CodLab / SECURITYSOFTWARE / HUMAN CONTEXT

ACCESS / EVIDENCE / BOUNDARIES

Trust begins
with clear boundaries.

Understand how CodLab handles access, review inputs, evidence and approved fixes. This page describes the hosted public reviewer and connected workspace. A separate enterprise agreement must define any private deployment, service level, or additional assurance.

Two monochrome source fields remain separated by a clear structural boundary.

A conceptual map of the review workflow.

Conceptual boundary · confirm the controls and limits below.

CHOOSE YOUR SCOPE

Three distinct access boundaries.

Public review

Only public GitHub repositories. CodLab checks repository visibility before fetching the diff. Analysis covers up to 30 changed files, with per-patch and model-input limits.

No customer GitHub token is requested. Anonymous reviews cannot publish patches.

Connected workspace

The GitHub App accesses selected installed repositories. Private review access requires current repository authorization and workspace membership.

Fix publishing requires an owner or administrator, current access, explicit patch approval, and GitHub write permission.

Enterprise requirements

Configured identity connections, larger review capacity, and procurement requirements are assessed separately. SSO configuration does not automatically grant repository access.

Private VPC, air-gapped deployment, residency, SCIM, and support SLAs are not included in the self-service workspace plans.

ENTERPRISE CONTROLS IN THE WORKSPACE

Policy and approval
at the point of action.

Controls operate on authorized repositories and current workspace roles. GitHub branch protection and required checks remain part of your repository's merge process.

Roles and access
Owner, administrator, and member roles. Fix publication requires an owner or administrator and a fresh repository access check.
Organization policies
Automatic review, AI use, minimum severity, and file budgets. Preview proposed policy settings before saving. Updates use version checks to avoid silently overwriting concurrent changes.
Approval before publication
Approval records the patch hash, reviewed commit, and publication choice. Stale or changed proposals cannot use an earlier approval.
Searchable audit history
Administrators can search current authorized events and page through a fixed snapshot. JSON exports contain one page of up to 200 matching events, with a cursor for more. Source, patches, and feedback reasons are excluded.
Identity connections
Organization SSO connections require provisioning and verification before use. A matching company domain alone does not create a connection or grant access.

SECURITY AND BLAST RADIUS

Show the finding.
Show the limits.

Inspect the code relationships supported by the reviewed source. Runtime reachability, deployment exposure and uninspected dependencies remain questions for validation.

A particle network highlights a bounded source path and dashed scope boundary, with unknown connections outside it.

A conceptual map of the review workflow.

Conceptual illustration · bounded code relationships; runtime exposure needs verification.

Observed

Changed paths, line counts, source-pattern matches, and matching evidence at the reviewed commit. A matched source pattern is not proof that an attacker can reach it.

Inferred

Possible attack paths and implications grounded in supplied evidence. These need validation against actual callers, permissions, configuration, and runtime behavior.

Proposed

Hardening steps and generated patches. CodLab's fix generator does not execute repository tests. Read the diff and validate the resulting revision before merging.

Blast-radius analysis combines changed-code inventory with bounded JavaScript and TypeScript imports, call references, and test links at the reviewed commit. This is a partial static graph. It does not establish runtime reachability, deployment exposure, or complete dependency coverage. Missing, excluded, unsupported, or truncated files remain visible limitations.

DATA AND PROCESSING

What enters the workflow.

Review inputs
Selected GitHub PR metadata and bounded diff text. Static repository context reads up to 24 authorized JavaScript or TypeScript files, at most 384 KiB total, and verifies each Git blob. Full static context files stay in Worker memory; reports retain selected evidence lines and paths. Supporting excerpts are excluded from AI by default. A current repository owner/admin must explicitly opt in, and the operator gate must be enabled, before bounded adjacent helper, guard and test excerpts from the immutable reviewed commit can be sent to Workers AI. The entire repository is not sent. When AI is enabled, bounded changed patches are processed through Cloudflare Workers AI. Organization policy can disable AI review. Pattern-based credential minimization omits matching changed-code hunks before AI analysis and masks matching finding text before persistence or publication; it does not detect every possible secret.
Stored workspace evidence
Connected reviews retain metadata, findings, source excerpts, and structured reports for workspace use. Do not assume zero source retention. GitHub comments may also contain excerpts and follow GitHub's retention controls.
Proposed fixes
Generated proposals include old and proposed file content. They expire after one hour; scheduled cleanup clears retained proposal content after 24 hours except while publication is pending or running. Minimal lifecycle metadata remains.
Permissions
The GitHub App reads selected repository content and review/check data. Publishing approved fixes needs Contents: read/write and pull-request permission. Installing it does not authorize unapproved patch publication.
Evidence retention
Administrators can configure 30–3,650 days, preview eligible report snapshots, finalized recovery payloads and terminal fix payloads, and explicitly confirm deletion. Configuration alone does not schedule deletion. This control preserves findings, feedback, audit, billing, authentication, and active work. Incomplete publication payloads remain recoverable; successful publication clears its journal payload atomically. Provider-managed copies and backups are separate.
CI evidence
After publication, CodLab can record check names, states, durations, and the exact candidate commit from GitHub. It does not execute repository commands or retain raw CI logs. Missing or skipped checks cannot establish passing validation.
Deletion and questions
Contact privacy@codlab.app about stored account or review information. Uninstalling the GitHub App removes future access; it does not by itself promise deletion of previously stored records.

ASSURANCE

Ask for evidence
before procurement.

This page does not claim SOC 2 or ISO certification, HIPAA compliance, or FedRAMP authorization. Confirm any required control, region, processor term, or retention obligation in the agreed product scope.

Review your requirements with us.

Send your identity, repository, retention, and assurance requirements without including secrets or private source code.

Contact CodLab

Privacy notice · Support