Skip to main content

Source handling and confidentiality

Where your code goes, and what is retained

A source-code review requires content from the agreed scope to be processed by the disclosed model providers. This page explains that flow, the temporary review environment and what remains after the engagement.

What is sent to model providers

Source-code content from the agreed review scope is transmitted to the disclosed model providers as required to perform the two independent reviews.

Before a run, we confirm the repository, exact commit, review configuration and provider arrangements with you.

LAN10 does not send customer source code to undisclosed model providers and does not use customer source code for its own training, benchmarking or product improvement.

Repository access

Read access to the agreed repository is sufficient. Git credentials are used to clone the agreed repository and are not included in model prompts or retained in findings or reports.

The ephemeral run container receives the credentials required to perform the engagement for the duration of the run.

Reviewer independence is maintained by information-flow separation: neither review stream receives the other reviewer’s prompts, progress, output or conclusions.

Where source lives during a review

Source is cloned into an ephemeral run container at the exact commit agreed for the review. It remains on that container’s temporary filesystem for the duration of the run.

At the end of the run, the container and its temporary filesystem are removed. The full cloned repository is not retained by LAN10.

This provides temporary filesystem handling and cleanup. It is not described as an enforced network boundary.

What is retained afterwards

LAN10 retains the review record required to deliver and evidence the engagement. This includes candidate findings, any source-code excerpts contained in those findings, human decisions and rationale, the exact commit SHA, recorded coverage and limitations, and the final report.

The full cloned repository is not retained.

Retention and deletion terms for the review record are agreed in writing before the engagement.

Model-provider processing

Processing and retention by each model provider are governed by the terms applicable to the endpoint and account arrangement used for the engagement.

Before a run, LAN10 identifies the providers and relevant account arrangements so that the applicable terms can be reviewed.

LAN10 does not characterise a provider’s retention behaviour as stricter than its published or contracted terms state.

Report and finding provenance

Each finding records which review stream reported it and retains the underlying reviewer material alongside the consolidated record.

The report records the exact commit reviewed, the coverage achieved, any limitations and the human decision behind every candidate finding.

Technology-provider disclosure

The current independent review streams use OpenAI Codex Security and Anthropic Claude. LAN10 operates the engagement scope, consolidation rules, human decisions and final report.

Plain-language summary

Your source code was reviewed at one exact commit inside an ephemeral run container created for that review. Source-code content from the agreed scope was processed by the disclosed model providers under their applicable terms. LAN10 retained the findings, any source excerpts they contain, the human decision record, the review metadata and the final report. The full cloned repository was not retained.