three permissions · findings only · no keys
Security
What aidep can touch, what it stores, and what it never sees.
Permissions
We request 3 permissions. Comparable tools request 10.
| permission | level | why |
|---|---|---|
| Metadata | Read | Mandatory for all GitHub Apps |
| Contents | Read and write | Branch creation requires it; the API cannot open a PR without it |
| Pull requests | Read and write | Opening and updating the PRs is the product |
Your code
We fetch a tarball of your repo at scan time, scan it in memory, and discard it. We never store your source code. We store findings only: file path, line number, the matched identifier, and the registry row it matched. Repo access uses GitHub’s 1-hour installation tokens.
One exception, and only if you turn on evals: to draft the eval cases for a migration PR, we send the affected files to Anthropic once each, using our own key, to extract the prompts. Credential-named files (.env, key, pem, p12, pfx, secrets, credentials) are never sent, and key-shaped strings in the rest are redacted before the call. The cases land in the PR for you to read before anything runs. Leave evals off (the default) and your code never leaves the scan.
Your inbox
We hold an email address only if you typed it: into notify in .github/aidep.json, the waitlist form, or the upgrade form on /pricing (that one only reaches us, so we can reply). A notify or waitlist address gets one confirmation mail with a link, for that repo or for the waitlist, and nothing else until the link is clicked. After that, plain text through Resend: a notify address gets a digest when a scan finds a new exposure or a retirement is inside 30 days; a waitlist address gets one mail per retirement date inside 14 days. We never read an address from GitHub; that would be a fourth permission. Every mail carries a one-click stop link, and a stopped address never hears from us again.
Your keys
The eval runs happen in your CI with your keys. We never hold the keys that run your prompts, and the held/drifted output stays in your repo as a PR comment. The one key we do hold is our own Anthropic key, used only to draft eval cases from your code when you opt in (see “Your code”).
This site
The site runs Vercel Web Analytics: cookieless page counts, no cross-site tracking, no advertising identifiers.
Self-hosting
The whole product is a Next.js app and a Postgres; see the README. If your policy says no third-party app touches the code, run it yourself.
On uninstall
Uninstalling the app purges all stored findings immediately.
Report a vulnerability
Email security@aidep.dev.