Security and data handling.

What the Veridical GitHub App can access, what a review processes and who processes it, how to remove access, and how to report a problem. This page summarizes the live app configuration, the Privacy Policy, and the published docs. The Privacy Policy and Terms of Service remain the governing documents.

GitHub App permissions.

The Veridical.dev GitHub App requests five repository permissions and no organization or account permissions. This is the set GitHub reports for the live app, checked on .

It does not request administration, Actions, secrets, workflows, deployments, environments, or organization members.

See the app on GitHub
PermissionAccessWhy
MetadataRead-onlyIdentify the installation, repositories, and pull requests in scope.
Pull requestsRead and writeRead the pull request and its exact base and head, then publish review comments and the review summary.
ChecksRead and writeFind and publish the review's neutral check run on the exact head commit.
IssuesRead-onlyReceive maintainer commands written as pull-request comments.
ContentsRead and writeRead: fetch the exact base and head revisions under review. Write: publish a verified fix on its own branch and open a pull request for it, on plans that include repair.

Why contents write exists

Write access to contents is used for one operation: publishing a verified fix as a separate branch and pull request, on plans that include repair. Launch is review-only, so Launch reviews never push code. Fix pull requests are never merged automatically, and Veridical does not merge pull requests.

Where to install it

To start reviews, create a workspace and install the app from there. An installation started on GitHub alone is not connected to a review allowance until a workspace claims it.

Webhook events.

The app subscribes to 4 events. GitHub also sends installation and repository-selection events to every app installation.

pull_request
Start, update, supersede, or close review work.
issue_comment
Accept commands, such as an additional review, from repository insiders only.
pull_request_review_comment
Track replies and whether a finding was acted on.
pull_request_review_thread
Track resolved and unresolved review threads.

What a review processes.

Only what is needed to review the exact pull-request revision and run the service. The marketing website never receives repository credentials, code, or card data.

  • GitHub installation, repository, pull-request, base, and head identifiers.
  • Pull-request metadata, commits, and the source files and diffs needed to review the exact base and head revisions.
  • The review's own output: findings, evidence receipts, coverage, and publication state.
  • Account and workspace identity from WorkOS, and plan and usage records.
  • Capacity, abuse-prevention, and operational records.

Safeguards in the hosted design

  • Webhook signatures are verified before any work is accepted.
  • GitHub installation tokens are short-lived and scoped to the repository being reviewed.
  • Review workers do not receive the GitHub App private key or standing cloud credentials.
  • Secrets and secret-bearing environment variables are redacted from receipts.
  • Customer views omit provider credentials, model routing, and internal cost telemetry.

These are design controls, not a certification or a guarantee. Read the data-handling docs.

Who processes it.

The providers named in the Privacy Policy. The hosted control plane is designed for Google Cloud's Warsaw region. Some providers, including Azure model processing, may process data outside Poland or the EEA under Standard Contractual Clauses or the EU-US Data Privacy Framework.

Google Cloud Platform
Hosted application, regional database, object storage, queues, logs, key management, and isolated review infrastructure.
Azure OpenAI and Google Vertex AI
Model processing for review workloads.
GitHub
Repository, pull-request, and delivery data for the repositories you connect.
WorkOS
Sign-in, identity, SSO, and directory lifecycle.
Stripe
Checkout, subscriptions, and payments for paid plans. Card details go to Stripe directly.
Resend
Transactional email for account, service, and inquiry messages.
Google Analytics 4, Microsoft Clarity, PostHog
Optional measurement, loaded only after you consent. PostHog event properties exclude code, finding text, email addresses, and authentication tokens.

Retention.

As set out in the Privacy Policy. Security, fraud, billing, and audit records may have a separate legal retention basis.

Review records and source-derived artifacts
Kept under the workspace retention policy, subject to legal hold, security investigation, backup, and billing-integrity exceptions.
Server and request logs
Up to 90 days, then deleted or aggregated.
Email correspondence
Up to 24 months, then deleted when no longer needed.
Billing and tax records
For the period accounting, tax, fraud-prevention, and legal obligations require.
Account and membership mappings
While the workspace is active, and for the limited period needed for security, disputes, and legal obligations after closure.

Remove access.

Uninstalling the app, or removing a repository from it, stops new review work for that scope. Comments and checks already posted stay on GitHub, under your repository's controls.

Personal account
Settings → Applications → Installed GitHub Apps → Configure next to Veridical.dev → Uninstall.
Organization
Your organizations → Settings → GitHub Apps (under Third-party Access) → Configure next to Veridical.dev → Uninstall.

The same Configure page lets you narrow repository access instead of uninstalling. If you also authorized the app on your personal account, you can revoke that under Authorized GitHub Apps. To delete account or review data, email contact@veridical.dev with the installation and repository identifiers needed to find the records.

Report a security issue.

Email contact@veridical.dev with a description of the issue, the steps to reproduce it, and only the identifiers needed to locate it. Never send tokens, private keys, private source code, or unredacted evidence by email.

The same contact is published in /.well-known/security.txt.