Your code is never stored. Not on our servers. Not anywhere.
Only AI agents see your code during review. No employees ever access it.
Code is deleted the moment the review completes. No traces left.
A transparent look at exactly what happens during a review
When a PR is opened, we create a temporary clone of your repository in an isolated container. This clone exists only in memory and on ephemeral storage.
Our AI agents analyze the changes in your pull request. They look at the code, understand the context, and generate review comments. Only the AI has access to your code.
The moment the review is complete, the container is destroyed. The clone, any intermediate files, everything is wiped. There is no way for code to persist.
Total processing time: typically under 2 minutes. Your code exists on our infrastructure for only as long as the review takes.
Each review runs in a completely isolated container — created specifically for your review and fully destroyed when complete.
No data from previous reviews
Cannot access other customers' data
Except to GitHub and AI services
Container and all data wiped on completion
No code remains after the review
There is no way for code to persist between reviews or be accessed after the process ends.
Even in the unlikely event of a security breach, there would be nothing to steal — the code simply doesn't exist on our infrastructure outside of active reviews.
Clear commitments about how we treat your intellectual property
You retain all ownership rights to your code. Always.
Your code is NEVER used to train AI models. Period.
We NEVER share your code with other customers or third parties.
diffray receives a license solely to provide the review service.
We use Claude AI through Anthropic's API. Anthropic does not train on customer data sent through their API. Your code is processed and forgotten — it never becomes part of any AI model.
We follow the principle of least privilege — we only request what we need.
| Permission | Purpose |
|---|---|
Contents (read) | Access changed files for review |
Pull requests (read/write) | Read PR details, post review comments |
Checks (read/write) | Create check runs for review status |
Metadata (read) | Basic repository information |
diffray runs on AWS with enterprise-grade security:
Enterprise customers requiring specific compliance documentation before our SOC 2 completion can contact security@diffray.ai for a detailed security questionnaire response.
See exactly how your code flows through our system during a review
Isolated • No persistent storage
All data wiped immediately
Transparency about what information we access
What we keep and for how long
| Data Type | Retention |
|---|---|
| Source code | Never stored |
| Review results (issues found) | 90 days (visible in dashboard) |
| Account data | While active + 30 days after deletion |
| Repository metadata | Deleted within 90 days of disconnecting |
You have control over your data
Request a copy of your data at any time
Fix inaccurate information in your account
Request deletion of your personal data
Unsubscribe from marketing communications
To exercise these rights, contact privacy@diffray.ai
No. Code is processed automatically by AI and deleted after review. Our team does not have access to customer source code during normal operations. There's no mechanism to access it even if we wanted to.
No. Your code is never used for training AI models. We use Claude AI through Anthropic's API, which does not train on customer data. Your code is processed and forgotten.
Your code is temporarily cloned into an ephemeral container that exists only for the duration of the review. This container has no persistent storage and is completely destroyed when the review completes.
Your repository metadata and review history are deleted within 90 days. Since we never store source code, there's nothing to delete on that front.
Account data is retained for 30 days (in case you change your mind), then permanently removed along with all associated review history.
Absolutely not. We never share your code with anyone. The only entities that access your code are our AI agents during the review process, and they don't retain any information.
Found a vulnerability? Have security concerns? We take security seriously and appreciate responsible disclosure.
Your code stays yours. We just make it better.