ZERO-TRUST EXECUTION MODEL

Your source code
is not our data.

Every review is a bounded computation inside an explicit trust boundary. codecr minimizes what enters, isolates what runs, records only contracted evidence, and destroys the analysis workspace when the job closes.

RETENTIONZero source retention
EXECUTIONEphemeral sandbox
MODEL USENo shared training
PR DATA LIFECYCLEZERO-RETENTION MODE
  1. 01
    Minimized ingestRequired PR objects only
    T+00:00
  2. 02
    Analyze in memoryIsolated execution workspace
    ACTIVE
  3. 03
    Destroy workspaceCompletion, failure, or timeout
    TERMINATE
  4. 04
    Return decision evidencePolicy result, hashes, timestamps
    NO SOURCE
Source · diff · embeddings · prompt payloadsEXCLUDED FROM PERSISTENT APPLICATION STORAGE

[ 01 / ZERO DATA RETENTION ]

An execution property.
Not a marketing promise.

Zero-retention mode is defined by the deployed data flow, storage controls, model route, observability configuration, and signed customer terms—not by a global toggle with undocumented exceptions.

ZR-01 / SOURCE MATERIAL

The review exists only for the duration of the review.

codecr receives only the pull-request objects required to evaluate the authorized change. Source files, diffs, embeddings, retrieved context, and model prompt payloads are excluded from persistent application storage and are not used to train shared or cross-tenant models.

The analysis workspace is terminated on successful completion, failure, cancellation, or timeout. Process memory and the in-memory workspace are released with the sandbox; no recoverable application copy is intentionally retained by codecr.

CONTRACTED EVIDENCE MAY INCLUDE
  • Decision and policy identifiers
  • Severity and gate outcome
  • Content hashes and timestamps
  • Named reviewer and approval actions

[ 02 / EPHEMERAL SANDBOXING ]

Every PR gets a sealed room.

Analysis runs in a short-lived, workload-isolated sandbox with a unique job identity, least-privilege repository scope, explicit egress policy, and a hard termination condition.

EPHEMERAL TRUST BOUNDARYjob_8421_9f3ac2e
01

Authorize

Issue a single-job identity limited to approved repositories, refs, and policy packs.

02

Mount in RAM

Place required PR material into an in-memory workspace; persistent volumes are not attached.

03

Analyze

Run model and policy calls through the approved route with bounded network egress.

04

Terminate

Revoke job credentials, close model sessions, release memory, and emit source-free evidence.

UNIQUE WORKLOAD IDENTITYNO SHARED WORKSPACEEGRESS ALLOWLISTHARD TIMEOUTAUDITABLE TERMINATION

[ 03 / CLOUD, VPC & ON-PREM ]

Same control engine.
Different data authority.

The deployment decision determines who operates the execution plane, where source and inference run, which keys authorize access, and how compliance evidence is produced.

DEDICATED CLOUDcodecr-operated execution plane

For approved vendor-operated processing.

A logically isolated enterprise environment runs within the codecr-managed cloud boundary. Zero-retention analysis, tenant-scoped encryption, network segmentation, isolated job sandboxes, and controlled support access are applied according to the executed security schedule.

  • Fastest managed activation and continuous updates
  • Customer-approved region and retention profile
  • Centralized operational evidence and incident response
COMPLIANCE SCOPE

SOC 2 control coverage and report availability must be confirmed in the applicable order documents. HIPAA workloads are accepted only under an executed Business Associate Agreement and an approved configuration; the platform alone does not make a customer HIPAA compliant.

VPC / ON-PREM / AIR-GAPPEDcustomer-operated data plane

For workloads that cannot enter a vendor data plane.

Source retrieval, context indexing, inference, and evidence storage can execute inside the customer boundary. The codecr control plane exchanges only the contract-approved control metadata required for licensing, policy distribution, or support—or exchanges nothing in an air-gapped deployment.

  • VPC peering uses private routes and customer security groups
  • On-prem connectivity can use an outbound-initiated, mutually authenticated tunnel with no public source transit
  • Air-gapped estates receive signed offline policy and release bundles
CUSTOMER AUTHORITY

The customer governs network access, keys, model endpoints, retention, backups, SIEM export, and administrator identity. codecr supplies deployment evidence; the customer retains responsibility for its infrastructure and regulatory configuration.

Control planeDedicated CloudVPC / On-Prem
Source executionDedicated codecr-managed tenantCustomer network or data center
Inference routeApproved private model endpointCustomer-selected local or private endpoint
Key authorityTenant-scoped managed keys or contracted customer key integrationCustomer KMS or HSM
Network pathRestricted service network with controlled egressPrivate peering, outbound mTLS tunnel, or no network route
Operational telemetrySource-free service telemetry under contractCustomer-controlled; optional or fully local

[ 04 / ENTERPRISE TRUST CENTER ]

One diligence room.
Every control artifact.

The Trust Center preview organizes assurance reports, contractual terms, deployment evidence, and continuous-control telemetry without overstating their status. Every badge resolves to an owner, scope, evidence object, review date, and publication rule.

TRUST CENTER / PROCUREMENT PREVIEW EVIDENCE-GATED STATUS
EVIDENCE REQUIRED
ASSURANCE REPORT

SOC 2 Type II

Independent report, system scope, review period, auditor identity, and exception status must be confirmed before access is marked available.

Portal state · report not attached
CERTIFICATE REQUIRED
ISMS CERTIFICATION

ISO/IEC 27001

Certificate number, certification body, validity dates, statement of applicability, and organizational scope must be attached.

Portal state · scope not verified
EXECUTION REQUIRED
DATA TERMS

HIPAA DPA / BAA

The DPA defines processing terms; applicable protected-health-information workloads require a separately executed Business Associate Agreement and approved configuration.

Portal state · customer-specific terms
TARGET MAPPING
FEDERAL READINESS

FedRAMP Moderate Readiness

Moderate control mapping and readiness work do not constitute a FedRAMP Marketplace designation, agency authorization, or government approval.

Portal state · no designation claimed
AUTOMATED VENDOR SECURITY ASSESSMENT RFP-READY TEMPLATE

Give Procurement a structured answer set—not another email chain.

Download the machine-readable questionnaire package covering data flows, encryption, access control, secure development, incident response, business continuity, subprocessors, evidence requests, and deployment-specific exceptions.

  • 01Claim and evidence status fields
  • 02Customer security-questionnaire intake
  • 03RFP control ownership and exception register
  • 04DPA, BAA, and deployment-term request map
Download Automated Security Questionnaire / RFP Package This downloadable template records evidence requirements; it does not assert that missing assurance documents exist.
CONTINUOUS MONITORING TELEMETRY SYNTHETIC PREVIEW

Live security status model

Sample values demonstrate the portal state model. Production values appear only after verified monitors and evidence feeds are connected.

Active critical CVEsKnown exploitable vulnerability feed

0 · SAMPLE

SLA window attainmentIllustrative rolling 30-day window

100.000% · SAMPLE

KMS key rotationCustomer-approved rotation policy

ACTIVE · SAMPLE

Last evidence sealSigned control snapshot

14m AGO · SAMPLE
CRIMSON ESCALATION THRESHOLDS
P0 CVEs> 0
SLA attainment< 99.95%
KMS key age> 90 days
Evidence feed> 60 min stale
PORTAL ACCESS MODELNamed reviewers · time-bound access · document watermarking · download audit

[ ENTERPRISE PRODUCTION DECISION ]

Put the architecture, evidence, and commercial decision in one room.

Review the VPC boundary with Engineering, open the controlled evidence room with Security, and give Procurement the exact terms and unresolved gates required for approval.

Schedule Executive VPC Demo
Executive architecture reviewEvidence-room accessDPA / BAA scopingProduction acceptance record
CONTROLLED TRUST CENTER ACCESS

Request the evidence room and data terms

Use this request to identify the artifacts, confidentiality terms, DPA, and—where applicable—Business Associate Agreement required for your diligence review.

01Assurance evidenceCurrent reports, certificate scope, testing summaries, and remediation status.
02Data-processing termsDPA, subprocessor schedule, retention profile, and regional processing boundaries.
03Architecture evidenceData flows, control ownership, KMS design, network paths, and incident escalation.