Security: where your code goes | Nurbak

Nurbak Security

Your code, accounted for

An AI pentester has to read your code. Here is exactly where it goes, what the GitHub App can do, what we keep and how you can prove it.

Where your code goes

Nurbak reads your repository through the GitHub App, analyzes it on infrastructure that exists only for the scan and deletes it when the scan ends. The AI review runs on Whitehat, our own self-hosted model.

1

Read through the GitHub App

Nurbak only reaches the repositories you grant to the Nurbak GitHub App when you install it. Public or private, you choose.

2

Analyzed on ephemeral GPUs, with our own model

The scan runs on ephemeral GPU infrastructure with Whitehat, Nurbak's self-hosted model, plus deterministic checks. During the scan your code is never sent to OpenAI, Anthropic or any other third-party AI.

3

Deleted after the scan

When the scan ends, the code is deleted. What stays is the report: the score and the findings.

GitHub App permissions

Read access to code

Needed to analyze the repository. It covers only the repositories you select when installing the app.

Contents and Pull requests (write)

Used only to open a fix Pull Request when you ask for one from a finding. Nurbak does not merge anything: you review the PR and decide.

Revocable at any time

Disconnect GitHub from your profile page and the Nurbak GitHub App access is uninstalled. From then on Nurbak cannot read your repositories or open Pull Requests.

What never happens

The strongest privacy promise is the data that never leaves.

No third-party AI during the scan

The AI review runs on Whitehat, our own model. Your code is not sent to OpenAI, Anthropic or other third-party AIs while it is scanned.

Only package names leave

The dependency audit checks OSV.dev with the package name and version. Your source code is never part of that request.

No changes without you

Nurbak never opens a Pull Request on its own. Generating a fix is opt-in: the confirmation tells you which file is sent and to which AI model, and the request is recorded in your audit trail.

Audit trail and stored data

Downloadable audit trail

Every scan comes with a JSON log of every AI interaction: what was sent, to which model and when. Hand it to your security team or an auditor as proof of where your code went.

What we store

The scan results (score and findings with severity, CWE, file, line, description and recommendation) and your account data. Not your code.

What we delete

The copy of your code used for the scan is deleted when the scan ends, together with the ephemeral infrastructure that ran it.

Security FAQ

Is my code sent to OpenAI, Anthropic or other AI providers?

Not during the scan. The AI review runs on Whitehat, Nurbak's self-hosted model. The only exception is optional: when you ask for a fix Pull Request, the confirmation tells you which file is sent to generate the fix and to which AI model, and nothing is sent until you confirm. The rest of your code does not leave, and the request is recorded in your audit trail.

Does Nurbak keep a copy of my code?

No. The code is deleted when the scan ends. We keep the report (score and findings with severity, CWE, file, line, description and recommendation) and your account data.

Why does the GitHub App ask for write permission?

Contents and Pull requests write access is used only to open a fix Pull Request when you ask for one. Nurbak does not merge anything and does not open Pull Requests on its own.

How can I prove my code did not leave?

Download the audit trail of the scan. It is a JSON log of every AI interaction: what was sent, to which model and when.

How do I revoke Nurbak's access?

Disconnect GitHub from your profile page. That uninstalls the Nurbak GitHub App access, so Nurbak can no longer read your repositories or open Pull Requests.

Find the vulnerabilities in your code before an attacker does

Connect GitHub and Nurbak analyzes your repo with its own AI: exploitable vulnerabilities with file and line, and the fix ready as a Pull Request.

Your code never goes to OpenAI or Anthropic. No credit card.