niiro

Security and data flow

What leaves your machine, what is stored, and how it is protected and deleted.

The path of your code

  • 01The CLI reads only what the include list in niiro.yml allows, and never your environment variables.
  • 02A secret scan runs before every upload and stops the push on a finding.
  • 03Only files niiro does not have yet are uploaded, encrypted in transit and at rest.
  • 04Analysis and generation read the snapshot in a sandbox: no code execution, no network beyond our own APIs.
  • 05Model calls run under a zero-data-retention agreement. Your code trains no models.

Four things we never do

  • ·Your code is never built.
  • ·Your code is never executed.
  • ·Your code is never used to train models.
  • ·Your code never leaves your tenant.

Storage

Snapshots are encrypted before they reach storage, with a key per tenant and one per snapshot. Storage addresses are derived with a tenant-specific salt, so identical files in different accounts never share a location, and deduplication never crosses tenants.

Deletion

On cancellation, files are deleted immediately and the tenant key is destroyed after seven days, which makes every remaining copy unreadable, backups included. Backups expire after thirty days at the latest.

If a secret slips through

The value is replaced with a redaction marker, the snapshot is re-encrypted, and you are notified with the location and a rotation recommendation.

Access

Project tokens are write-only: they can push snapshots but never read code or anything derived from it. Staff access is role-based and logged; nobody opens raw code without an explicit, recorded approval.

Subprocessors and the full storage terms are on the trust page.

Updated 2026-08-05