Security and trust

Investigate the system without modifying the source.

RefineBrief is designed around read-only access, derived technical representations and visible uncertainty. This page gives security and engineering teams one place to review that boundary.

READ-ONLY PRODUCT ROLE

Map. Investigate. Prepare work. Never modify source code.

Product boundaries

The access RefineBrief needs — and the access it does not.

These are product principles, not claims of a certification or compliance program.

01
Access model

Read-only access to your Git provider.

RefineBrief requests read-only repository access so it can investigate the code connected by your team. The product does not need permission to write to repositories in order to map or analyze them.

02
Source handling

No retained copy of your source code.

RefineBrief works from technical maps and indexes derived from the connected repositories. It does not keep a traditional working checkout or a retained copy of customer source code.

03
No code changes

No edits, commits or pushes.

The product investigates and prepares engineering work. It does not change files, create commits, push branches or implement the suggested work in your repositories.

04
Customer separation

Customer environments and indexes stay isolated.

The technical maps and indexes created for one customer remain isolated from those created for another customer. They are used to investigate that customer’s connected system.

05
Model use

Customer code does not train shared models.

Source-code context and the derived technical representation are not used to train a shared model for other customers.

06
Honest uncertainty

A suggestion is not presented as a confirmed fact.

RefineBrief keeps discovered evidence, reasonable inference and unanswered questions visibly separate. Missing product or operational context remains a question for the team to decide.

A narrow operational loop

From connected code to reviewed work.

The repository remains the source of truth. RefineBrief keeps only the derived technical context needed to investigate and prepare reviewable work.

  1. 01
    Git provider

    Read connected repositories

  2. 02
    Derived representation

    Build isolated maps and indexes

  3. 03
    Investigation

    Link findings, inference and questions

  4. 04
    Jira review

    Create only the approved work items

Bring security into the first conversation

Give engineering and security the same product boundary.

Use the security page as the starting point for review.