Security is part of the workflow.
Pipelix is designed for governed engineering execution. Access, branch boundaries, quality gates, and evidence are defined before work begins.
Least-privilege access
Connections should receive only the repository and Azure DevOps permissions required for the agreed workflow. Customer teams retain control over credentials and can revoke access.
Code and change control
Code remains in customer-controlled repositories. Pipelix works within project and branch rules, producing reviewable changes rather than bypassing engineering controls.
Validation and auditability
Configured builds, tests, scans, logs, changed files, and review outcomes form an evidence trail for each run. Your existing pipelines remain quality gates.
Deployment review
Security requirements vary by organization. We document the proposed data flow, permissions, retention, and approval boundaries during the workflow review before connecting production repositories.
For a security review, contact [email protected].