Security model
Last updated 12 July 2026
Least privilege
URL-only inspections require no repository access. GitHub is optional and read-only by default. Code writes require separate authorisation for a branch or draft pull request.
Browser isolation
Each inspection uses a fresh server-controlled browser context. Target credentials are supplied directly to that context and excluded from transcripts, findings and AI prompts.
Evidence boundaries
Browser observations, source readiness and authenticated provider proof are recorded separately. A route response or repository implementation is not treated as proof of a completed external deployment.
Human approval
External writes, destructive actions, purchases, permission changes and deployments require explicit approval. Generated remediation is tested and returned for review.
Reporting
Report suspected vulnerabilities privately to security@releasecouncil.app. For production incidents or service-impacting support, contact support@releasecouncil.app. Do not include sensitive exploit details in public issues. Receipt is a contact path, not a claim that an incident has been resolved.