Gradle Technologies is now Develocity — read the announcement

Security & Compliance

Security and data protection built into Develocity at every level, whether you self-host or run on managed SaaS.

Develocity security capabilities shown alongside the self-hosted, Full SaaS, Hybrid SaaS, and BYOC deployment models.

Feature overview

Security & Compliance

Develocity is trusted by many of the world's largest financial institutions and technology companies, with security and data protection built in at every level. Develocity runs self-hosted or air-gapped, as fully managed SaaS or Hybrid SaaS, or in your own cloud under Bring Your Own Cloud (BYOC). See Deployment Options for more information. Single sign-on and SCIM provisioning are standard, with role and project-level access control. Develocity is SOC 2 Type II audited, with the current report and its scope available in the Trust Portal.

Integrates with your identity provider, scoped to least privilege

  • Single sign-on integrates with any SAML or LDAP identity provider.
  • A SCIM 2.0 integration automatically manages user and group lifecycles, so developers get access quickly.
  • Role-based access control gives each user the minimal privileges they need.
  • Project-level access control lets separate teams or products share one Develocity instance while keeping each project's data visible only to the right people.
An identity provider feeding Develocity via SAML or LDAP, resolving to role- and project-level scopes, with SCIM provisioning.

Encrypted in transit and at rest, with keys you can own

  • All communication with Develocity is encrypted in transit using modern TLS.
  • Sensitive data is encrypted at rest by default
  • On SaaS, Bring Your Own Key (BYOK) lets you supply and control your own encryption key.
Encryption in transit and at rest, with the SaaS Bring Your Own Key option.

Reachable through your existing network controls

  • On SaaS, AWS PrivateLink provides VPC-to-VPC networking that stays off the public internet.
  • IP allowlisting restricts access to the networks and IP ranges you trust.
  • Supports HTTP/S proxies and SSL inspectors for the web UI, build tools, and AI agents.
PrivateLink connectivity, IP allowlisting, and HTTP/S proxy and SSL-inspector compatibility.

Your data isolated, on the infrastructure and in the region you choose

  • Single-tenant data storage within shared clusters, or dedicated VPCs and clusters for Enterprise customers.
  • Deployment regions in the US, EU, and Asia Pacific keep infrastructure close to your CI and developers.
  • Hybrid SaaS lets you run on-premises Edge Nodes to keep cache artifacts within your own infrastructure.
  • All SaaS connections are customer-initiated, so no inbound access to your network is required.
Single-tenant isolation, a region selector, the dedicated-environment option, and customer-initiated connectivity.

Continuously scanned, independently tested

  • All development for Develocity follows a security methodology with continuous vulnerability scanning, dependency analysis, and artifact-integrity checks.
  • Source code and dependencies are scanned for known vulnerabilities nightly, and any discovered vulnerability follows a documented disclosure process.
  • Each major release goes through third-party penetration testing, with results available in our Trust Portal.
A nightly vulnerability-scanning pipeline with dependency analysis and independent third-party penetration testing.

AI that runs on your data without sharing it

  • Develocity's AI runs on our own models, shipped with the product; we don't train on your data or send it to external AI services.
  • AI features work only on your build and test data.
  • Your own AI agents connect through the Develocity MCP server, authenticated with scoped access keys.
  • Agents and AI features run under the same encryption, access, and privacy controls as the rest of Develocity.
Develocity AI on bundled models, with customer agents connecting via the MCP server, and no data sent to external AI services.

Private by design, with independently audited controls

  • Privacy by design for new product features and internal processes. Develocity never captures your source code.
  • For on-premises deployments, we only process your data when you share it with us for customer support.
  • Compliance with data-protection regulations in every country we operate in, including GDPR and CCPA, with our subprocessor list published publicly.
  • Independently audited to SOC 2 Type II; the report and its scope are in the Trust Portal.
Badges for SOC 2 Type II, GDPR, and CCPA.

Resources

Security whitepapers (SaaS & on-premises)
Whitepaper

What's next

Get started today with a 30-day free trial of the entire Develocity product suite.

Start Free Trial

© 2026 Gradle, Inc. Gradle®, Develocity®, Build Scan®, and the Gradlephant logo are registered trademarks of Gradle, Inc.

Get an AI summary of Develocity: