Prepared for: Chief Information Security Officer
Assessment Date: March 19, 2026
Classification: Internal β Restricted Distribution
Scope: Ampcode AI Coding Agent Β· Sourcegraph Code Search Platform
Ampcode is an AI-powered coding agent built by Sourcegraph, Inc. β a company trusted by Reddit, Uber, Dropbox, Databricks, and other Fortune-500 engineering organizations. This assessment evaluates Ampcode and Sourcegraph's security posture against enterprise requirements.
SOC 2 Type II Β· ISO/IEC 27001:2022 Β· GDPR Β· CCPA Β· EU AI Act compliant. Annual third-party penetration testing across full stack.
Enterprise plan provides zero data retention on all LLM providers. AES-256 encryption at rest. TLS 1.2+ in transit. No model training on customer data.
Hosted on Google Cloud Platform (US). Terraform-managed infrastructure. Segregated customer environments. All US-based service providers β no China-based infrastructure.
Enterprise SSO via Okta/SAML/OIDC. Directory Sync (SCIM) for auto-provisioning. Audit logging. Role-based workspace controls.
Sourcegraph maintains a comprehensive compliance program verified by independent auditors. All certifications and reports are available through the Security Trust Portal and Amp Trust Portal.
Ampcode operates as a two-component system. The client runs locally; the server is a multi-tenant cloud service. The client never clones, indexes, or stores the entire codebase β only relevant snippets are sent as LLM context.
.env and credential filesampcode.com domainsEnterprise-grade data protection with zero LLM retention, volume-level encryption, and granular thread lifecycle management.
Sourcegraph's infrastructure is hosted entirely on Google Cloud Platform, managed via Terraform, with defense-in-depth security controls.
Ampcode Enterprise provides full enterprise-grade identity management including SSO, SCIM directory sync, and comprehensive audit logging.
ampcode.com,
auth.ampcode.com,
authapi.ampcode.com.
See Client Security documentation.
Ampcode includes built-in automatic secret detection and redaction at the lowest level of the system, preventing secrets from reaching LLMs, storage, or external services.
Detected secrets are replaced with markers like:
[REDACTED:amp]
Redaction occurs before data leaves the client β secrets never reach the LLM, local cache, or server.
.env filesComplete mapping of all third-party providers, their locations, and what data they can access. All providers are US-based. No China-based infrastructure.
| Provider | Location | Data Exposure | Purpose | Risk Level |
|---|---|---|---|---|
| Google Cloud Platform | πΊπΈ USA | Partial Code | Primary infrastructure, PostgreSQL, storage | Low |
| Anthropic (Claude) | πΊπΈ USA | Partial Code | Primary LLM inference | Low |
| OpenAI | πΊπΈ USA | Partial Code | LLM inference (select models) | Low |
| Google Vertex AI | πΊπΈ USA | Partial Code | Gemini / Claude inference | Low |
| Amazon Bedrock | πΊπΈ USA | Partial Code | Claude inference | Low |
| xAI | πΊπΈ USA | Partial Code | LLM inference | Low |
| Fireworks | πΊπΈ USA | Partial Code | Proprietary Amp model features | Low |
| Baseten | πΊπΈ USA | Partial Code | Proprietary Amp model features | Low |
| Cloudflare | πΊπΈ USA | Metadata Only | WAF, DNS, Rate Limiting | Low |
| WorkOS | πΊπΈ USA | No Code | Authentication, SSO, User management | Low |
| Parallel | πΊπΈ USA | No Code | Web search / page retrieval | Low |
| Stripe | πΊπΈ USA | No Code | Billing & payments | Low |
| Sparkpost / Bird | πΊπΈ USA | No Code | Email delivery (10-day header retention) | Low |
| Sentry | πΊπΈ USA | Error Data | Error monitoring / debugging | Low |
Residual risk assessment after considering Ampcode's security controls. All identified risks are within acceptable enterprise thresholds.
AES-256 encryption, GCP-managed keys, segregated environments. Thread data deleted within 30 days of deletion request.
TLS 1.2+ enforced on all connections. Cloudflare WAF provides additional protection. No plaintext transmissions.
Enterprise zero-retention agreements with all LLM providers. No model training on customer data. Training permanently disabled on Enterprise plans.
Enterprise SSO with SCIM, MFA-enforced, exclusive SSO mode available. Annual penetration testing validates auth controls.
Automatic redaction is best-effort β non-standard secrets may pass through. Mitigation: Developer training, secret rotation policy, custom secret pattern requests.
Inherent to all LLM-based agents. Ampcode has bash/tool execution capabilities. Mitigation: User approval for destructive actions, bug bounty program covers prompt injection.
Restricted employee access, JIT provisioning, SSO with MFA, access logged and monitored. Regular access reviews.
SOC 2 Type II, ISO 27001:2022, GDPR, CCPA, EU AI Act compliant. All data in US jurisdiction. No China-based providers.
Like all cloud services, Ampcode operates under a shared responsibility model. Security is a partnership β here is exactly what the vendor handles versus what your organization must own.
rm, curl, git push, and network operations.env files and vault-based secret management β Amp best-effort avoids reading theseampcode.com, auth.ampcode.com, authapi.ampcode.com on corporate proxyRECOMMENDED FOR ENTERPRISE USE
Ampcode/Sourcegraph demonstrates a mature enterprise security posture with SOC 2 Type II certification, ISO 27001:2022, comprehensive encryption, zero LLM data retention on Enterprise plans, SSO/SCIM support, and a well-defined shared responsibility model. All infrastructure is US-based with no China-based providers.
Conditional on: Enterprise plan activation, SSO enforcement, developer training completion, and regular audit log reviews.
| Document | URL | Type |
|---|---|---|
| Ampcode Security Reference | ampcode.com/security | Primary Source |
| Sourcegraph Security Page | sourcegraph.com/security | Primary Source |
| Sourcegraph Security Trust Portal | security.sourcegraph.com | SOC 2 / Pentest / ISO |
| Amp Trust Center | trust.ampcode.com | SOC 2 / Reports |
| Privacy Policy | sourcegraph.com/terms/privacy | Legal / Privacy |
| Subprocessors List | sourcegraph.com/terms/subprocessors | Data Processing |
| System Status | sourcegraphstatus.com | Operational Status |
| Terms of Service | sourcegraph.com/terms | Legal |
| SBOM Documentation | sourcegraph.com/docs/cli/how-tos/fetch_sboms | Supply Chain |
| Repository Permissions | sourcegraph.com/docs/admin/permissions | Configuration |
| No BYOK Policy | ampcode.com/news/no-more-byok | Architecture Decision |
Β© 2026 β CISO Security Assessment Report β Prepared with Ampcode
This document is based on publicly available security documentation and should be supplemented with direct vendor engagement, NDA-protected document review (SOC 2, pentest reports), and internal risk committee evaluation.