Security & trust
Your build is evidence, then it's gone.
You're handing us a build and, sometimes, a test login. Here's exactly what happens to both — and how each claim on this page maps to real behavior in the product, not marketing.
01 Your build is deleted the moment the audit completes
We remove the uploaded build from storage as soon as your report is ready, and stamp the exact UTC deletion time into the report itself — you can read it in the app header ("Build deleted — … UTC"). If a run fails, the build is held only for a 72-hour retry window, then deleted the same way.
02 Your test credentials never touch a log
Use a disposable test account with fake data. Demo credentials are encrypted at rest with a per-audit key, decrypted in memory only for the length of the run, and permanently wiped when the audit completes or fails. They are never written to logs or telemetry.
03 The evidence lives in your report and nowhere else
Every screenshot and the frame from the moment a task failed are embedded in the report we hand you. The originals — including the screen recording the frame was cut from — are destroyed along with your build when the audit completes. We keep no copy, which also means we cannot re-send the evidence later: your report is it. Findings survive only in de-identified, aggregate form for category benchmarks.
04 Your build is never used to train a model
The agent that drives your app runs only on a commercial API — never on a consumer subscription. That is a deliberate, load-bearing choice: a subscription would void this guarantee. Your build and its contents are inputs to your audit and nothing else.
05 The audit runs on an isolated, hardened machine
Audits run on a dedicated macOS user with FileVault on and no inbound network connections — the worker only polls out. Each run happens on a throwaway simulator clone that is erased and destroyed afterward, so nothing from one audit reaches the next.
72hfailed-build retry window
noneevidence we keep
0credentials in logs
neverused for training