Skip to content

Security and data handling

This page covers the questions engineers ask before installing: what the app can access, where analysis happens and what controls you have. The legal documents govern the details and nothing here replaces them. Questions can go to [email protected].

What the GitHub App can access

The GitHub App uses read access to repository contents and pull request context, because a useful review requires understanding a change in the codebase where it will run, not only the diff lines.

Write access exists for outputs, not code: publishing pull request reviews and comments and creating or updating the Foundry Verify check run. The app also reads pull request conversation comments so repository members can use commands.

Agentic SQA does not create or push branches to your repository and cannot modify your code. Each review checks out the exact commits under review into a detached, task-local checkout inside IR Labs' analysis environment, discarded when the review task ends.

Where analysis happens

Analysis runs in isolated tasks in IR Labs' environment on Amazon Web Services, with portions of the code and analysis context sent to OpenAI for model inference. We have not enabled any data sharing with OpenAI for training OpenAI's models.

We do not claim your code never leaves your environment. A review means repository content reaches our systems, and we would rather say that plainly than talk around it.

Questions about other service providers can go to [email protected].

Local verification with uok

Verification through the uok command-line tool executes in your own environment, not in IR Labs' hosted environment: it runs against your checkout and available build context. The CLI authenticates to your workspace so runs, quotas and support attribute correctly.

Local execution does not mean nothing is transmitted. The CLI sends IR Labs verification verdicts, compile commands and build metadata and, where applicable, intermediate compiler representations, plus usage telemetry from the locally installed component.

Online use against a pull request requires git and gh and reuses your existing GitHub CLI authentication. When you invoke the CLI against local changes, the corresponding code may be committed and pushed to a connected repository — including a service-created working branch we create and later remove — so analysis reaches the code through your source-code host rather than by direct upload from your machine.

This is a summary. The Privacy Policy governs the details, and the CLI docs cover install, platform support and modes.

Your controls

GitHub controls whether the app is installed on all repositories or a selected list. The workspace console controls which granted repositories are enabled for review, without touching the GitHub installation.

Uninstalling the app revokes repository access and invalidates cached access tokens immediately. Deleting your workspace ends processing and closes the account.

Data use and retention

How we may use your data to improve the product, including model training, is covered in the content, data and permissions and model-training provisions (Sections 6 and 7) of the Terms of Service, and what we retain is governed there and in the Privacy Policy. We keep that language in the legal documents rather than restating it here, so there is exactly one authoritative version.

Requests about retained data can be sent to [email protected].

Encryption

Data is encrypted in transit using TLS and at rest using AWS server-side encryption. Credentials used for repository reviews are short lived and are not durably stored.

Permissions in detail · Privacy Policy · Terms · Terms of Service