Trust boundary
Source code is not uploaded by design.
The CLI runs analysis locally or in CI, then uploads generated reports and metadata for dashboard review.
- Uploaded bundles include manifests, repository identity, branch and commit SHA, tool reports, summaries, findings, recommendations, scores, and evidence fields.
- Reports may include paths, filenames, package names, dependency names, platform readiness details, tool versions, schema versions, and release metadata.
- Original audit bundles are retained in `audit-bundles`; parsed technical report data is retained for report detail, retry, and read workflows.
- A separate strict/privacy mode is not implemented in the current service.