← Back to Guides

    How to Secure Sourcegraph Cody

    Step-by-step guide to using Sourcegraph Cody securely with self-hosted and enterprise options.

    Sourcegraph Cody Security Context

    Cody is codebase-aware AI that can be self-hosted for maximum security. Enterprise features include advanced access controls and audit logging.

    Security Checklist

    1

    Review AI-generated code

    Critical

    Always review Cody's suggestions for security vulnerabilities.

    2

    Configure self-hosted options

    Critical

    Consider self-hosting Sourcegraph for maximum data control.

    3

    Audit codebase access

    Critical

    Review what repositories Cody has access to.

    4

    Protect secrets

    Critical

    Ensure sensitive files are excluded from Cody's analysis.

    5

    Review enterprise security features

    Critical

    Leverage Sourcegraph's enterprise security features if available.

    6

    Configure access controls

    Set appropriate access controls for team members.

    7

    Enable audit logging

    Track Cody usage for security monitoring.

    8

    Review suggested dependencies

    Audit packages suggested for vulnerabilities.

    9

    Validate code patterns

    Ensure generated code follows security best practices.

    10

    Configure integration settings

    Review IDE integration security settings.

    11

    Test authentication flows

    Verify any generated auth code works securely.

    12

    Review API usage

    Check API integrations for proper security.

    13

    Enable two-factor authentication

    Require 2FA for Sourcegraph access.

    14

    Review network security

    Ensure secure connections to Sourcegraph.

    15

    Configure data retention

    Set appropriate data retention policies.

    16

    Run security scan

    Use VibeEval to scan deployed applications.

    Related Resources

    Automate Your Security Checks

    Let VibeEval scan your application for vulnerabilities.

    Scan Your App