Data classification

Source Code

Source code is proprietary intellectual property. Vendors with access to source code — CI/CD providers, code hosting platforms, AI coding assistants, and security scanners — carry significant IP and supply chain risk.

Risk profile

Source code access creates supply chain attack vectors (SolarWinds, 3CX), IP theft risk, and potential exposure of secrets embedded in code. Vendors with source code access should have SOC 2 Type II, code isolation architecture, and clear data use policies for AI features.

Applicable frameworks

SOC 2ISO 27001

Example vendors

GitHubGitLabSnykSonarQubeGitHub Copilot

Common questions

Does using GitHub Copilot expose my source code?
GitHub Copilot for Business and Enterprise include data privacy commitments and do not use your code to train the model. Review the data use terms in your agreement and GitHub's published subprocessor list for current commitments.
What supply chain risks apply to CI/CD vendors?
A compromised CI/CD vendor could inject malicious code into your build pipeline, steal secrets from environment variables, or exfiltrate source code. Supply chain attacks through CI/CD are one of the most significant software security vectors. Require SOC 2 Type II and review pipeline isolation architecture.

Which of your vendors handle Source Code?

TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.

Book a demo