// SECURITY

Your code is evidence. We treat it that way.

The same constitutional controls OAG audits for are the controls OAG runs on.

Zero-retention digestion

Repositories are cloned into an ephemeral workspace, parsed to AST, audited, then destroyed. We retain findings and Merkle roots — evidence — never source code.

No training on your code

Customer code is never used for model training, evaluation or benchmarking. Contractually guaranteed in our Terms of Service.

Tenant isolation

Every audit runs in a segregated execution context on its own isolated network segment. One customer's job can never observe another's.

Tamper-evident sealing

Reports are chained into a Merkle audit trail. Any post-hoc alteration — by us, by you, by anyone — is mathematically detectable.

PII interception

Ten PII patterns are masked before content reaches any model provider, with every masking event logged for audit.

Self-hosted option

Enterprise customers can run the full stack inside their own perimeter. The sealing and verification machinery works identically offline.

SECURITY DISCLOSURES: me@jhosen.com · WE ACKNOWLEDGE WITHIN 72 HOURS.

Put your next audit
beyond dispute.

Three free audits a month. No credit card. Ninety seconds to evidence.

ENTERPRISE & SELF-HOSTED: me@jhosen.com