Confidentiality and code handling
Handing your codebase to a stranger is the hardest part of buying an audit. Here is exactly what happens to it, including the parts most services leave vague.
What we commit to
Access is limited to the audit
We use a dedicated read-only audit identity. We never ask for your normal account password, and we never connect to your production database.
You choose how your code is processed
The AI-processing mode is your decision, made explicitly at intake. There is no default that quietly sends your code anywhere.
Your source is not used to train our products
We do not use client code to train, improve or benchmark mAIb products.
Your code is never executed on our machines
Static review reads files. If you permit execution, it happens inside a disposable, network-restricted container that is destroyed afterwards.
Temporary materials are deleted
The repository copy, extracted workspace and temporary evidence are deleted at the end of the retention period, and a deletion record is produced.
A mutual NDA can be considered
If your situation calls for one, ask before you purchase.
Your three AI-processing choices
Some audit work is assisted by AI models. Whether that may touch your code is your call, and you make it before we start.
Mode 1 — No external AI processing of my source code
My source code must not be sent to any external AI provider. The audit uses static tools, local deterministic parsers and manual operator review only.
The most restrictive option. Some analysis depth depends on manual review time, so a small number of checks may take longer or be marked as not run.
Mode 2 — Redacted snippets may be processed by a disclosed AI provider
Selected, redacted code snippets may be sent to the disclosed external AI provider to assist analysis. Secrets, personal data and customer data are removed before any snippet is sent.
A middle option. Only fragments relevant to a specific finding leave our environment, after redaction. The provider is named in the report and in our AI-processing disclosure.
Mode 3 — Repository-level AI assistance is permitted
The repository may be processed by the disclosed external AI provider, under that provider's applicable data-processing terms, to assist the analysis. I understand my code is transmitted to that provider under this option.
The fastest and most thorough option. Your code is transmitted to the named provider. We do not make claims about that provider's own training or retention practices beyond their published data-processing terms, which we reference in our disclosure.
Retention and deletion
Deleted at the end of retention
- The repository copy or uploaded archive
- The extracted working copy of your code
- Temporary evidence beyond the minimum kept for the report
- Any temporary access token, which is also revoked
Kept as a service record
- The job record and your consent records
- The findings register and the report we issued you
- The minimum commercial record for accounting
- The deletion record itself
The default retention period is 30 days after delivery. You can request deletion sooner at any point, and we will confirm when it is done. Full detail is in the code-handling policy and the privacy notice.