Security and data flow
What leaves your machine, what is stored, and how it is protected and deleted.
The path of your code
- 01The CLI reads only what the include list in niiro.yml allows, and never your environment variables.
- 02A secret scan runs before every upload and stops the push on a finding.
- 03Only files niiro does not have yet are uploaded, encrypted in transit and at rest.
- 04Analysis and generation read the snapshot in a sandbox: no code execution, no network beyond our own APIs.
- 05Model calls run under a zero-data-retention agreement. Your code trains no models.
Four things we never do
- ·Your code is never built.
- ·Your code is never executed.
- ·Your code is never used to train models.
- ·Your code never leaves your tenant.
Storage
Snapshots are encrypted before they reach storage, with a key per tenant and one per snapshot. Storage addresses are derived with a tenant-specific salt, so identical files in different accounts never share a location, and deduplication never crosses tenants.
Deletion
On cancellation, files are deleted immediately and the tenant key is destroyed after seven days, which makes every remaining copy unreadable, backups included. Backups expire after thirty days at the latest.
If a secret slips through
The value is replaced with a redaction marker, the snapshot is re-encrypted, and you are notified with the location and a rotation recommendation.
Access
Project tokens are write-only: they can push snapshots but never read code or anything derived from it. Staff access is role-based and logged; nobody opens raw code without an explicit, recorded approval.
Subprocessors and the full storage terms are on the trust page.
Updated 2026-08-05