Decisions increasingly require an outside view
An external reading is only useful if it can be trusted without reservation. That trust cannot rest on assurances, it has to rest on something an outside party can verify for themselves.
Trust
RepoTruth interprets a read-only snapshot and surfaces what deserves your attention, while asking for no production access, no credentials, and no authority over your systems.
Trust is not a layer we add with badges and assurances. It is a property of how RepoTruth is built: it interprets the evidence and hands your people priorities, confidence, and a clear account of the unknowns, and the things you most need it never to do, it simply cannot. Capability you can use; boundaries you can verify.
Why trust matters
When the decision matters most, the reading has to come from somewhere you can trust completely.
Modernization, migration, AI adoption, diligence, acquisition, the moments that matter most are exactly when an organization needs an independent, evidence-based reading of software it does not fully control.
An external reading is only useful if it can be trusted without reservation. That trust cannot rest on assurances, it has to rest on something an outside party can verify for themselves.
A vendor can promise to be careful. Promises can be broken, misconfigured, or quietly changed. RepoTruth removes the question by removing the capability: there is no access to misuse, no credential to leak, no authority to overstep.
Trust you can verify in the architecture is worth more than trust you have to take on faith.
What RepoTruth actively provides
Capability first, bounded by the guarantees that follow.
We read the system’s real structure and interpret what the evidence shows: how it is layered, where it concentrates, and how far it has drifted from its original shape.
Every observation is cited to its source and assembled into a readable account, not a raw dump, but a narrative your people can follow.
We surface where human attention is best spent first, ordered by investigation urgency and paired with confidence.
We reveal where authority and dependency gravity concentrate, the regions the rest of the system leans on most.
We surface what could not be determined as first-class findings: the questions worth asking next, never quietly filled in.
Every reading carries how firmly it is held, and why, so you can rely on the strong and challenge the weak.
We trace suggested paths through the system for human review: a way to look, mapped to the evidence beneath.
We highlight patterns, friction, legacy sediment, and the unusual regions that stand out, what most deserves a closer human reading.
This is the intelligence. The boundaries that follow are what make it safe to trust.
Constitutional guarantees
Not settings. Not promises. The architecture itself.
We write to nothing in your environment. There is no path by which RepoTruth can change your code.
We analyze an inert, point-in-time copy, never a live or running system.
We never connect to production. Not to observe, not for any reason.
We store, request, and reuse no credentials, because we connect to nothing that needs them.
We execute, deploy, and remediate nothing. RepoTruth cannot act on your systems.
Every output is built for a human to review and decide on. RepoTruth reaches no conclusion of its own.
The boundary charter
The capability above is real. So is the boundary here. Most platforms earn trust by promising to behave; RepoTruth earns it by being unable to misbehave. Each line below is not a policy we set, it is something the architecture cannot do.
There is no network path from RepoTruth to a running system. We analyze an inert copy, offline.
We need none, because we connect to nothing that authenticates. There is nothing to hand over.
Analysis is static. We never run, build, or invoke anything from your codebase.
RepoTruth ships nothing, promotes nothing, and releases nothing.
We change nothing. There is no auto-fix, no patch, and no edit applied.
We issue no approval, sign-off, or clearance. A package is evidence, never a green light.
RepoTruth reaches no conclusion. The decision is, and remains, your people’s.
How we stay read-only
Three properties of the model that make change structurally impossible.
You provide a point-in-time, read-only copy. We work from the copy, never the original, and never a live system.
The snapshot is analyzed in isolation. There is no connection back to your environment at any stage.
Nothing runs. No process from your codebase is started, and no live endpoint is contacted.
There is no write path, no execution path, and no live connection, so there is nothing to misuse.
Human review model
RepoTruth informs. Your people interpret and decide.
RepoTruth produces evidence, priorities, confidence, and unknowns, and then stops. It interprets nothing on your behalf and concludes nothing.
The reading, the judgment, and the decision belong to your people, every time. There is no point at which RepoTruth substitutes for human review.
The unknown
Unknown ≠ Low Risk.
Most tools quietly fill in what they cannot determine, or omit it entirely. RepoTruth does the opposite. Where the evidence runs out, we record an Unknown, explicitly, prominently, and as a first-class part of the picture. Ownership that can’t be established. Behavior a snapshot can’t reveal. Rationale that was never written down. Surfaced, never assumed away.
An unknown is not low risk. It is un-assessed. A region full of unknowns isn’t safe, it’s precisely where your people should look. Treating uncertainty as a finding, rather than hiding it, is one of the strongest forms of honesty a platform can offer.
We would rather tell you the truth about what we can’t see than hand you a false sense of completeness.
Constitutional Manifest
Trust is easier to extend when the limits are written down.
Every Diagnostic Package ships with a Constitutional Manifest, a plain account your security and legal teams can read, stating exactly where the analysis began and ended.
A platform you can trust is one that tells you where its knowledge ends.
Methodology principles
The methodology is built on what each output is, and what it is not.
Evidence attests to a snapshot, not to reality. We never present an observation as final truth.
Confidence states how firmly we hold a finding, never that it is certain, and never that you should act.
A priority orders where to look first. It is not a decision, a severity, or an instruction.
We may interpret what was observed. We never recommend what to do.
An unknown is un-assessed, not safe. It is a question to investigate, not a region to ignore.
Trust center
The operational details your security and legal teams will ask for, stated plainly.
For security-related inquiries, write to security@repotruth.app. We acknowledge promptly and coordinate from there.
If you believe you have found a vulnerability, email security@repotruth.app with the details and steps to reproduce. We follow a simple coordinated-disclosure process: acknowledge, investigate, remediate, and credit, before any public discussion.
RepoTruth runs on European infrastructure. A submitted snapshot is processed within defined boundaries and is not moved outside them without your agreement. We state only what is true, and never more.
Available on request, for review by your security and legal teams: an NDA, a Data Processing Agreement (DPA), and a Security Whitepaper. Ask at security@repotruth.app.
Security & legal
No. RepoTruth never connects to a production or running system. We analyze an inert, point-in-time snapshot, offline. There is no network path from RepoTruth into your environment.
No. We store, request, and reuse no credentials, because we connect to nothing that needs them. If a secret happens to appear inside a snapshot, it is treated as sensitive data to flag for rotation, never used.
No. RepoTruth is read-only by architecture. It executes, deploys, and remediates nothing. There is no path by which it can write to, or act on, anything in your environment.
No. A Diagnostic Package is evidence for a human decision, never an approval, certification, or verdict. It states, in its own manifest, that it concludes nothing.
Only what is necessary to produce and deliver your package, handled under a data processing agreement, with defined retention and deletion. We never retain credentials, and we never publish customer artifacts. The specifics are available for your security and legal teams to review.
A read-only diagnostic, scoped to your decision.
Tell us the decision you’re facing. We’ll scope a Diagnostic Package to it, one that interprets the evidence and surfaces what deserves your attention, read-only and snapshot-based, with no production access, no credentials, and no authority over your systems.
No credentials. No production access. We never change your code.