Security

Effective 2026-08-24 ยท v1

Gondolier asks for a forge personal access token or OAuth token to operate your merge queue. Here's specifically how we protect it and the rest of your tenant data.

Credential protection

This is strong encryption at rest with key rotation, not KMS-backed envelope encryption with a per-tenant data key. Moving the wrapping key to a managed KMS is a planned step before we represent this as such; see our public documentation for the current, precise description if that distinction matters for your evaluation.

Data isolation

Request integrity

Reporting a vulnerability

If you find a security issue, email gondolier@laputacloudco.com with what you found and how to reproduce it. We don't yet have a formal disclosure program or bounty, but we'll respond and work the issue with you.