The review exists only for the duration of the review.
codecr receives only the pull-request objects required to evaluate the authorized change. Source files, diffs, embeddings, retrieved context, and model prompt payloads are excluded from persistent application storage and are not used to train shared or cross-tenant models.
The analysis workspace is terminated on successful completion, failure, cancellation, or timeout. Process memory and the in-memory workspace are released with the sandbox; no recoverable application copy is intentionally retained by codecr.
- Decision and policy identifiers
- Severity and gate outcome
- Content hashes and timestamps
- Named reviewer and approval actions