Security

Runs on your hardware. Answers to your rules.

Reqursor Development is installed on your own server or Raspberry Pi. Here is exactly what it sends where, what it can touch, and what it never will.

Data flow

What leaves your infrastructure

Your code and tickets leave the machine for exactly three kinds of destination, all of them chosen and configured by you.

Your server or Raspberry Pi

Reqursor Development: the dashboard, the worker and the agent sandbox, plus your tickets, run history, audit log and encrypted secrets.

  • 1

    The model provider you choose

    Prompts and working context, including the code the agent reads, go to Anthropic, or to Amazon Bedrock, Google Vertex AI or Microsoft Foundry if you use them.

  • 2

    Your git remote

    Commits and pull requests go to the repository you connected, on the branches you allow.

  • 3

    The integrations you connect

    Your tracker, email, Slack or webhooks receive the updates you switch on. Nothing more.

  • Reqursor: license check only

    Once a day, eight fields of metadata. No code, tickets or names.

License check

Eight fields a day. Nothing else.

Once a day, your install checks its license with Reqursor. The request contains exactly these fields:

  • No code or diffs
  • No ticket text
  • No repository names
  • No user names or email addresses

If the license server can’t be reached, work carries on and a banner appears. A short outage never stops your team.

Agent isolation

The agent only sees the code it works on

Ticket text is untrusted input, so the agent runs with the least it needs.

  • Runs in a sandbox that sees only the project’s working copy
  • Never sees your data directory, your license or your real API keys
  • Model calls go through a local gateway that adds the key on the agent’s behalf
  • Pushes, pull requests and tracker updates are made by Reqursor Development, not by the agent
  • Ticket text is treated as data, never as instructions, and scanned for prompt-injection patterns

Guardrails

Rules enforced in code, not in prompts

A model can be talked out of an instruction. It can’t be talked out of code that refuses the command.

  • No force-push

    Force-pushes are refused outright.

  • No history rewrites

    No rebase, amend or hard reset on shared history.

  • No skipped hooks

    Commits that try to skip your git hooks are refused, so your hooks always run.

  • Protected branches

    The agent never pushes to the branches you protect.

  • Protected paths

    Changes to CI workflows, environment files or secrets folders refuse the whole commit.

  • Approval gates

    Large or sensitive diffs wait for a person to approve them.

Secrets and access

Locked down by default

  • Secrets

    • Encrypted at rest with AES-GCM
    • Write-only through the API, shown only as ••••last4
    • Redacted from logs, live events, the audit log and diagnostics
    • Never sent to Reqursor
  • Access

    • Sign-in required for every page and action
    • Roles: Owner, Admin, Developer and Viewer
    • CSRF protection and scoped API tokens
    • Metrics endpoint protected by a token

Audit trail

Every action on the record

An append-only audit log records every run, decision and settings change. Export any run as a post-mortem in Markdown or JSON for your own records.

Updates and licensing

Never destructive

  • Signed releases

    Every update is signature-checked before it installs.

  • Automatic rollback

    A backup is taken first, and a failed update restores it.

  • Fails safe

    An expired license stops new work at the next ticket boundary. It never deletes data or touches your repositories.

  • No third-party code

    The dashboard loads no external scripts, fonts or trackers.

Found a vulnerability?

Email [email protected] with the details, and we’ll work with you on a fix and on disclosure.

Bring your security questions

We’ll walk your security team through the architecture, the data flows and the isolation model.