Your code is never run
OpenRouting reads source code. It never installs dependencies, builds your project, or runs scripts from it.
Security
A security tool reads your most sensitive asset. Here is exactly how OpenRouting handles it.
$ openrouting sandbox --inspect ✓ network ✓ repo mount ✓ user ✓ your code ✓ secrets clone deleted after the scan $
OpenRouting reads source code. It never installs dependencies, builds your project, or runs scripts from it.
Every scan runs in a fresh container with networking disabled, privileges dropped, a read-only mount, and CPU, memory, and time limits.
Scanners get a read-only view of a single scan's folder, so no scan can reach another customer's code.
Keys, tokens, and passwords are replaced before any code is sent to the review model.
OpenRouting keeps the few flagged lines it shows you, not a copy of your repository. The clone is removed when the scan finishes.
Every account gets its own workspace, and every request is scoped to it. GitHub tokens are encrypted at rest and never returned to the browser.
No. It clones and reads your code. It never builds or runs it, and scanners run in network-isolated containers.
The clone is deleted after each scan. Only the flagged lines of each finding are kept so you can review them.
Only the lines around a finding, with secrets redacted first. Review runs on Amazon Bedrock. Your whole repository is never sent.
Access tokens are encrypted at rest, never returned to the browser, and injected only at clone time via a header that's kept out of logs and process arguments.