Redacted transcripts are stored encrypted, separately for each org, and deleted after 30 days. Or keep them in your own bucket.
The GitHub App has no Contents permission. It sees what a pull request changes, and it reads your rules through GitHub's Single file permission, which covers one path.
| PERMISSION | WHAT IT READS | WHY |
|---|---|---|
| Pull requests | The PR's diff, commits and labels | read & write: to post the comment |
| Checks | Nothing: it only writes | read & write: to post the check run |
| Single file | One file, .verity/rules.yml | read: your rules |
| Metadata | Repository names and settings | read: required by GitHub |
| Members (org) | Whether you are an org owner | read: for the Settings page |
| Contents | Not requested | no access to your code |
The session comes from the capture hooks, redacted on the developer's machine, as below.
The capture worker redacts secrets as the session is saved, before anything leaves the developer's machine.
[REDACTED:high_entropy]Verity's server redacts the session again before writing it to the org's transcript store.
second pass · storedA final check runs before any model sees text. Models answer yes-or-no questions and never see the PR description.
final check · analysedServer logs hold ids, counts and error names. No log line or database column holds transcript text.
session=… steps=34| DATA | WHERE IT LIVES | KEPT FOR |
|---|---|---|
| Redacted transcripts | Verity's storage, encrypted and isolated per org, or your own S3 bucket | 30 days, or your bucket's rule |
| Reports | Verity's servers, encrypted and isolated per org. They include excerpts of flagged steps, command output and diffs | 90 days by default |
| Session index | Ids, repo, branch and times. No content | Until the reports expire |
| Model prompts | Not logged | Off by default |
Only people signed in with GitHub who can read the code repository. Access is checked against GitHub on every view, so removing someone from the repo removes their access.
Only redacted text, after the final check, and never the PR description. They answer yes-or-no questions and write the report's short summaries; the rules decide every result. Their prompts and outputs are not logged.
The GitHub login and account type (user or bot) of whoever added the override label, and when. Nothing from the session.
Capture is an org decision, and the hooks are committed to the repo so everyone can see them. For the developer, the session is evidence that their PR was done properly, which is what gets it reviewed faster.
Not today. Verity is hosted only.
Sign in with GitHub. Reports open only for people who can read the repository.