Security
Built so your code never has to leave.
Afara's analysis runs where your code already is. Here is exactly what stays with you and what reaches us.
What stays, and what's sent.
Your machine
- Commits are read from git
- Your AI tool analyses a read-only copy
- State is kept in .git/afara
- API key stored readable only by you
Afara
- Wireframes: nodes, edges, file paths and line ranges
- Ticket text needed for the story side
- Comparisons, findings and decisions
- Your account, company and roles
Your AI coding tool's own data handling is governed by your agreement with its provider. Afara never calls a model with your source.
Security by design.
Commits only
Afara reads commits, never the working tree. Uncommitted changes are never read or sent.
No source upload
Code analysis happens on your machine. Only the wireframe is published, after afara push.
Read-only analysis
Your AI tool works in a read-only checkout of the commit. It cannot change your repository.
Browser sign-in for the CLI
The CLI gets its own key through the browser, so passwords never reach the terminal. One active key per user per session.
HttpOnly sessions
Dashboard sessions are HttpOnly, SameSite cookies. The token never reaches JavaScript.
Least-privilege GitHub App
You pick exactly which repositories the app can see. Owners can disconnect an account at any time.
Local-only callbacks
CLI sign-in only returns a key to localhost, 127.0.0.1 or [::1], so a crafted link cannot send it elsewhere.
Verified releases
Every release publishes SHA-256 checksums. The installer checks the download before installing.
Every file Afara writes, listed.
Per-repository state lives inside .git, so it can never be committed by accident. Delete it and Afara forgets the clone.
- ~/.config/afara/credentials
- Your API key, readable only by you
- ~/.config/afara/model
- The AI model you chose
- ~/.config/afara/session
- A random ID for this installation
- .git/afara/state.json
- Feature names, linked tickets, generated commits
- .git/afara/features/<id>.json
- The last generated wireframe for each feature
- .git/hooks/pre-push
- The hook afara init installs
Report a vulnerability
Email security@afara.dev with the details and steps to reproduce. We acknowledge reports within two business days and keep you updated until it's fixed.
Security reviews
Enterprise customers can request our architecture overview, data-flow documentation and answers to their security questionnaire.
Request a reviewSee Afara on one of your own features.
A 30-minute walkthrough with an engineer. Bring two repositories and a ticket, and see the context your agent would get.