Skip to content

TRUST CENTER

Trust should come with details.

A clear view of the current product’s access controls, data paths, and limitations. Last reviewed September 20, 2026.

PRIVACY

Data handling

Understand what is processed locally, what reaches hosted services, and which records remain in your workspace.

Read the privacy notice

SECURITY

Review boundaries

Understand authorization, revision checks, source evidence, and what a successful review does not establish.

Review the controls

TRANSPARENCY

Service providers

See the providers involved in hosting, identity, workspace storage, repository access, and AI review.

View provider roles

Human Review access and evidence

Human Review operators can access only requests customers explicitly submit to that service. An operator role does not grant general browsing of customer repositories or access to their GitHub tokens. Assignment, scope agreement, messages and assessments are recorded against the request; a human assessment identifies its author, publication time and reviewed revision.

Withdrawing consent removes the copied evidence, ends operator access to the request and blocks pending notifications. It does not recall email already submitted to a sending provider. The request, messages, activity and earlier assessments remain in account records until account deletion. The privacy notice explains the limits of deletion and provider retention.

Controls implemented in the website

GitHub identity and repository access are checked on the server. Workspace records are scoped by repository membership, with a 15-minute access lease. Explicit disconnection removes membership immediately.

GitHub provider tokens are encrypted on the server. Dashboard APIs do not return those tokens or the AI service key. Saved review results are tied to the current head and base commits and target branch.

AI responses must be complete and their source references must match the supplied diff. Errors preserve prior successful results. Review limits bound input size and request volume.

Controls that are not claimed

There is no published SOC 2 or ISO 27001 certification for AntiCode, no independent penetration-test attestation, and no uptime SLA. Vendor certifications do not become AntiCode certifications.

Enterprise pilots include role-based team access, remediation targets and read-only workspace audit history. Organization SSO, SCIM, audit-retention administration, custom residency, scheduled security scans and automatic GitHub merge gates are not configured. This page is a product disclosure, not a compliance attestation.

Sensitive reports and procurement

Do not post secrets, personal information, or exploit details in a public GitHub issue. Review the vulnerability disclosure page for the current reporting-channel status.

The operator is Rashad Elkersawy in Oldenburg, Germany; contact admin@rtwochain.com. A customer DPA, verified retention schedule, and transfer details still need finalization for a complete procurement package.

Bring a little more care to your next change.

Connect a repository, review the evidence, and keep the decision yours.

Get started ↗