What Convalesce reads, sends and changes.
Convalesce works on your pipelines, so this page says plainly what it touches. Where an answer rests on the legal pages, it links to the part it comes from.
What Convalesce reads
The shape of your data, all the time: schemas, types, row counts and lineage.
While it investigates a failure it may also run small read-only queries to confirm a cause. Those are capped, personal columns are masked, and the rows are never stored.
From the DPA, section 6.1.
What leaves your environment
Only the incident bundle for the failed run, and only what the investigation needs. It is not a copy of your warehouse.
Before that context goes to the AI model, Convalesce masks personal information inside its own cloud environment. Automated masking cannot be guaranteed to catch every item, so it reduces that exposure and does not remove it.
Convalesce does not use customer personal data to train general AI models, and does not instruct its AI provider to.
From the DPA, section 6.2 and DPA, section 6.3.
What it can change
Nothing on its own. The most it does is open a pull request against your repository, with the evidence attached. You review it and you merge it.
The access you choose
Reading is set per connection, and you can switch it off for any of them.
Access to your code is a separate step: you install the GitHub app on the repositories you pick.
You can revoke a connected integration. Once it is revoked, Convalesce stops making new requests with it.
From the DPA, schedule 2.
The measures in place
- Encryption
- Information is encrypted in transit.
- Sign-in
- Multi-factor authentication for internal and administrative access.
- Access
- Role-based access controls, least-privilege service accounts, and restrictions on staff access to customer data.
- Secrets
- Integration credentials and secrets are kept in Google Secret Manager.
- Environments
- Development and production are kept separate.
- Logging
- Audit logging for the operation and security of the service.
- Hosting
- Google Cloud, region us-central1 (Iowa, United States).
- Deletion
- Customer data is deleted within 60 days of a valid deletion request or the end of an account, with the limited exceptions the DPA sets out.
- Incidents
- You are told without undue delay once a security incident affecting your personal data is confirmed.
From the DPA, schedule 2, with section 11 and section 15.