Where it runs
Web and API live on Railway, in isolated containers. Secrets stay in the environment — not in the repo.
Trust
Fair question before any AI touches production code. Here’s what we run, who we call, and how a review stays scoped to the PR you opened.
Powered by
Web and API live on Railway, in isolated containers. Secrets stay in the environment — not in the repo.
You choose which repos. Tokens are short-lived. We don’t ask for a personal password to your org.
Reviews go through OpenAI and Anthropic. We send the diff and what’s needed for that review — not a dump of your company.
TLS on every browser and webhook call. Keys live in a managed secret store.
We watch webhook delivery and API latency. If a review doesn’t post, we want to know before you do.
The review job reads the diff in memory. We store workspace metadata, usage, and messages you send us. Ask if you need a DPA.
We read the diff for that pull request. We are not scraping your entire org. What we store is workspace metadata, usage, and anything you send us through the product.
Product changes are published on our changelog.
Questions security and engineering teams actually send us.
We only see the repos you connect. Traffic is TLS. Secrets live in a managed store. We read the diff for that review — not your whole org “just in case.” Email us if you need a questionnaire or a DPA.
The pull request diff and the metadata needed to write the review. Not your entire codebase. Each job is scoped to that PR or merge request.
It’s the official GitHub App. You choose which repositories to install on. You can revoke access anytime.