Security
Boundaries are part of the review.
Access boundaries
Sign-in is handled by WorkOS AuthKit. Workspace access, review visibility, approval policy, and billing actions are checked on the server. GitHub and Slack credentials are used through their integration boundaries, and review approval remains an explicit human action.
Review and billing controls
Review requests are restricted by configured workspace and repository policy. Evidence is scoped to the reviewed commit. Approval and billing state are recorded as separate events, and credit is added only after a confirmed payment event. Prepaid AI calls reserve credit before they start; uncertain provider usage remains held until an operator reconciles it.
Responsible disclosure
If you find a security issue during the beta, use the support path on the support page or email the beta owner at manthan@ludicrous.io. Include the affected workflow, a safe reproduction, and whether any account or repository access was involved. Please do not include credentials or private tokens in the request.