Trust
Security & repository access
- Effective:
- Last updated:
What Worql reads from your repositories
Worql's delivery audit ("Worql Review") works by reading the code you connect. Now that anyone can install the Worql Review GitHub App, here is exactly what we read and why — plainly, with nothing hidden.
What we read
When you connect a repository to an engagement (by installing the GitHub App and binding a repo), Worql reads, through that installation:
- Repository source contents — the files in the repo, at the commit we audit.
- Pull-request diffs and changed-file lists — what each PR adds, changes, or removes.
- Referenced issues / tickets — the issues a PR says it addresses (and, if you connect a Linear or Jira tracker, the tickets it references there).
- Commit history and contributor metadata — commit author and committer details, GitHub account logins, GitHub's commit-signature verification status, and which areas of the codebase each account contributed to.
Why we read it
So the audit can compare the delivered work against the acceptance criteria in your Statement of Work and surface where the evidence does and does not line up, using commit and contributor metadata as supporting signal. Worql does not judge whether the code is "good"; it records what was delivered against what was agreed, for both parties to weigh. Where it is enabled for your engagement, Worql can also produce a repository-provenance record — what shipped, when, and by which verified account. This record is evidence, not a verdict: it is shown to both parties (the client and the vendor), and the vendor can respond to it. It is not a surveillance tool.
What we do NOT do
- We do not certify that the delivered code is correct, secure, or fit for purpose. The audit records provenance and how the work maps to the agreed acceptance criteria; it is not exhaustive and is not a substitute for the parties' own review or for professional/legal advice.
- We do not infer your location, working hours, time zone, or lifestyle from commit activity. We read commit counts and authorship, not when you work.
- We do not assert that any individual is "junior" or "senior", or that a named person did or did not do the work. The audit reports observed evidence and labeled signals about the code and the accounts, for the reader to weigh.
- We do not store your repository wholesale. Repository contents are read at audit time using short-lived installation tokens that are minted per request and never persisted. We keep the structured audit findings and the provenance records, in which contributor identities are pseudonymized (a keyed hash of the commit email — the raw email is not retained there).
Your control
Access begins when you install the App and ends the moment you uninstall it or remove the repository from the installation. When you do, the engagement is marked disconnected and audits stop. Repository contents are sent to our AI sub-processor (Anthropic) at audit time to produce the review, and are not used to train models under Anthropic's commercial terms. We retain the structured findings and provenance records, not the source itself.
For the full picture, see our Privacy Policy (section 3g, "Connected repository data", and section 9, "Security") and our Sub-processors list. Security reports: security@worql.app.