Security & data handling

How Fettl handles your code.

Your source does not need to leave your machine for Fettl to inspect it. Local analysis and account services have distinct roles.

Review the source, access, and repair boundaries before introducing Fettl to your workflow.

Data handling

Local analysis and connected services.

ON YOUR MACHINE

Code analysis and local findings

Free checks and supported Pro hooks evaluate code locally. Free does not require an account or source upload. Local findings and repair verification stay in your workflow.

ACCOUNT SERVICES

Identity and Pro access

Pro login uses the browser and account service to issue signed access. The CLI stores credentials through the operating system’s secure credential store. Valid signed local access does not require an account-service call for every agent event.

Deterministic repairs

Apply. Check. Keep or restore.

Explore what happens when a repair passes, fails, or meets changed code.

normalize.tsRepair example · CQ003
// TODO: implement normalizeLabel  export function normalizeLabel(label: string) {
    return label.trim().toLowerCase();
  }
fettl fix --filter CQ003 --dry-run
Planned

Remove the stale TODO.

The function already works. Only its outdated comment needs to go.

If recovery needs attention

If Fettl cannot confirm that the original files were restored, it keeps backups and reports what needs recovery.

Fettl fixes eligible defects. Architecture and product decisions stay with you.

Agent hooks

Checks at the moments that matter.

Six native events across four agents. Pro connects them to your local checks.

Claude CodePreToolUsePostToolUseStop
PreToolUse
Checks a proposed shell command or edit. Can block an unsafe action before it runs.
PostToolUse
Checks the result of a shell command or edit and returns findings to the agent.
Stop
Checks completion evidence when the assistant finishes.
Codex CLIPostToolUse
PostToolUse
Checks completed tool work and returns findings for the agent’s next action.
OpenCodefile.edited
file.edited
Checks the file that was just edited and returns findings to the agent.
Hermespost_tool_call
post_tool_call
Checks code after write_file or patch completes and returns findings to the agent.

Post-tool checks act on completed work. Missing or incomplete analysis is reported explicitly.

Planned: richer agent steering

User-configured model providers, confirmed rules from your feedback, questions when intent is unclear, and synced profiles.

Security questions

Discuss your security requirements.

Ask about data handling, access, or repairs.

Ask a security question

Choose what you share. Privacy notice