Security & data handling

Local first. Explicit when hosted.

The Free CLI runs where your code already lives. Running Free checks does not require a source upload.

The hosted control plane revalidates authority server-side. LLM-assisted or external-agent repair is separate future Max scope and is not available in Pro.

Local execution

No source round trip to prove local value.

Running Free checks, scanning changed or staged files, and local-only CLI use do not themselves upload source code to Fettl.

available

Free stays local.

Local analysis produces text findings and a basic score on the machine invoking Fettl. Hosted behavior begins only when a managed capability is explicitly enabled.

Install the CLI

Privacy modes

Choose what crosses the boundary.

Fettl names four privacy modes for hosted workflows: LocalOnly, MetadataOnly, RedactedFindings, and FullSourceOptIn. Free stays local by default; full-source handling requires an explicit opt-in.

Analysis stays on the machine running Fettl. Source and findings are not sent to a Fettl-hosted service.

Nothing crosses the boundary. Stays local: source, findings, score.

Current gap: the exact public customer inventory for GitHub payload fields, redaction residue limits, subprocess output handling, and workflow-by-workflow retention detail is not yet published as a final operational guarantee.

Managed GitHub workflow

Installation is not blanket access.

Protected hosted operations revalidate trusted-edge identity plus repository, installation, membership, subscription, and entitlement authority. Missing repository-provider settings fail closed instead of silently enabling a workflow.

01

Repository selection

Repository-provider selection stays explicit: github_app, github_action, or disabled. Detecting an installation alone does not auto-enable managed processing.

02

Hosted findings

The current hosted path is backed by the Sites worker and Cloudflare D1. Entitlement and runtime-setting responses are marked no-store, and contested writes use idempotency plus compare-and-swap guards.

03

Redaction

RedactedFindings and FullSourceOptIn are named product boundaries, but the exact public redaction guarantee for every GitHub payload and failure path is still an open operational detail.

Future Max

Repair automation is not a Pro feature.

Future Max plans are reserved for LLM-assisted or external-agent repair. These boundaries describe the launch requirement, not a capability available today.

01

Isolated execution

A future Max repair would run in a dedicated branch or worktree rather than writing directly into a contributor’s working tree.

02

Constrained scope

Each run would be bounded by allowed paths, commands, runtime, network policy, retry limits, and a stated resource budget.

03

Evidence before application

Fettl would run relevant tests and checks, rescan the result, and verify that the targeted finding improved without adding a new critical or high finding.

04

Human approval

Any future Max launch begins with approval-required patches. Nothing is applied to a pull request without a person approving it.

05

Human-decision findings

Architecture, product behavior, compatibility, public APIs, data models, and ambiguous security choices remain explanations and options in the PR thread, not unilateral edits.

Current boundary

Claims follow evidence.

Fettl does not claim certifications, audits, retention guarantees, residency, service levels, or implementation controls before they exist and can be verified.

planned

Security contact is pending business email

Use the private-beta form for non-sensitive security or privacy questions. A vulnerability-reporting mailbox and policy are not yet operational, so do not send secrets or sensitive exploit details through the beta form.

Read the Privacy draft

Private beta

Bring your repository and security requirements.

Join the beta to review the applicable data mode before any managed processing begins.