Frequently asked questions.
Six questions engineering, security, and IT teams ask before installing the GitHub App.
Frequently asked questions
What permissions does the GitHub App request, and why?
Read access to PRs and the diff (per-PUSH scanning is what makes the review always-on). Write access limited to PR status checks and the inline-comment thread — used to post review findings, nothing else. Metadata read for the repo picker at install time. No contents write on the repo, no admin or org scopes, no push, no merge keys. Manage and revoke the install from /app/repos; the per-repo-first install flow is the default.How do you handle private-repo data?
The diff and the surrounding context needed to score findings are processed and then dropped from the inference path; nothing is used to train models and nothing is persisted long-term beyond the findings record. Findings-tagged secrets are stripped before any logging, and the audit log export on Team and Enterprise shows exactly what was read and when — see the plans or the audit dashboard once you are installed.What scan types run, and what is covered?
OWASP ASVS-aligned SAST, dependency / SCA, secrets detection, and infra-as-code checks — CWE-tagged on every finding so you can map a hit back to a control. Scope is tuned for noise (no "everything, always" by default). Compare to a per-PR AI reviewer side by side in our CodeRabbit comparison — the coverage model is a different surface area, not just a different UI.How is the regression baseline set and updated?
Pinned to the branch you choose at install (mainby default). Every subsequent push is re-scored against that baseline — anything that was already "known" stays out of your inbox; only net-new findings surface. Refresh the baseline from /app/baseline (or per-repo in /app/repos) when you intentionally close out findings; nothing auto-resets without you.Can the Slack digest be customized?
Channel per repo, severity threshold (so noise stays out), and per-repo on / off from /app/repos. One end-of-day rollup is the default — a single message open findings, regressions, and stalled PRs — calibrated per channel so a low-trafficinfraroom does not get the same volume asfrontend.SOC2 / audit export?
SOC2 Type II is in progress; the controls list and current status letter live on the trust page. The audit export itself is shipped today: CSV / JSON download from /app/audit, time-windowed, scoped to your install. Enterprise request flow for formal SOC2 artefact exchange goes through /contact.
Read access to PRs and the diff (per-PUSH scanning is what makes the review always-on). Write access limited to PR status checks and the inline-comment thread — used to post review findings, nothing else. Metadata read for the repo picker at install time. No contents write on the repo, no admin or org scopes, no push, no merge keys. Manage and revoke the install from /app/repos; the per-repo-first install flow is the default.
