Repository selection
Repository-provider selection stays explicit: github_app, github_action, or disabled. Detecting an installation alone does not auto-enable managed processing.
Security & data handling
The Free CLI runs where your code already lives. Running Free checks does not require a source upload.
The hosted control plane revalidates authority server-side. LLM-assisted or external-agent repair is separate future Max scope and is not available in Pro.
Local execution
Running Free checks, scanning changed or staged files, and local-only CLI use do not themselves upload source code to Fettl.
Local analysis produces text findings and a basic score on the machine invoking Fettl. Hosted behavior begins only when a managed capability is explicitly enabled.
Privacy modes
Fettl names four privacy modes for hosted workflows: LocalOnly, MetadataOnly, RedactedFindings, and FullSourceOptIn. Free stays local by default; full-source handling requires an explicit opt-in.
Analysis stays on the machine running Fettl. Source and findings are not sent to a Fettl-hosted service.
Nothing crosses the boundary. Stays local: source, findings, score.
Current gap: the exact public customer inventory for GitHub payload fields, redaction residue limits, subprocess output handling, and workflow-by-workflow retention detail is not yet published as a final operational guarantee.
Managed GitHub workflow
Protected hosted operations revalidate trusted-edge identity plus repository, installation, membership, subscription, and entitlement authority. Missing repository-provider settings fail closed instead of silently enabling a workflow.
Repository-provider selection stays explicit: github_app, github_action, or disabled. Detecting an installation alone does not auto-enable managed processing.
The current hosted path is backed by the Sites worker and Cloudflare D1. Entitlement and runtime-setting responses are marked no-store, and contested writes use idempotency plus compare-and-swap guards.
RedactedFindings and FullSourceOptIn are named product boundaries, but the exact public redaction guarantee for every GitHub payload and failure path is still an open operational detail.
Future Max
Future Max plans are reserved for LLM-assisted or external-agent repair. These boundaries describe the launch requirement, not a capability available today.
A future Max repair would run in a dedicated branch or worktree rather than writing directly into a contributor’s working tree.
Each run would be bounded by allowed paths, commands, runtime, network policy, retry limits, and a stated resource budget.
Fettl would run relevant tests and checks, rescan the result, and verify that the targeted finding improved without adding a new critical or high finding.
Any future Max launch begins with approval-required patches. Nothing is applied to a pull request without a person approving it.
Architecture, product behavior, compatibility, public APIs, data models, and ambiguous security choices remain explanations and options in the PR thread, not unilateral edits.
Current boundary
Fettl does not claim certifications, audits, retention guarantees, residency, service levels, or implementation controls before they exist and can be verified.
Use the private-beta form for non-sensitive security or privacy questions. A vulnerability-reporting mailbox and policy are not yet operational, so do not send secrets or sensitive exploit details through the beta form.
Private beta
Join the beta to review the applicable data mode before any managed processing begins.