GitHub DevLog AI GitHub DevLog AIPrivate webhook inbox for GitHub
Trust Center

GitHub webhooks carry sensitive context. DevLog AI treats that as a product concern, not a detail.

This page brings together public commitments for security, privacy, operations, and support so developers, teams, and reviewers can understand how the platform protects events, secrets, and payloads.

Principles

The default is private, signed, and auditable.

Workspace isolation

Events belong to the authenticated workspace. One developer cannot view another workspace's payloads.

HMAC signature

GitHub webhooks are validated with X-Hub-Signature-256 before they enter trusted history.

Sanitized payloads

Headers and sensitive fields are cleaned to reduce accidental exposure of tokens and secrets.

Operations

The product is designed to move beyond a demo and become a team routine.

Public status

System health and relevant incidents are available on a dedicated page.

Support

Users have a channel for technical issues, billing, the GitHub App, accounts, and security.

Audit trail

Critical actions such as invites, secrets, billing, and AI analyses enter an operational trail.

Clear limits

Monthly usage, retention, and advanced AI limits are visible in the workspace dashboard.

Data and retention

Less surprise, more control.

Plans can set event, retention, and AI-analysis limits. The goal is predictability: know what arrived, how long it remains available, and when usage requires an upgrade.

Rotatable secrets

The workspace lets you change a secret when there is suspicion, a team change, or a security routine.

Deletion and privacy

Requests for export, correction, or deletion are handled through support and administrative processes.

Governed AI

Local AI is free. Advanced AI uses an external provider, is limited by plan, and records estimated cost.