Security, for engineers
The data-handling questions you ask before you install a review bot, answered with the same claims as the security page. Each answer renders from the Aevral security posture manifest, Verified against the running worker 898916bf7 (2026-10-01); the binding commitments are in the DPA, section 1.7.
The questions, with their manifest claims
- What does a review read, and what does it never do?
Scans read one archive of your repository at a single fixed commit. Pull request reviews read the diff, plus full files at the head commit for some changed files. Both have size limits. Code is processed in memory on a server in Paris. No customer code is executed, and the model has no tools or shell.
Verified in code · claim code.access_and_processing
The worker runs in the Deno sandbox with outbound network limited to a list of hosts and environment access. It has no permission to write files, run subprocesses, load native code or read system information, and it loads no code at run time beyond what the image cached when it was built.
Verified in code · claim code.sandbox_today
The worker has no write access to disk at all, not even to a temporary folder. Repository archives are read in memory.
Verified in code · claim code.no_file_writes
- Which hosts process my code?
Scans and pull request reviews run on GLM-5.3 or GLM-5.3 Flash through OpenRouter, depending on the job and plan, pinned to three hosting providers listed on the Aevral sub-processor page: Together AI (US), Fireworks AI (US) and Inceptron (Sweden). Inceptron does not currently serve these models, so in practice requests are processed in the US. The running worker reports its rail and model ids publicly.
Reported by the running service · claim model.rail_today
When Aevral uses OpenRouter, every request is restricted to a closed list of hosting providers, with data collection denied and zero data retention required. The list is never widened without a sub-processor notice.
Verified in code · claim model.provider_pin
- Is my code used to train models?
Your code is not used to train models. Each model request asks the provider not to collect or retain data; the account-level setting is attested by the provider.
Policy · claim policy.no_training
- What happens to secrets-looking paths and patterns?
Scans leave out files whose paths look like secrets and redact credential patterns in the code they send. Pull request reviews hold back sensitive files and name them in the Check as not sent. Detection is pattern-based.
Verified in code · claim secrets.pattern_based
- What GitHub access does a review hold?
Each scan or pull request review gets its own GitHub token, minted for that job, limited to one repository and capped as described above. Tokens live in memory only, expire after GitHub's default of one hour, and are never stored.
Verified in code · claim tokens.per_job_scoped
Every token Aevral mints is capped below what the App holds: Contents read, Metadata read and Checks write, plus Pull requests write for pull request reviews. No token Aevral mints carries Contents write or Issues access.
Verified in code · claim tokens.capped_below_app
Aevral writes to your repositories only as advisory check runs and pull request review comments submitted as comments. It never commits, pushes, creates branches, merges or approves. Suggested fixes are text only.
Verified in code · claim writes.advisory_only
- What is stored, where, and for how long?
Aevral data is stored in a Supabase database in the EU (Frankfurt). Row level security is on for every Aevral table exposed through the database API and limits access to members of your organization; internal tables sit in a schema the API does not expose. The worker uses its own database role without row level security bypass, which may only call a fixed list of functions and holds no direct table access, and it refuses to start with any other role's key.
Verified in code · claim data.database
Automatic deletion runs today for these records: findings in the worklist are deleted 24 months after they were last seen, and disconnected AI tool connections are deleted 90 days after they were disconnected.
Verified in code · claim retention.automatic
- Can I check this myself, live?
The current state of the MCP connection, MCP scans, the review command, standards sync writes and EU-only processing is read from the running worker.
Reported by the running service · claim flags.runtime_state
Scans and pull request reviews run on GLM-5.3 or GLM-5.3 Flash through OpenRouter, depending on the job and plan, pinned to three hosting providers listed on the Aevral sub-processor page: Together AI (US), Fireworks AI (US) and Inceptron (Sweden). Inceptron does not currently serve these models, so in practice requests are processed in the US. The running worker reports its rail and model ids publicly.
Reported by the running service · claim model.rail_today
The full posture, including the announced changes and what Aevral does not have yet: the security page. The sub-processor list: trust center.