This page outlines how Sandgarden approaches security for its Doc Holiday product.
The leadership team has backgrounds in network security and cryptography, and security is a first principle of design. For any questions, please email security@sandgarden.com.
Doc Holiday automatically generates and updates release notes and documentation. Doc Holiday indexes code, commits, PRs, product specs, and tickets, then writes crystal-clear documentation and release notes.

Sandgarden is SOC 2 Type II certified and conducts pen testing at least annually. Prospective and current customers may request a copy of the report, associated management summaries, and a select list of policies and procedures, via email at support@sandgarden.com.
Sandgarden's Doc Holiday product relies on the following subprocessors:
The product deploys as a fully hosted SaaS product. We do not yet have a hybrid nor self-hosted deployment option.
Doc Holiday automatically generates and updates release notes and documentation (both new and diff) as code is released. Its inputs are the code base, bug tracking system, engineering ticketing system, product specs, PRs, existing docs, brand voice, and more. It reads and summarizes (but does not store) code, commits, and tickets, then authors documentation and release notes on your behalf. The product creates connectivity to code repositories (either via an application, personal access token, or service account) to implement some functionality; permissioning has been specifically scoped down to the narrowest possible to allow the product to function. When customers connect ancillary applications (e.g. product specs) to augment and enhance documentation output, connections to those systems are defined within the Doc Holiday Admin UI. Secrets, tokens, and passwords are backed by KMS and encrypted at rest.
GitHub access is created using an application. Private access tokens are unfortunately not able to perform all the operations needed by Doc Holiday within GitHub specifically. Access granted to Doc Holiday must be explicitly provided on a per repo basis.
To provide its features, Doc Holiday makes AI requests to various LLM vendors. An AI request will include indexed information about your product, code base, brand voice, amongst other things.
Doc Holiday indexes codebases as part of providing its services, but does not store the raw source code. The only points saved are metadata and derived artifacts, such as summaries or vector embeddings.
You can delete your account at any time. Please email support@sandgarden.com and we will delete all data associated with your account, including any indexed codebases. Complete removal may take up to 30 days due to various cloud storage backup definitions.
If you believe you have found a vulnerability in Sandgarden, please email security@sandgarden.com. We will acknowledge and address the report promptly.
Begin your free trial and start your Doc Holiday today!