security & data access
Telemetry access is read-only. Perfloop can read metadata, metric series, log aggregates, and sampled profiles within the scope you connect. Loki queries can also return log text within set time and size limits. Axiom and Datadog raw event rows stay with the provider. On code, writes are limited to approved branches and pull requests. Perfloop cannot merge, approve, or deploy a change.
connection reads and writes are bounded by your grants and visible in provider audit logs where supported
You choose the repositories and exact telemetry resources. Each connection guide explains the permissions it needs and the data it can read.
| category | what crosses the boundary | what perfloop keeps | retention |
|---|---|---|---|
| telemetry · metrics & logsread-only | schema metadata, labeled metric series, time-bounded log aggregates, and bounded Loki log entries, including authorized labels and grouping values | connection scope, query definitions, captured results, and derived model or proof evidence | while the customer account is active |
| telemetry · profilesread-only | sampled stacks, values, labels, function and file names, build identifiers, and profile files; Google reads Cloud Profiler profiles across the selected project before target and time selection | capture receipts, stack previews, and selected profiles that model tools can inspect as proof artifacts | while the customer account is active |
| source coderead + pr write | code in repos you connect; writes are approved branches and their pull-request surfaces, never a merge or deployment | repository metadata, code-derived model, session transcripts, tool records, proposed changes, and proof artifacts | while the customer account is active; rebuildable caches 7 days |
current retention · active product records remain while the customer account is active · an authorized account deletion stops access and removes live data after a selected 1-to-30-day recovery period · database recovery copies expire after 7 to 30 days · object recovery copies expire after 30 days
not requested as separate inputs
What you connect and where Perfloop runs are separate, independent choices. Each connection is its own grant and can be revoked at its provider. Revocation stops new provider reads; product-data deletion is separate. Nothing is connected by default.
Read access plus bounded writes on repositories you select: approved branches; PR creation and title or body updates; comments, comment-only reviews, replies, and review requests. Perfloop cannot merge, approve, request changes, or change draft state.
benchmarks run in perfloop's sandbox · every write is bound to the approved branch or pull request
Read access to resources you name or select: schema metadata, labeled metric series, log aggregates, and sampled profiles. A setup picker can show resource metadata. Google access covers Cloud Profiler profiles across the selected project.
read-only provider grant + customer-selected resource scope are the confidentiality boundary · aggregate validation is defense in depth
One workspace per customer on shared infrastructure.
the default · product data is stored in our gcp deployment · selected model context goes to the providers below
Product storage can run in a project you provision. Approved inference providers still receive selected model context.
not generally available · requires a current-release acceptance review and separate agreement
the soc 2 type ii report is not issued · the current observation status is below
Use credentials with read-only access to the resources you want to connect. Perfloop checks that it can read those resources, but cannot inspect every permission the credential holds. Remove broader roles before you connect. The data Perfloop receives can include labels, grouping values, and profile metadata.
Provider permissions control which data a credential can access. Google Cloud Profiler, for example, returns profiles for the whole project before Perfloop filters them by workload and time. Use a separate project to restrict which profiles it can receive. Each guide explains the permissions and data for that source.
The agent runs your code and reads your telemetry, so the architecture treats it as compromised and contains it.
the agent is treated as compromised
Containing the agent is half of it. The platform that holds your derived data is itself least-privilege.
least privilege by default
Answered up front, against ground truth.
Yes. Connected source code, prompts, and tool results can enter model context. Case, triage, and model-build sessions currently use OpenAI. Controller and operator tasks use Google Vertex AI. OpenAI Responses requests set store=false; this is not a zero-data-retention claim, and OpenAI's applicable abuse-monitoring retention can still apply. Commonplane does not use customer content to train models. Schema metadata, metric series and labels, log aggregates, and profile previews can enter model context. Models can also use standard tools to inspect the full retained profile files. Tool output can include function and file names, build identifiers, labels, and sampled values. Bounded Loki reads can return authorized log entries and log text. Axiom and Datadog do not provide raw log or event rows.
Assume it happens; the architecture does. The session holds no upstream provider credentials and has one network path: the proxy, where destination allowlists, per-session permissions, and credential injection are enforced outside the model. A hijacked agent gains no provider credentials, no new destinations, and no way to merge anything, and every request it makes passes through the proxy's route checks.
Google Cloud hosts the product and provides Vertex AI inference for controller and operator tasks. OpenAI provides inference for case, triage, and model-build sessions. WorkOS authenticates users and stores account data such as name, email, and IP address. Axiom holds operational logs, traces, and metrics. A tenant setting that is off by default can enable diagnostic capture of customer or source-derived agent content, which Perfloop classifies as Customer Confidential. When you connect a telemetry account, Perfloop queries that customer-authorized service under the grant and resource scope you provide.
Authorized Commonplane personnel can access customer data when needed to operate, secure, diagnose, or support the Service. Access uses authenticated product and operator paths. Provider grants remain bounded by the scope you gave Perfloop. Revoking a provider grant stops new reads but does not delete records already stored in the Service.
Remove repositories from the GitHub App or uninstall it to stop GitHub access. GitHub enforces the changed repository grant on installation tokens. Revoke the telemetry grant at its provider to stop new telemetry reads. These actions do not delete product records or artifacts already stored by Perfloop; an authorized tenant deletion removes those under the retention process above.
You name or select each resource before connection. The Grafana setup picker can list datasource metadata visible to your grant. Perfloop then reads schema, metrics, log aggregates, or profiles within the selected scope. Google lists Cloud Profiler profiles across the selected project before local filtering; it has no permission for other Google resource types. Perfloop does not add resources on its own.
This page documents what Perfloop accesses and how that access is controlled, in claims you can verify today. Formal attestations are in progress; their status is below.
full specification + security questions: security@perfloop.ai →