Security and data handling.
What the Veridical GitHub App can access, what a review processes and who processes it, how to remove access, and how to report a problem. This page summarizes the live app configuration, the Privacy Policy, and the published docs. The Privacy Policy and Terms of Service remain the governing documents.
GitHub App permissions.
The Veridical.dev GitHub App requests five repository permissions and no organization or account permissions. This is the set GitHub reports for the live app, checked on .
It does not request administration, Actions, secrets, workflows, deployments, environments, or organization members.
See the app on GitHub| Permission | Access | Why |
|---|---|---|
| Metadata | Read-only | Identify the installation, repositories, and pull requests in scope. |
| Pull requests | Read and write | Read the pull request and its exact base and head, then publish review comments and the review summary. |
| Checks | Read and write | Find and publish the review's neutral check run on the exact head commit. |
| Issues | Read-only | Receive maintainer commands written as pull-request comments. |
| Contents | Read and write | Read: fetch the exact base and head revisions under review. Write: publish a verified fix on its own branch and open a pull request for it, on plans that include repair. |
Why contents write exists
Write access to contents is used for one operation: publishing a verified fix as a separate branch and pull request, on plans that include repair. Launch is review-only, so Launch reviews never push code. Fix pull requests are never merged automatically, and Veridical does not merge pull requests.
Where to install it
To start reviews, create a workspace and install the app from there. An installation started on GitHub alone is not connected to a review allowance until a workspace claims it.
Webhook events.
The app subscribes to 4 events. GitHub also sends installation and repository-selection events to every app installation.
- pull_request
- Start, update, supersede, or close review work.
- issue_comment
- Accept commands, such as an additional review, from repository insiders only.
- pull_request_review_comment
- Track replies and whether a finding was acted on.
- pull_request_review_thread
- Track resolved and unresolved review threads.
What a review processes.
Only what is needed to review the exact pull-request revision and run the service. The marketing website never receives repository credentials, code, or card data.
- GitHub installation, repository, pull-request, base, and head identifiers.
- Pull-request metadata, commits, and the source files and diffs needed to review the exact base and head revisions.
- The review's own output: findings, evidence receipts, coverage, and publication state.
- Account and workspace identity from WorkOS, and plan and usage records.
- Capacity, abuse-prevention, and operational records.
Safeguards in the hosted design
- Webhook signatures are verified before any work is accepted.
- GitHub installation tokens are short-lived and scoped to the repository being reviewed.
- Review workers do not receive the GitHub App private key or standing cloud credentials.
- Secrets and secret-bearing environment variables are redacted from receipts.
- Customer views omit provider credentials, model routing, and internal cost telemetry.
These are design controls, not a certification or a guarantee. Read the data-handling docs.
Who processes it.
The providers named in the Privacy Policy. The hosted control plane is designed for Google Cloud's Warsaw region. Some providers, including Azure model processing, may process data outside Poland or the EEA under Standard Contractual Clauses or the EU-US Data Privacy Framework.
- Google Cloud Platform
- Hosted application, regional database, object storage, queues, logs, key management, and isolated review infrastructure.
- Azure OpenAI and Google Vertex AI
- Model processing for review workloads.
- GitHub
- Repository, pull-request, and delivery data for the repositories you connect.
- WorkOS
- Sign-in, identity, SSO, and directory lifecycle.
- Stripe
- Checkout, subscriptions, and payments for paid plans. Card details go to Stripe directly.
- Resend
- Transactional email for account, service, and inquiry messages.
- Google Analytics 4, Microsoft Clarity, PostHog
- Optional measurement, loaded only after you consent. PostHog event properties exclude code, finding text, email addresses, and authentication tokens.
Retention.
As set out in the Privacy Policy. Security, fraud, billing, and audit records may have a separate legal retention basis.
- Review records and source-derived artifacts
- Kept under the workspace retention policy, subject to legal hold, security investigation, backup, and billing-integrity exceptions.
- Server and request logs
- Up to 90 days, then deleted or aggregated.
- Email correspondence
- Up to 24 months, then deleted when no longer needed.
- Billing and tax records
- For the period accounting, tax, fraud-prevention, and legal obligations require.
- Account and membership mappings
- While the workspace is active, and for the limited period needed for security, disputes, and legal obligations after closure.
Remove access.
Uninstalling the app, or removing a repository from it, stops new review work for that scope. Comments and checks already posted stay on GitHub, under your repository's controls.
- Personal account
- Settings → Applications → Installed GitHub Apps → Configure next to Veridical.dev → Uninstall.
- Organization
- Your organizations → Settings → GitHub Apps (under Third-party Access) → Configure next to Veridical.dev → Uninstall.
The same Configure page lets you narrow repository access instead of uninstalling. If you also authorized the app on your personal account, you can revoke that under Authorized GitHub Apps. To delete account or review data, email contact@veridical.dev with the installation and repository identifiers needed to find the records.
Report a security issue.
Email contact@veridical.dev with a description of the issue, the steps to reproduce it, and only the identifiers needed to locate it. Never send tokens, private keys, private source code, or unredacted evidence by email.
The same contact is published in /.well-known/security.txt.