agenticreview.ai

Last updated: 6 October 2026

Security & data

How your code is handled

Each review runs on GitHub's own hosted runners. Your repository is cloned into memory inside GitHub's infrastructure, analysed, and discarded when the runner shuts down. Commit author identities are read only during the analysis to count contributors and are not stored.

What is stored

Only the derived metrics leave GitHub, and they are stored in the EU (Frankfurt). We never store source code, file names or commit messages, and never per-person data.

Infrastructure and region

Code analysis runs inside GitHub's infrastructure. Derived metrics are stored in the EU (Frankfurt).

Access and secrets

  • Access: our GitHub App asks for read-only access to contents and metadata, only for the repositories you choose. You can remove it at any time in GitHub.
  • Verification: a GitHub installation is only linked to your account after we confirm that you, as the signed-in GitHub user, have access to it.
  • Isolation: each account can only see its own reviews.
  • Payments: handled by Stripe as merchant of record. We never see your card details.

Reporting a vulnerability

Report security issues or send questions to info@agenticreview.ai. Reports are answered within two business days.