocable - You can revoke access anytime from GitHub settings
  • • Token Rotation - Automatic rotation for security
Data Storage

We use enterprise-grade database infrastructure with high availability and security.

PostgreSQL 16

  • ✓ Self-hosted on dedicated European servers
  • ✓ Encrypted connections (TLS)
  • ✓ Automatic daily backups
  • ✓ Point-in-time recovery
  • ✓ Managed via Coolify orchestration

Data Isolation

  • ✓ Logical database separation
  • ✓ Row-level security
  • ✓ Organization-based isolation
  • ✓ Encrypted connections only
  • ✓ IP allowlist support
Infrastructure Security

DevLyTicks runs on dedicated European servers (Hetzner, Germany) with enterprise-grade infrastructure security.

Hetzner VPS & Docker Containers

Application runs in isolated Docker containers on dedicated European servers with Coolify orchestration and automated deployments

Network Security

Firewall rules, rate limiting, and DNS proxy protection enabled

Reverse Proxy & TLS

Let's Encrypt TLS certificates auto-renewed via Coolify with security headers enforced

Backup & Recovery

Comprehensive backup strategy ensures your data is never lost and can be recovered quickly.

Backup Procedures:

  • • Automated Daily Backups - Full database backups every 24 hours
  • • Continuous Backups - Transaction logs backed up every 5 minutes
  • • Point-in-Time Recovery - Restore to any point in last 30 days
  • • Geo-Redundant Storage - Backups replicated across multiple regions
  • • Tested Recovery - Monthly disaster recovery tests
  • • Retention Policy - 30-day retention for daily backups
Security Audits

Regular security assessments and audits ensure our systems remain secure.

Internal Audits

  • • Weekly vulnerability scans
  • • Monthly penetration testing
  • • Continuous dependency audits
  • • Code security reviews

External Audits

  • • Annual SOC 2 audits
  • • Third-party penetration tests
  • • Compliance assessments
  • • Security certifications
Incident Response

Our incident response team is ready to quickly respond to and mitigate security incidents.

24/7 Monitoring

Automated security monitoring with real-time alerts for suspicious activity

Rapid Response

Dedicated incident response team available 24/7 with documented procedures

Transparent Communication

Affected customers notified within 24 hours of any security incident

Data Deletion

You have full control over your data and can request deletion at any time.

Deletion Process:

  1. Request deletion via Organization Settings or contact support
  2. 7-day grace period for accidental deletions
  3. After grace period, all data permanently deleted
  4. Deletion confirmation sent via email
  5. Backups purged within 30 days

Important: Data deletion is permanent and cannot be undone after the 7-day grace period.

Vulnerability Disclosure

If you discover a security vulnerability, please report it responsibly:

  • •Email: [email protected] (PGP key available)
  • •Response Time: Within 24 hours
  • •Acknowledgment: Security researchers credited (if desired)

On This Page

Security OverviewEncryptionGitHub TokensData StorageInfrastructureBackupSecurity Audits

Related Documentation

Privacy PolicyAccess ControlsComplianceOAuth Setup

Need Help?

Contact Support
DevLyTicks Logo
DevLyTicks

Making GitHub analytics beautiful and actionable for development teams worldwide.

GitHubTwitterLinkedInYouTubeDiscord

Product

  • Features
  • Pricing
  • Documentation
  • Dashboard

Docs

  • Quick Start
  • OAuth Setup
  • Contributor Insights
  • Quality Metrics
  • Team Setup

Company

  • About Us
  • Blog
  • Careers
  • Contact

Support

  • Help Center
  • Support
  • Privacy Policy
  • Terms of Service
  • Security
© 2026 DevLyTicks. All rights reserved. Built with ❤️ for developers.