Trust and compliance
Published practices and practical review topics for engineering, security, privacy, and procurement teams.
Updated
Published information
Start with the Trust model for access and evidence boundaries, Privacy notice for information handling, and GDPR and data protection for rights and processing topics.
The methodology explains source coverage, collection state, observed evidence, modeled interpretations, and limitations. Our Acceptable use policy sets expectations for authorized and responsible use.
Access and security review
Start with selected repositories, a defined review period, and named reviewers. GitHub authorization and repository selection define connection scope; workspace membership and report access govern who can view findings.
Customer reviews should confirm the permissions required, how access is granted and revoked, how sensitive information is handled, and which controls apply to the deployment. Bring security and procurement reviewers into that discussion before expanding the scope.
Report suspected security issues to [email protected]. Our security contact record provides the public reporting contact. Reporting a concern does not authorize further testing or access to other people's information.
Hosting, suppliers, and processing terms
The public website uses Cloudflare hosting and optional Microsoft Clarity analytics, as described in Privacy. Customer product data is hosted on AWS in the geographic region where the customer is located.
For a customer deployment, review the actual provider and subprocessor inventory, services used, processing and support locations, access boundaries, and applicable transfer terms. Website providers are not a complete inventory for the product.
Use the hosting and transfer disclosure as a starting point. Confirm the applicable data-processing addendum, supplier authorizations, retention, and deletion arrangements in the customer review.
Independent assurance
Binomial does not currently have a SOC 2 report. The procedures described on this website are not an independent assurance report or a certification.
Using Binomial does not itself establish that an organization satisfies a privacy law, security standard, or industry requirement. Confirm the evidence required for your procurement decision and the commitments in the applicable agreement.
AI and engineering evidence
Binomial does not use data to train artificial intelligence (AI) or machine-learning (ML) models. This includes visitor information and customer data processed by Binomial.
GitHub activity is engineering evidence, not direct AI-tool telemetry. A modeled interpretation does not prove AI caused an outcome or establish authoritative AI spend without appropriate sources.
Named insights remain within authorized customer review. Review the evidence, work context, confidence, and limitations together. Binomial does not reduce a person to a single productivity score, publish cross-customer employee rankings, or make automated personnel decisions.
Discuss your review requirements
Write to [email protected] with the organization, proposed deployment, and the topics you need to review. Useful topics include:
- Selected sources, information categories, and authorized reviewers.
- Applicable customer and data-processing agreements.
- Provider inventory, locations, and transfer safeguards.
- Access controls, incident handling, and security evidence.
- Retention, return, deletion, and support requirements.
Document availability and any customer commitments must be confirmed for the actual environment. Confidential review material may require an agreed handling process. Contact Binomial to start the discussion.