SECURITY

Redacted twice before anything is stored.

Redacted transcripts are stored encrypted, separately for each org, and deleted after 30 days. Or keep them in your own bucket.

WHAT VERITY READS

The PR's diff, one file, and the session. Not your codebase.

The GitHub App has no Contents permission. It sees what a pull request changes, and it reads your rules through GitHub's Single file permission, which covers one path.

PERMISSIONWHAT IT READSWHY
Pull requestsThe PR's diff, commits and labelsread & write: to post the comment
ChecksNothing: it only writesread & write: to post the check run
Single fileOne file, .verity/rules.ymlread: your rules
MetadataRepository names and settingsread: required by GitHub
Members (org)Whether you are an org ownerread: for the Settings page
ContentsNot requestedno access to your code

The session comes from the capture hooks, redacted on the developer's machine, as below.

REDACTION

Secrets are removed before anything leaves the laptop.

ON THE LAPTOP

Before upload

The capture worker redacts secrets as the session is saved, before anything leaves the developer's machine.

[REDACTED:high_entropy]
ON UPLOAD

Before storage

Verity's server redacts the session again before writing it to the org's transcript store.

second pass · stored
BEFORE ANY MODEL

Before analysis

A final check runs before any model sees text. Models answer yes-or-no questions and never see the PR description.

final check · analysed
IN LOGS

Never logged

Server logs hold ids, counts and error names. No log line or database column holds transcript text.

session=… steps=34
RETENTION

What is kept, where, and for how long.

DATAWHERE IT LIVESKEPT FOR
Redacted transcriptsVerity's storage, encrypted and isolated per org, or your own S3 bucket30 days, or your bucket's rule
ReportsVerity's servers, encrypted and isolated per org. They include excerpts of flagged steps, command output and diffs90 days by default
Session indexIds, repo, branch and times. No contentUntil the reports expire
Model promptsNot loggedOff by default
FAQ

Questions security teams ask.

Who can see a report?

Only people signed in with GitHub who can read the code repository. Access is checked against GitHub on every view, so removing someone from the repo removes their access.

What do models see?

Only redacted text, after the final check, and never the PR description. They answer yes-or-no questions and write the report's short summaries; the rules decide every result. Their prompts and outputs are not logged.

What does Verity record about overrides?

The GitHub login and account type (user or bot) of whoever added the override label, and when. Nothing from the session.

Can developers opt out of capture?

Capture is an org decision, and the hooks are committed to the repo so everyone can see them. For the developer, the session is evidence that their PR was done properly, which is what gets it reviewed faster.

Can we self-host?

Not today. Verity is hosted only.

See what your agents actually did.

Sign in with GitHub. Reports open only for people who can read the repository.