ProdgatorDocs
AdministrationAI features

AI data and privacy

What each AI feature sends to the model and when, how answers show their sources, and regenerating or rating an answer.

What data is sent and when

The table below shows what data Prodgator sends to the AI model for each feature:

FeatureData sentWhen
Failure explanationsFailing job logs (excerpt around the error), commit diff summary, earlier explanations for the same workflowAutomatically when a run fails
Dashboard widgetsNone; the model sees only the prompt and the data catalog, not your actual dataWhen you request a widget generation
Security triageUp to the 500 most severe open GitHub security alerts, combined by cause into at most 120 entries: count, title, repositories, package and versions, CVE, rule, file paths and the first 300 characters of the description; secret scanning alerts send only type, repository, rule and file pathWhen someone clicks Analyze on the Security page
Release risk summariesCommit message first lines and pull request titles since the last successful deployment to the environment, failed runs and failed deployments of that change set with their explanation headlines, the newest policy evaluation's results, attestations for the commitWhen someone who can approve opens the approval dialog for a deployment waiting for approval
Policy drafting assistantYour request, the policy in the editor, approver group names and ids, member names and emails (up to 200), and a description of the policy input documentWhen you click Generate in the editor's Draft with AI dialog
Ask ProdgatorYour question and the results of the lookups the model asks for (runs, deployments, security alerts without secret descriptions, metrics, earlier AI answers), each limited to what your role and plan allow. If you turn it on, also a short description of the page you are on (see Page context)Every message you send. Searching and reading these docs sends nothing about your organization

Page context

When you send a message to Ask Prodgator from a page in the app, the message can carry a description of that page. It is off until you turn it on: click the chip above the message box to see exactly what would be sent, and use its switch to start or stop sharing. See Ask Prodgator.

What is sent:

  • The page name, its path and the filters in the address bar.
  • The items you have open or selected, by id and title (for example an expanded run or pull request).
  • A summary of data the page has already loaded for what you see: for example run status, branch and duration, pull request titles and gate results, deployment status and approvals, and security alert titles and severities. It is cut to a few kilobytes.

What is never sent:

  • Secrets. Secret scanning alerts are left out entirely, and anything that looks like a token, key or password is removed in the browser and again on the server.
  • Log excerpts, commit messages, descriptions, links and email addresses.
  • Anything from Settings, your profile, onboarding or the Admin Console.
  • Data from another organization. The description only covers the organization you are signed in to.

The model reads the description as data, not instructions, and it does not change what Ask can look up. The description is stored with your message as part of the conversation and is deleted with it, after 30 days or when you delete the conversation.

Feature requests

You can request a feature from a card in Ask Prodgator or from Request a feature in the Help menu. The Help menu entry is on every plan and for every role, and a request costs no AI credits. Nothing is sent until you press Send request.

A request stores:

  • The summary shown on the card, up to 500 characters. Anything that looks like a token, key or password is removed first.
  • The feature it is about, your user id, your organization's id, name and plan, the language you use, where you sent it from (Ask or the Help menu), and when you sent it.

Nothing from the conversation, the page you were on or your data is attached. Prodgator staff read the summaries to decide what to build, and see the totals per feature, the plans and organizations that asked, and who sent each request. Other people in your organization cannot see your requests. When a feature you asked for becomes available, you may get a notification.

Data privacy and security

AI features send the data needed for each answer (for example the failing part of a build log, the commit's changed files, or the findings being triaged) to an AI model that runs inside our cloud provider's United States regions. Your data is not used to train models and is not shared with the model's developer. Secrets we can recognize (tokens, keys, passwords in assignments, credentials in URLs) are removed before anything is sent. Log text, commit messages and diffs are passed to the model as data only: instructions written inside them are ignored, and links in an answer are shown only when they point to one of the answer's sources. Answers are stored in Prodgator for as long as your plan keeps pipeline data (at least 7 days, at most 365). Prodgator does not log prompt text. Admins can turn AI off for the whole organization or for single features.

Answer provenance

Every AI-generated answer shows:

  • AI-generated: A label that marks the answer as written by AI
  • Sources: The specific runs, logs, commits, findings, or other data that informed the answer
  • Date: When the answer was generated

The model that wrote an answer is kept with the answer for auditing, but not shown on the page.

You can click "Why am I seeing this?" to open the full AI features guide and understand how the answer was created.

Regenerating answers

All AI-generated answers can be regenerated on demand:

  • Failure explanations: Regenerate using the Regenerate button on the pipeline run page or Failures view. Turning off AI features or rotating credentials may cause the feature to become unavailable; in this case, the explanation is marked as skipped.
  • Security triage: Reanalyze on the triage card; the card says when findings were detected after the triage was written.
  • Release risk summaries: Regenerate inside the approval dialog. A summary is reused across the organization until the commits, failures, policy results or attestations change.
  • Policy drafts: Generate again from the dialog; every draft is a new one, nothing is cached.
  • Ask Prodgator: Ask again. Conversations are private to you and are not shared answers.
  • Widgets: Edit the widget prompt or request a fresh generation.

Feedback

You can mark AI answers as helpful or not helpful. Prodgator counts the votes to improve its prompts. They are not used to train any model.

On this page