Skip to main content
← CodePeel

Security and code handling

Understand what CodePeel processes before connecting a repository or submitting code for review.

What is sent for review?

CodePeel processes submitted code changes and relevant context to generate findings and answer review questions. That can include file paths, code snippets, repository information and conversation context. Requests are processed by external AI providers. Your source does not stay exclusively inside GitHub.

Only submit repositories and content you have permission to share with CodePeel and its providers. Avoid including credentials, personal data or other sensitive material in code or prompts.

What can be retained?

Review history can include finding descriptions, source snippets, suggested fixes, file paths, line numbers and review metadata. Repository context indexes can also retain source chunks and embeddings so relevant code can be retrieved for later reviews.

CodePeel is not a zero-retention or metadata-only service. Provider processing and retention are subject to the provider's terms and configuration. We do not claim a universal zero-retention agreement across providers.

For the broader account and data policy, see the Privacy Policy. Contact us if you need clarification about data deletion or your repository has processing restrictions.

GitHub access

Choose which repositories the CodePeel GitHub App can access during installation. Review the permissions GitHub shows before approving access. Reviews require reading code and posting feedback; supported fix workflows also need permissions to create changes.

You can manage or uninstall the GitHub App through GitHub's installation settings. Removing access prevents future access through that installation; it does not itself erase data already retained by CodePeel or third-party providers.

Review coverage and limitations

A review can identify potential security issues, but it cannot certify a repository or prove the absence of vulnerabilities. Its scope depends on the changes and context available. Use tests, dependency and secret scanning, and human review appropriate to your project.

Read the security review guide for how to investigate findings. Never interpret an empty findings list as a security audit or compliance certificate.

Report a concern

Use the contact page to report a security concern privately. Include the affected feature, steps to reproduce and impact, but omit live credentials and unnecessary personal information. Do not post sensitive reports in a public pull request.