Data & Trust
A plain account of what NittiM stores, how long it keeps it, and how to make it go away.
What we store — and what we don't
Audit report
Findings, scores, verdict, repository name. Persisted so you can retrieve it later via a shareable link or the API.
Source code
Never stored. Fetched into server memory during analysis, discarded when the pipeline finishes. The one deliberate exception: a finding's evidence includes the few offending lines it points at — those excerpts live in your report (access-gated for private repos), because a finding without evidence is an opinion.
GitHub tokens
Never stored. A pasted token is used once to call the GitHub API, then discarded from memory. GitHub App installation tokens are minted per-audit and expire on their own within the hour; NittiM records only the installation id.
Request logs containing code
Application logs record request metadata only — never the source snapshot content.
Does an AI train on your code? No.
Read-only by construction
Retention schedule
Deleting a report
Shareable links
Organization access
Infrastructure
How accurate is NittiM?
Trust shouldn't be taken on faith. We publish our accuracy methodology and results in the open.
See the benchmark →