Policy

Security

How Bivouac protects the credentials it needs, the audit trail it produces, and the evidence it exports.

Credentials

Bivouac uses a scoped GitHub App to read advisory feeds and open patch PRs. Repository tokens are stored encrypted at rest and only mounted when the triage loop needs them.

Audit trail

Every signal we triage, every decision we took, every PR we opened and merged, and every test run that gated a merge is captured in the audit trail. The trail is exportable as evidence your team can use in SOC 2, NIS2, and EU Cyber Resilience Act reviews. Bivouac is itself not certified against these frameworks.

Contact

For responsible-disclosure reports, write to bivouac-c3gb0w@polsia.app.