The trust policy
You are letting us read the thing you are selling. These seven commitments say exactly what we do with that access, and every one of them is kept by how the system is built.
Last updated 7 August 2026
The seven commitments
- Read-only access to one repository. We use a GitHub App with read-only contents permission on exactly the repository you choose. We cannot write to it, and we never see your other repositories.
- Pinned and ephemeral. Your analysis runs against one commit inside an isolated, single-use virtual machine with restricted network access. The machine is created for your job and destroyed when it finishes.
- We do not keep your source code. After analysis we keep the report: findings, short evidence excerpts of a few lines each, measurements, and cryptographic hashes. Every copy of your source is destroyed with the analysis machine. An uploaded archive is deleted within seven days.
- No training, ever. AI analysis runs under commercial API terms that do not train on your data. Region-pinned processing is available on request.
- If we find live credentials, we protect you first. Secrets are always redacted in reports and never stored or displayed in full. If we detect an apparently live credential we notify you immediately with rotation guidance. Any verification we do is read-only and side-effect free.
- Buyers never touch your code. Buyers see the report and the certificate. Sharing is yours to control: links expire, carry the viewer's identity as a watermark, can be revoked, and every view is logged. The public certificate carries grades and hashes, never code.
- Confidential by default. Our terms include a mutual confidentiality clause covering your code and your report. We never aggregate or resell anything derived from your codebase. Our subprocessors are listed publicly, with what each one can see.
Why the certificate shows so little
The certificate is public and your app is live. Publishing vulnerability specifics, file names, or dependency names would hand an attacker a map. So the certificate carries grades, counts, and fingerprints only. The detail lives in the report, which is yours to share selectively.
What we do not claim
We assess code. We do not verify revenue, MRR, churn, or any other financial claim, and we say so on the certificate. Marketplaces already connect Stripe for that.
A report reflects one commit at one moment. It is a point-in-time, best-effort assessment, not insurance and not a warranty.
Where the detail lives
How we handle your code covers the personal information side, including the subprocessor list and how long anything is kept. The methodology says what we look at, and the terms say what we promise about it.