Trust and privacy

Clearline is built to minimize what it touches. This page shows exactly what data moves, what stays in your environment, and what Imua retains.

Clearline delivery intelligence architecture diagram

Clearline uses operational metadata only. It does not ingest message contents, documents, source code, or employee communications.

What we access

When you connect Clearline to your delivery tools, Imua requests read-only access scoped to a project, repository, or workspace. Access is granted by an API token that you create and may revoke at any time.

Depending on the system, the metadata accessed includes issue status, type, priority, dates, story points, sprint and epic membership, commit cadence, and pull or merge request timing.

Imua does not request access to ticket descriptions, comments, attachments, source code, repository contents, documents, or message bodies. These remain in your environment and are never part of any Clearline diagnostic.

Security posture

Clearline is designed for low-data exposure. Connect uses scoped, read-only access to operational metadata and avoids source code, ticket body text, comments, attachments, documents, and message bodies. Access can be revoked by the client. Security review and DPA support are available on request.

How scoring works

Scores are computed by deterministic analysis. AI isn't required to produce a score.

The Clearline scoring engine runs on Imua's infrastructure. It computes six organizational failure mode scores from the metadata described above.

Some clients choose to interact with their results through a conversational interface. That layer is optional and entirely under your control. You may use your own AI model and your own commercial terms with that vendor, or retrieve results with no AI involved at all.

What we retain

Raw, issue-level metadata is discarded once scoring is complete. Imua retains only the aggregated, de-identified scores, bands, and findings produced by Clearline.

Imua does not retain issue descriptions, comments, attachments, source code, repository contents, or raw issue-level metadata after scoring is complete.

Where personally identifiable information appears incidentally in standard project metadata, such as an assignee or reporter name, it is used solely to compute scores and is never shared, sold, or used outside the scope of the engagement.

Personally identifiable information (PII) and protected health information (PHI)

Clearline is designed to access engineering delivery metadata only and is not designed to request, require, or intentionally process personally identifiable information (PII) or Protected Health Information (PHI).

In practice, certain project metadata may incidentally contain limited identifiers, such as an assignee or reporter name, email address, or user ID provided by a connected system. When such information is present, it is used solely to compute diagnostic scores, is never sold, and is never used to train foundation models or third-party AI systems.

Clearline does not require personally identifiable information to compute organizational scores. Limited identifiers may pass through incidentally depending on how a connected system labels its data, but the scoring methodology itself does not depend on them.

Raw metadata, including any incidental identifiers, is discarded after scoring is complete.

Organizations operating in regulated environments are encouraged to discuss their specific privacy, security, and compliance requirements with us before an engagement begins.

Questions

If you have questions about how Clearline accesses or handles your data, or want to discuss a Business Associate Agreement or Data Processing Addendum for your organization, reach out at jim@imuasystems.com.