Trust

Trust built into the architecture.

RepoTruth interprets a read-only snapshot and surfaces what deserves your attention, while asking for no production access, no credentials, and no authority over your systems.

Trust is not a layer we add with badges and assurances. It is a property of how RepoTruth is built: it interprets the evidence and hands your people priorities, confidence, and a clear account of the unknowns, and the things you most need it never to do, it simply cannot. Capability you can use; boundaries you can verify.

  • Read-only
  • Snapshot-based
  • No production access
  • No credentials
  • No authority over your systems

Why trust matters

External analysis is now part of every major software decision, and trust can’t depend on promises.

When the decision matters most, the reading has to come from somewhere you can trust completely.

Modernization, migration, AI adoption, diligence, acquisition, the moments that matter most are exactly when an organization needs an independent, evidence-based reading of software it does not fully control.

Decisions increasingly require an outside view

An external reading is only useful if it can be trusted without reservation. That trust cannot rest on assurances, it has to rest on something an outside party can verify for themselves.

Promises are not a security model

A vendor can promise to be careful. Promises can be broken, misconfigured, or quietly changed. RepoTruth removes the question by removing the capability: there is no access to misuse, no credential to leak, no authority to overstep.

Trust you can verify in the architecture is worth more than trust you have to take on faith.

What RepoTruth actively provides

RepoTruth interprets evidence and surfaces what deserves human attention.

Capability first, bounded by the guarantees that follow.

  • Architectural interpretation

    We read the system’s real structure and interpret what the evidence shows: how it is layered, where it concentrates, and how far it has drifted from its original shape.

  • Evidence narratives

    Every observation is cited to its source and assembled into a readable account, not a raw dump, but a narrative your people can follow.

  • Investigation priorities

    We surface where human attention is best spent first, ordered by investigation urgency and paired with confidence.

  • Dependency concentration insights

    We reveal where authority and dependency gravity concentrate, the regions the rest of the system leans on most.

  • Unknown preservation

    We surface what could not be determined as first-class findings: the questions worth asking next, never quietly filled in.

  • Confidence-scoped intelligence

    Every reading carries how firmly it is held, and why, so you can rely on the strong and challenge the weak.

  • Review corridors

    We trace suggested paths through the system for human review: a way to look, mapped to the evidence beneath.

  • Structural themes & anomalies

    We highlight patterns, friction, legacy sediment, and the unusual regions that stand out, what most deserves a closer human reading.

This is the intelligence. The boundaries that follow are what make it safe to trust.

Constitutional guarantees

Six permanent guarantees, properties of how RepoTruth is built.

Not settings. Not promises. The architecture itself.

  • Read-only

    We write to nothing in your environment. There is no path by which RepoTruth can change your code.

  • Snapshot-based

    We analyze an inert, point-in-time copy, never a live or running system.

  • Zero production access

    We never connect to production. Not to observe, not for any reason.

  • Zero credentials

    We store, request, and reuse no credentials, because we connect to nothing that needs them.

  • Zero command authority

    We execute, deploy, and remediate nothing. RepoTruth cannot act on your systems.

  • Human review required

    Every output is built for a human to review and decide on. RepoTruth reaches no conclusion of its own.

The boundary charter

What we never do.

The capability above is real. So is the boundary here. Most platforms earn trust by promising to behave; RepoTruth earns it by being unable to misbehave. Each line below is not a policy we set, it is something the architecture cannot do.

  • Never connect to production

    There is no network path from RepoTruth to a running system. We analyze an inert copy, offline.

  • Never request credentials

    We need none, because we connect to nothing that authenticates. There is nothing to hand over.

  • Never execute code

    Analysis is static. We never run, build, or invoke anything from your codebase.

  • Never deploy

    RepoTruth ships nothing, promotes nothing, and releases nothing.

  • Never remediate

    We change nothing. There is no auto-fix, no patch, and no edit applied.

  • Never approve

    We issue no approval, sign-off, or clearance. A package is evidence, never a green light.

  • Never decide

    RepoTruth reaches no conclusion. The decision is, and remains, your people’s.

How we stay read-only

Read-only is not a setting. It’s how the analysis runs.

Three properties of the model that make change structurally impossible.

  1. Snapshot model

    You provide a point-in-time, read-only copy. We work from the copy, never the original, and never a live system.

  2. Offline analysis

    The snapshot is analyzed in isolation. There is no connection back to your environment at any stage.

  3. No runtime connectivity

    Nothing runs. No process from your codebase is started, and no live endpoint is contacted.

There is no write path, no execution path, and no live connection, so there is nothing to misuse.

Human review model

Humans remain terminal.

RepoTruth informs. Your people interpret and decide.

RepoTruth produces evidence, priorities, confidence, and unknowns, and then stops. It interprets nothing on your behalf and concludes nothing.

Where authority lives

The reading, the judgment, and the decision belong to your people, every time. There is no point at which RepoTruth substitutes for human review.

The unknown

An unknown is a finding, not a blank we fill in.

Unknown ≠ Low Risk.

Most tools quietly fill in what they cannot determine, or omit it entirely. RepoTruth does the opposite. Where the evidence runs out, we record an Unknown, explicitly, prominently, and as a first-class part of the picture. Ownership that can’t be established. Behavior a snapshot can’t reveal. Rationale that was never written down. Surfaced, never assumed away.

An unknown is not low risk. It is un-assessed. A region full of unknowns isn’t safe, it’s precisely where your people should look. Treating uncertainty as a finding, rather than hiding it, is one of the strongest forms of honesty a platform can offer.

We would rather tell you the truth about what we can’t see than hand you a false sense of completeness.

Constitutional Manifest

Every package declares its own boundaries.

Trust is easier to extend when the limits are written down.

Every Diagnostic Package ships with a Constitutional Manifest, a plain account your security and legal teams can read, stating exactly where the analysis began and ended.

What the manifest declares

  • What was analyzed, the scope, paths, and surfaces covered.
  • What was not analyzed, what fell outside the snapshot or the method.
  • Limitations, the constraints and decay that bound the analysis.
  • Unknown boundaries, what is unknowable from a snapshot, named rather than guessed.

A platform you can trust is one that tells you where its knowledge ends.

Methodology principles

Five distinctions we never collapse.

The methodology is built on what each output is, and what it is not.

  • Evidence ≠ Truth

    Evidence attests to a snapshot, not to reality. We never present an observation as final truth.

  • Confidence ≠ Certainty

    Confidence states how firmly we hold a finding, never that it is certain, and never that you should act.

  • Priority ≠ Decision

    A priority orders where to look first. It is not a decision, a severity, or an instruction.

  • Interpretation ≠ Recommendation

    We may interpret what was observed. We never recommend what to do.

  • Unknown ≠ Low Risk

    An unknown is un-assessed, not safe. It is a question to investigate, not a region to ignore.

Trust center

Security, disclosure, hosting, and procurement.

The operational details your security and legal teams will ask for, stated plainly.

Security contact

For security-related inquiries, write to security@repotruth.app. We acknowledge promptly and coordinate from there.

Responsible disclosure

If you believe you have found a vulnerability, email security@repotruth.app with the details and steps to reproduce. We follow a simple coordinated-disclosure process: acknowledge, investigate, remediate, and credit, before any public discussion.

Hosting & data residency

RepoTruth runs on European infrastructure. A submitted snapshot is processed within defined boundaries and is not moved outside them without your agreement. We state only what is true, and never more.

Procurement readiness

Available on request, for review by your security and legal teams: an NDA, a Data Processing Agreement (DPA), and a Security Whitepaper. Ask at security@repotruth.app.

Security & legal

Questions your security and legal teams will ask.

Do you connect to production?

No. RepoTruth never connects to a production or running system. We analyze an inert, point-in-time snapshot, offline. There is no network path from RepoTruth into your environment.

Do you require credentials?

No. We store, request, and reuse no credentials, because we connect to nothing that needs them. If a secret happens to appear inside a snapshot, it is treated as sensitive data to flag for rotation, never used.

Can RepoTruth change our systems?

No. RepoTruth is read-only by architecture. It executes, deploys, and remediates nothing. There is no path by which it can write to, or act on, anything in your environment.

Can outputs be treated as approvals?

No. A Diagnostic Package is evidence for a human decision, never an approval, certification, or verdict. It states, in its own manifest, that it concludes nothing.

What data do you keep?

Only what is necessary to produce and deliver your package, handled under a data processing agreement, with defined retention and deletion. We never retain credentials, and we never publish customer artifacts. The specifics are available for your security and legal teams to review.

Trust the method. Verify the architecture.

A read-only diagnostic, scoped to your decision.

Tell us the decision you’re facing. We’ll scope a Diagnostic Package to it, one that interprets the evidence and surfaces what deserves your attention, read-only and snapshot-based, with no production access, no credentials, and no authority over your systems.

No credentials. No production access. We never change your code.