Security

Your code stays yours

A security tool reads your most sensitive asset. Here is exactly how OpenRouting handles it.

$ openrouting sandbox --inspect
✓ network none
✓ repo mount read-only
✓ user non-root, capabilities dropped
✓ your code never built or run
✓ secrets masked before AI review
clone deleted after the scan
$ 

Your code is never run

OpenRouting reads source code. It never installs dependencies, builds your project, or runs scripts from it.

Scanners have no network

Every scan runs in a fresh container with networking disabled, privileges dropped, a read-only mount, and CPU, memory, and time limits.

One scan, one repository

Scanners get a read-only view of a single scan's folder, so no scan can reach another customer's code.

Secrets masked before AI

Keys, tokens, and passwords are replaced before any code is sent to the review model.

Clones deleted after scans

OpenRouting keeps the few flagged lines it shows you, not a copy of your repository. The clone is removed when the scan finishes.

Private, isolated workspaces

Every account gets its own workspace, and every request is scoped to it. GitHub tokens are encrypted at rest and never returned to the browser.

Clone hardening

  • Clones are restricted to HTTPS on allow-listed hosts, blocking local-file, SSH, and SSRF-style URLs.
  • Git is hardened against hostile repositories: system and global config ignored, hooks, filters, and credential helpers neutralized, submodules never recursed, and symlinks flattened.
  • A clone-size cap guards against clone and zip bombs.
  • Interrupted scans are marked failed and their credits refunded, not left stuck or silently retried.

Security questions

Does OpenRouting execute my code?

No. It clones and reads your code. It never builds or runs it, and scanners run in network-isolated containers.

Is my source code stored?

The clone is deleted after each scan. Only the flagged lines of each finding are kept so you can review them.

What does the AI model see?

Only the lines around a finding, with secrets redacted first. Review runs on Amazon Bedrock. Your whole repository is never sent.

How are GitHub credentials protected?

Access tokens are encrypted at rest, never returned to the browser, and injected only at clone time via a header that's kept out of logs and process arguments.