Built to be audited.
Autter is the gate teams trust to catch leaked secrets, phantom dependencies, and removed authentication before merge. A security tool has no excuse for a soft underbelly, so the platform is built and run to the same standard it enforces: least privilege, ephemeral compute, and a paper trail for every call.
ephemeral sandboxes · never trained on your code · encrypted in transit and at rest · on-prem available
The life of your code inside Autter.
One pass, five stations, and the only things that outlive the run are the verdict and the audit entry. This is the whole data path; there are no other doors.
Scoped read
A native GitHub App with least-privilege scopes clones the pull request. Autter reads what it reviews and nothing more.
Encrypted transit
Code moves over TLS and lands encrypted at rest, inside a sandbox built fresh for this one run.
Isolated execution
The suite runs against the base branch in full isolation. No shared state, no neighbors, no way out.
Verdict posted
Findings land on the pull request pinned to file and line. The verdict and the audit entry are what persist.
Teardown
The sandbox is destroyed the moment the verdict lands. Your source does not outlive the run.
What we keep. What we never keep.
The clean way to reason about a vendor is to ask what data outlives a session. Here is the full inventory, in both directions.
kept
Findings and verdicts
Pinned to file and line, they are the review record your team works from.
The map, not the territory
Product memory stores structure: APIs, routes, schema, owners, hotspots. A graph about your code, not a copy of it.
The audit log
Actor, token, duration, result, and error code for every machine-facing call.
Account and billing data
Covered end to end by the privacy policy.
never kept
Your source after the run
Code exists inside the ephemeral sandbox for exactly one review, then the sandbox is destroyed with it.
Training data
Your code never trains a model, ours or anyone else's.
Prompts from the CLI
Local-only mode never uploads a prompt. Attribution lives in your Git history, on your machine.
Standing credentials
Tokens are scoped and expire on schedule. There is no forever-key to steal.
The posture, clause by clause.
These are the controls the platform runs on today, written the way we would want to read them in a vendor review. Every one of them is answerable in detail; ask.
- Ephemeral execution
- Every pull request runs in a sandbox built fresh for that run and destroyed the moment the verdict lands. Nothing lingers between runs, and no two customers ever share one.
- No training, ever
- Your source is never used to train models. It exists inside the run, and then it is gone.
- Encrypted throughout
- In transit and at rest, from the moment the sandbox clones to the moment the verdict posts.
- Least privilege
- The GitHub App asks for the minimum scopes a review needs. Autter reads what it reviews and nothing more, through access you can revoke at any time.
- Tokens that expire
- Personal access tokens carry narrow scopes (mcp:read, mcp:write, mcp:llm), expire on schedule, and revoke instantly from the dashboard.
- Everything audited
- Every machine-facing call records actor, token, duration, result, and error code in the organization audit log.
- Rate limited per token
- Runaway agent loops get slowed down instead of taking the org down.
- Isolation and SSO
- Organizations are isolated from each other, and the Fleet plan adds SSO / SAML for centralized access control.
Run it inside your walls.
Autter Cloud is the default: managed, isolated, ephemeral. For teams whose code cannot leave the building, the Fleet plan ships the entire review plane on-prem.
autter cloud
- Live in minutes through the native GitHub App
- Ephemeral compute per pull request, destroyed after the run
- SSO / SAML and audit logs on the Fleet plan
on-prem · fleet plan
- The full review plane deploys into your cloud account or data center
- Source never crosses your network boundary
- Your keys, your logs, and updates as versioned releases you approve
On-prem deployments are scoped with your infrastructure team. Talk to us about running Autter in your network.
Autter reviews Autter.
Every pull request to our own codebase clears the same gate we sell: sandbox execution, dependency verification, secret scanning, and a merge button that stays locked until the checklist clears. If the gate has a gap, it is our production that finds out first.
Talk to the people who built it.
Security questions do not go into a ticket queue here. Both of these channels land with the founders directly.
Report a vulnerability
Write to support@autter.dev or use the contact form's Security lane. A founder reads every report, and fixes ship through the same verified pipeline as everything else.
Open the contact formRun your vendor review
Questionnaires, data-handling walkthroughs, and the detail behind every clause on this page. Bring your checklist and work through it with us on a call.
Book the founders
