







Rollbar Lines · Security
Your code stays inside your network, and nothing merges without one of your engineers.
Rollbar Lines is installed in your cloud account or your own data center, and the only traffic that leaves your environment is model calls to your provider, on your keys. The people you allow start runs, a person on your team merges every change, every run is logged on your systems, and you turn it off by revoking its credentials.
Where it runs
It runs on your systems, inside your network, on your keys.
Rollbar Lines is installed on your own systems, in your cloud account or your own data center. The service that takes your requests and starts each job, the virtual machines that do the work, and the disks they use all live there. It reaches your repositories and your ticket system with credentials you create and scope.
Inside
The Rollbar Lines service, the virtual machines, your repositories, your ticket system, your development environment, the run logs.
Inbound
Events from your ticket system and code host, to an endpoint on your systems.
Outbound
Model calls to the provider you already have an agreement with, on your keys. Rollbar does not receive your code.
Your own systems
Rollbar Lines service
Takes your requests, starts each job, keeps the log
Virtual machine
One per job, created on demand
Virtual machine
One per job, created on demand
Your repositories
Your ticket system
Run logs and reports
Who asked, what ran, what it wrote
model calls only
Your model provider
On your keys, under your agreement
Your third-party integrations
Reached with credentials you scope








Who stays in charge
Your people approve every change.
Rollbar Lines works within rules you set, and we help you write them during the install. It does not merge its own work.
Which tickets it may take
You control an allowlist of repositories and labels, and anything outside it is declined and logged.
Who reviews and merges
A person on your team approves every pull request. Rollbar Lines has no path to your main branch.
What it may never run
Each repository carries a written list of what it may never run, starting with pushes to main, production shells, and data exports, and you add to it.
A log of every run
The log records who asked, what it did, what it ran, and the report it wrote. It stays on your systems, and you can read it at any time.
Security review
These are the questions we get in every security review.
Where does the agent run?
Does any of our code go to Rollbar?
What leaves our environment?
Who can start a run?
What can it change?
How do we see what it did?
How do we turn it off?
What about single sign-on, retention, and certifications?
Tell us about your stack.
We will tell you what the first line looks like.
Set up a demo, or talk with a Rollbar engineer about where it would fit.