Coming soon

Enterprise

Proof your auditors can read. Access you approve.

For teams whose changes move money or decide access, and who answer to a security review. Bracel Enterprise adds identity, retention, hosted execution and an access model where nothing happens without your consent.

Support access

We cannot look unless you let us.

Support works without access by default. When access is needed, it is narrow, short, recorded, and yours to end.

  1. 01 · Default

    Nobody at Bracel, including operators, can see your code, pull requests, merges or results.

  2. 02 · First step

    A masked support bundle that you generate and review before you send it.

  3. 03 · If needed

    Time-limited, read-only access to one repository. We propose the duration, you approve it, and the system enforces deletion at the end by destroying the key. The hard maximum is 7 days; an extension needs your approval.

  4. 04 · Every session

    Recorded by the support console itself, not by the operator. You can see who accessed what, when and for how long, including the recording, and revoke access at any time.

Support access · your organizationyou are in control
  1. Accessnone · defaultclosed
  2. Support bundlemasked · reviewed by you before sendingsent by you
  3. Read-only key · one repositoryduration proposed by us · approved by youapproved
  4. Session recordedby the support console · visible to you · revocablerecorded
  5. Key destroyedend of the approved window · access ends with itdeleted
Illustrative · Enterprise support access is planned

What Enterprise adds

Built for the security review.

Everything in Business, plus the controls a regulated organization asks for first.

  • Identity

    Single sign-on and provisioning

    SAML or OIDC single sign-on, separate from GitHub login, and SCIM provisioning for joiners and leavers.

  • Evidence

    An audit trail auditors can use

    The approval trail and the evidence behind every verdict, retained by contract and exportable through an API.

  • Execution

    Hosted, independently controlled runs

    Verification on Bracel infrastructure with its own trust class, bracel-hosted. Code is processed only while a run executes and is deleted by default.

  • Keys

    Per-customer encryption keys

    Every customer has its own keys and access logs. On Enterprise you can hold the encryption key yourself.

  • Projects

    Kept projects stay locked

    A hosted project you choose to keep is frozen, and unlocked only with an authenticator app.

  • Terms

    Contracts that fit your review

    Negotiated data processing terms, service levels and enterprise agreements, alongside the standard terms of every paid plan.

Coming soon

Transparency report

Every quarter, the numbers.

From version 1.1 we publish a quarterly report on support access, so you do not have to take our word for it.

Support accesses
all customer-approved
Accesses without approval
target 0
Session recordings shared
count
Automatic deletions
count

Two trust classes

Know where every verdict came from.

customer-ci

Ran in your own runner. Bracel did not observe it. Protects against accidental regressions; protect your workflows with code owners.

bracel-hosted

Ran on Bracel infrastructure under independently controlled conditions. Every evidence record states which of the two produced it. One engine, one rule format, one evidence format.