TRUST

Your repository stays yours.

Every exercise runs against a temporary copy. Here is exactly what that means.

Temporary copies

Workspaces expire automatically after the rehearsal or configured retention window.

Redacted secrets

Environment values, keys, credentials, and private material are removed before injection.

Allowlisted commands

Only supported diagnostic and verification operations can run inside the workspace.

Read-only source

The original repository is never modified by a rehearsal.

How workspaces are created and destroyed

A filtered source snapshot is copied into an isolated workspace. Completed workspaces are deleted; unfinished work expires automatically.

What we redact

Environment files, private keys, credentials, binary assets, generated dependencies, and oversized files are excluded from analysis.

Command allowlisting

The workspace exposes approved command IDs rather than a general-purpose shell. Package installs, outbound repository-controlled networking, and privileged execution stay blocked.

Data retention

Anonymous snapshots expire after 24 hours. Signed-in repository snapshots and reports remain reusable until they are removed from the account.

What we never do

We never write to the original repository, store provider passwords or OAuth access tokens, or use uploaded source to train a model.

Questions? Open a security or privacy inquiry ↗