Rollbar Lines · Security

Your code stays inside your network, and nothing merges without one of your engineers.

Rollbar Lines is installed in your cloud account or your own data center, and the only traffic that leaves your environment is model calls to your provider, on your keys. The people you allow start runs, a person on your team merges every change, every run is logged on your systems, and you turn it off by revoking its credentials.

Where it runs

It runs on your systems, inside your network, on your keys.

Rollbar Lines is installed on your own systems, in your cloud account or your own data center. The service that takes your requests and starts each job, the virtual machines that do the work, and the disks they use all live there. It reaches your repositories and your ticket system with credentials you create and scope.

Inside

The Rollbar Lines service, the virtual machines, your repositories, your ticket system, your development environment, the run logs.

Inbound

Events from your ticket system and code host, to an endpoint on your systems.

Outbound

Model calls to the provider you already have an agreement with, on your keys. Rollbar does not receive your code.

Your own systems

Rollbar Lines service

Takes your requests, starts each job, keeps the log

Virtual machine

One per job, created on demand

Virtual machine

One per job, created on demand

Your repositories

Your ticket system

Run logs and reports

Who asked, what ran, what it wrote

model calls only

Your model provider

On your keys, under your agreement

Your third-party integrations

Reached with credentials you scope

Who stays in charge

Your people approve every change.

Rollbar Lines works within rules you set, and we help you write them during the install. It does not merge its own work.

Which tickets it may take

You control an allowlist of repositories and labels, and anything outside it is declined and logged.

Who reviews and merges

A person on your team approves every pull request. Rollbar Lines has no path to your main branch.

What it may never run

Each repository carries a written list of what it may never run, starting with pushes to main, production shells, and data exports, and you add to it.

A log of every run

The log records who asked, what it did, what it ran, and the report it wrote. It stays on your systems, and you can read it at any time.

Security review

These are the questions we get in every security review.

Where does the agent run?

Does any of our code go to Rollbar?

What leaves our environment?

Who can start a run?

What can it change?

How do we see what it did?

How do we turn it off?

What about single sign-on, retention, and certifications?

Tell us about your stack.
We will tell you what the first line looks like.

Set up a demo, or talk with a Rollbar engineer about where it would fit.