Security · Data handling
What happens to your code during a scan
No marketing language. This is the actual sequence, so you can judge it yourself.
1. Clone
The branch you chose is cloned into a temporary directory on our server in Frankfurt, using the token you provided. Nothing is written to a database at this point.
2. Parse, without AI
Routes, database models, dependencies, scripts and environment variable names are extracted by static analysis. Values of secrets are not read; .env files are ignored.
3. Document each endpoint, with AI
For each endpoint, an AI model is given the handler and the files it calls, and returns a structured description: purpose, rules, steps, data access, errors. Only the files relevant to that endpoint are sent, over TLS, to the model provider. The provider does not use API data for training.
4. Verify
Every file path the description cites is checked against the clone. Claims that cannot be tied to a real file lose their citation or are dropped.
5. Store the documentation, delete the code
The generated documentation, diagrams and structural metadata are saved. The temporary directory with your code is deleted, whether the scan succeeded, failed or was cancelled.
What the stored documentation contains
- Endpoint paths, methods and parameter names.
- Plain-language descriptions of behaviour and business rules.
- Names of files and functions where a step is implemented, without their contents.
- Table and field names, and which endpoints read or write them.
- Short code-like examples only where the documentation needs one, such as a sample request body.
Deleting data
- Delete a project: its scans, endpoints, diagrams, documentation and repository token are removed.
- Delete your account: all projects you own are removed the same way.
- Documentation synced to your Notion or Confluence stays there, under your control.
Questions
- Is the whole repository sent to the AI?
- No. Each endpoint is documented separately and only the files on its call path are sent.
- Do you log prompts or code?
- Application logs record what was done (which endpoint, how many files, token counts), not file contents.
- Can we avoid sending code to your AI provider account at all?
- Yes, on Enterprise: use your own provider key or self-host. See the enterprise deployment page.
Try it on your own repository
Connect a repo, run one scan, and read what each endpoint does. Starter is free. Pro has a 14-day free trial.