> ## Documentation Index
> Fetch the complete documentation index at: https://aspect.build/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> How Aspect Workflows handles build data, access, encryption and compliance on Aspect Cloud and Aspect Enterprise, with security updates, advisories and how to report a vulnerability.

export const MarketingPage = () => <div className="marketing-page-marker" style={{
  display: "none"
}} />;

export const CopyEmail = ({email = "hello@aspect.build"}) => <span className="inline-flex items-center gap-2">
    <a href={`mailto:${email}`} className="text-blue-600 dark:text-blue-400 font-semibold hover:underline">{email}</a>
    <button type="button" onClick={e => {
  navigator.clipboard.writeText(email);
  const b = e.currentTarget;
  b.textContent = "Copied!";
  setTimeout(() => {
    b.textContent = "Copy";
  }, 1500);
}} className="text-xs px-2 py-0.5 rounded-md border border-zinc-300 dark:border-zinc-600 text-zinc-500 dark:text-zinc-400 hover:bg-zinc-100 dark:hover:bg-zinc-700 transition cursor-pointer">
      Copy
    </button>
  </span>;

export const Section = ({children, className = "", gray = false, dark = false, id}) => <section id={id} className={`w-full flex justify-center px-4 py-16 md:py-24 ${gray ? "bg-gray-50 dark:bg-zinc-900" : dark ? "bg-zinc-900 dark:bg-zinc-950" : ""} ${className}`}>
    <div className="w-full" style={{
  maxWidth: "1140px"
}}>
      {children}
    </div>
  </section>;

<MarketingPage />

<Section>
  <div className="mx-auto prose dark:prose-invert prose-zinc" style={{ maxWidth: "800px" }}>
    <h1>Security</h1>

    <p>Security and data privacy are top priorities at Aspect. Your build data is encrypted in transit and at rest, and only your organization can see it. On Aspect Enterprise, no other customer shares your infrastructure, and self-hosted keeps it in your own cloud account.</p>

    <h2>Compliance</h2>

    <div className="flex items-center gap-4 mb-8">
      <img noZoom src="https://mintcdn.com/aspectbuild/-wpvJHm1oveu-5Pt/images/security/soc-badge.svg?fit=max&auto=format&n=-wpvJHm1oveu-5Pt&q=85&s=4a3d2a20fe334decf45bb570977d2287" alt="AICPA SOC" width="88" height="88" className="m-0" data-path="images/security/soc-badge.svg" />

      <p className="m-0">Aspect invests in security best practices and the certifications that matter to our customers. Aspect is SOC 2 Type 2 certified.</p>
    </div>

    <h2>Authentication</h2>

    <p>Every endpoint is authenticated. Aspect supports the OpenID Connect and SAML authentication standards.</p>

    <p>Cache data is only ever available to members of your organization. Build results are too, by default. On Aspect Cloud, an organization can choose public visibility, which lets any signed-in Aspect Cloud user view its build results.</p>

    <p>On Aspect Enterprise, users can sign in with SSO through your identity provider, or the deployment can trust your identity provider directly, with no Aspect accounts in between.</p>

    <h2>Data encryption</h2>

    <p>Aspect Cloud stores your data on AWS. Aspect Enterprise stores it on AWS or GCP, depending on your deployment.</p>

    <p>All data is encrypted at rest, and all traffic is encrypted in transit with TLS 1.2 or later.</p>

    <h2>Data use</h2>

    <p>Aspect uses your build data only to provide and maintain the service, never to train models or build other products without your written consent. Section 2.1 of the <a href="/terms">Cloud Service Terms</a> lists every permitted use.</p>

    <h2>Data deletion</h2>

    <p>Aspect Cloud keeps cache contents and build history for a fixed retention period, then deletes them. On Aspect Enterprise you set the retention period: hosted by Aspect, Aspect applies it; self-hosted, you manage and delete the data directly.</p>

    <p>You can request deletion of your data at any time. Email <CopyEmail email="security-requests@aspect.build" /></p>

    <h2>What we store</h2>

    <div className="overflow-x-auto">
      <table className="w-full text-sm border-collapse" style={{ minWidth: "560px" }}>
        <thead>
          <tr className="border-b border-zinc-200 dark:border-zinc-700"><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">Data</th><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">What it is</th><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">Aspect Cloud</th><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">Aspect Enterprise</th></tr>
        </thead>

        <tbody className="text-zinc-600 dark:text-zinc-400">
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Cache contents</td><td className="py-2 px-4">Action inputs and outputs: object files, archives, test logs, anything Bazel produces</td><td className="py-2 px-4">✓</td><td className="py-2 px-4">✓</td></tr>
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Build events</td><td className="py-2 px-4">The BEP stream: target outcomes, timings, test results, invocation metadata</td><td className="py-2 px-4">✓</td><td className="py-2 px-4">✓</td></tr>
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Build logs</td><td className="py-2 px-4">stdout/stderr from build and test actions</td><td className="py-2 px-4">✓</td><td className="py-2 px-4">✓</td></tr>
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Runner state</td><td className="py-2 px-4">The output base and workspace on a CI runner’s local disk, kept between jobs</td><td className="py-2 px-4">—</td><td className="py-2 px-4">With CI runners</td></tr>
        </tbody>
      </table>
    </div>

    <p>Aspect Enterprise CI runners check out your repository with credentials your CI provider issues, the way your existing runners do. The checkout is deleted when the runner is recycled. Aspect stores no other copy of your source.</p>

    <h2 id="where-it-lives">Where it lives</h2>

    <p>Aspect Enterprise gives you <strong>data isolation</strong>: no other customer shares your cache, workers or build event database. Self-hosted adds <strong>data ownership</strong>: the account, credentials, retention and audit trail are yours.</p>

    <div className="overflow-x-auto">
      <table className="w-full text-sm border-collapse" style={{ minWidth: "560px" }}>
        <thead>
          <tr className="border-b border-zinc-200 dark:border-zinc-700"><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white" /><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">Aspect Cloud</th><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">Enterprise, hosted by Aspect</th><th className="text-left py-3 px-4 font-semibold text-zinc-900 dark:text-white">Enterprise, self-hosted</th></tr>
        </thead>

        <tbody className="text-zinc-600 dark:text-zinc-400">
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Infrastructure</td><td className="py-2 px-4">Shared, scoped to your organization</td><td className="py-2 px-4">Isolated, yours alone</td><td className="py-2 px-4">Isolated, in your account</td></tr>
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Cloud account</td><td className="py-2 px-4">Aspect’s</td><td className="py-2 px-4">Aspect’s</td><td className="py-2 px-4">Yours</td></tr>
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Operated by</td><td className="py-2 px-4">Aspect</td><td className="py-2 px-4">Aspect</td><td className="py-2 px-4">Aspect, or your team</td></tr>
          <tr className="border-b border-zinc-100 dark:border-zinc-800"><td className="py-2 px-4">Air-gapped / GovCloud</td><td className="py-2 px-4">—</td><td className="py-2 px-4">—</td><td className="py-2 px-4">✓</td></tr>
        </tbody>
      </table>
    </div>

    <h2>Who at Aspect can reach it</h2>

    <p>Aspect operates Aspect Cloud and Aspect Enterprise hosted by Aspect. On self-hosted, you choose how much access Aspect holds, from fully managed to none; see <a href="/docs/aspect-workflows/enterprise/deployment-options/self-hosted#who-operates-it">who operates it</a>. Aspect’s roles are least-privilege, and every action they take lands in your AWS CloudTrail or GCP audit log.</p>

    <h2>Security updates</h2>

    <p>Security updates address newly discovered attacks reported to Aspect Build Systems, Inc. by the security research community. Disclosures are made confidentially, so fixes reach users before details are public.</p>

    <ul>
      <li><a href="/security-updates">Security updates</a>: how fixes are announced, and the mailing list</li>
      <li><a href="/security-advisories">Security advisories</a>: published advisories with mitigation guidance</li>
      <li><a href="/security-vulnerability-report">Report a vulnerability</a>: the responsible disclosure policy</li>
    </ul>

    <h2>Questions</h2>

    <p>Have a question about how Aspect handles security or data privacy? Email <CopyEmail email="security-requests@aspect.build" /></p>
  </div>
</Section>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.