Security
What Enact reads, what it never does.
Enact sits upstream of your codebase and your issue tracker. Here's exactly what that means for your data.
We don't train on your data
Enact does not train models on your code, your tickets, or your Slack data. Your data is used only to generate and govern specs for your own workspace — never shared with third parties or used to improve models.
Enact never touches your codebase
Enact operates at the planning layer. It reads repos to understand architecture and map which services a change would touch, and produces specs, acceptance criteria, and architecture notes — it does not write or modify code. What your engineers do with a spec is entirely up to them.
Access is scoped and revocable
Repo, Slack, and project-management access is granted via OAuth to the specific channels, projects, and repos you choose. Disconnecting a repository or integration immediately stops Enact from reading it.
Approval history is an audit trail, not a feature
Every approval, rejection, and scope change is attributed to the person who made it and timestamped. That history is available to your team for as long as your workspace exists.
Need a completed security questionnaire, a signed DPA, or details for a vendor review? Email dushyant@enactapp.io and we'll get you what you need.