Skip to content
Afara

Security

Built so your code never has to leave.

Afara's analysis runs where your code already is. Here is exactly what stays with you and what reaches us.

What stays, and what's sent.

Your machine

  • Commits are read from git
  • Your AI tool analyses a read-only copy
  • State is kept in .git/afara
  • API key stored readable only by you
afara push

Afara

  • Wireframes: nodes, edges, file paths and line ranges
  • Ticket text needed for the story side
  • Comparisons, findings and decisions
  • Your account, company and roles

Your AI coding tool's own data handling is governed by your agreement with its provider. Afara never calls a model with your source.

Security by design.

Every file Afara writes, listed.

Per-repository state lives inside .git, so it can never be committed by accident. Delete it and Afara forgets the clone.

Configuration reference
~/.config/afara/credentials
Your API key, readable only by you
~/.config/afara/model
The AI model you chose
~/.config/afara/session
A random ID for this installation
.git/afara/state.json
Feature names, linked tickets, generated commits
.git/afara/features/<id>.json
The last generated wireframe for each feature
.git/hooks/pre-push
The hook afara init installs

Report a vulnerability

Email security@afara.dev with the details and steps to reproduce. We acknowledge reports within two business days and keep you updated until it's fixed.

Security reviews

Enterprise customers can request our architecture overview, data-flow documentation and answers to their security questionnaire.

Request a review

See Afara on one of your own features.

A 30-minute walkthrough with an engineer. Bring two repositories and a ticket, and see the context your agent would get.