Skip to main content

Understand what happens to your code

This is a practical overview of Yanib’s access and processing boundaries. It is not a certification, security-audit report, or contractual guarantee.

Repository access
GitHub sign-in and GitHub App access are separate. Connect only authorized repositories; organization installation approval may be required.
Cross-repository scope
Choose connected targets for each source repository. Directional selection allows analysis, but a finding still requires evidence. Other repositories are not automatically included because they share an organization.
Publication
Analysis, GitHub review posting, docs pull requests, and downstream issues have independent controls. Private consumer details are subject to audience checks before they can appear in another repository.
Source processing
Indexing and review read source files and diffs, not just metadata. Derived indexes, bounded excerpts, findings, and delivery records are stored to provide the service.
Model processing
Enabled model-backed features can send diffs and bounded dependency evidence to Anthropic. AI features use Yanib’s platform account. Provider terms apply separately.
Disconnect and retention
Disconnect and revocation trigger durable removal workflows with retries. This is not immediate erasure from every system, backup, or external destination. Already published GitHub content remains subject to GitHub’s controls.

Have specific security requirements?

Before connecting sensitive repositories, ask us to confirm applicable processor agreements, hosting regions, backup and deletion schedules, and your organization’s access requirements. Yanib does not offer a general zero-retention or regional-processing guarantee.

Engineering description reviewed September 4, 2026. Operational assurances must be confirmed for your evaluation; this page does not claim legal approval.