What leaves the machine, what is never executed, and how promotion is constrained.
Security and privacy boundaries
Source data sent to providers
In-scope source chunks and source-derived manifests are sent to the configured model provider for extraction and narration. Use only an endpoint approved for the repository and review the provider's retention policy.
Repository content is data
- Source scripts and configuration are never executed, sourced, or evaluated.
- Prompts delimit repository text and instruct the model to ignore embedded instructions.
- Likely credentials are redacted as defense in depth and reported without repeating the value.
- Oversized and binary files are skipped with a recorded reason.
- README and docs files may guide interpretation but are labeled untrusted hints.
Narrow write boundary
Before review, writes are limited to runtime and staging areas. Approval verifies that vault HEAD has not changed, promotes only planned paths by atomic replacement, stages an explicit allowlist rather than git add -A, and restores pre-promotion content if commit fails.
Run evidence
report.json records versions, source and vault SHAs, provider/model identity, file dispositions, validation results, deltas, model-call counts, staged paths, committed paths, and final vault SHA without including API keys or full source files.