Skip to content
Privacy and access

Your code can stay private

There is no integration to install, no deploy key to hand over and no third party sitting inside your source control. The procedure runs where your code already lives, and you decide what comes back.

How the work happens

Where each part actually runs

The only thing that crosses the boundary is what you choose to upload.

  1. Your context is stored, your code is not

    What TechnicalAngel keeps is a description of your system: stack, hosting, integrations, constraints, past decisions. Not files, not repositories, not credentials.

    You write it, you can edit it, and you can see exactly what is stored.

  2. The procedure is generated from that description

    It is text: steps, questions, evidence requirements and an output format. Producing it does not require reading your code.

  3. You run it on your side

    Inside your environment, with your Claude Code or Codex, against your repository. This is where your source is actually read, and it never leaves your machines.

  4. You choose what to bring back

    A report, a diagram, a summary — whatever you decide is safe. Reading the result before uploading it is the whole point, and nothing pushes you to skip that step.

  5. What you upload stays yours

    Files are scoped to your account, served through signed private links and never exposed at a public URL. Nothing is used to train anything.

What this buys you

Fewer obstacles before the first useful thing

No access review to pass

Nobody has to be added to your organisation, granted a role or issued a token before work can start.

A much smaller NDA conversation

The question changes from “who may read our source” to “which document are we sharing”, and that is a question you can answer in a minute.

No onboarding week

There is no environment to set up on our side and no repository to clone. The first procedure can run the day you subscribe.

The workspace itself

How your account is protected

Strict boundaries between accounts

Every project, document, action and review belongs to exactly one account. Cross-account access is blocked by the data layer, not by hiding a button.

No public links to private files

Uploads are never served from a guessable address. Downloads go through short-lived signed links tied to your session.

An audit trail you can read

Who ran what, who spent which credits, who uploaded what and who was invited — recorded and visible to your account administrator.

Roles that actually restrict

On team plans you decide who can run actions, who can only read, and whether a person has a credit ceiling of their own.

Being straight about it

What we do not claim

A privacy page that only makes promises is not a privacy page. Here is the other half.

We hold no security certifications

No SOC 2, no ISO 27001, no penetration-test badge. If your procurement requires one, we are not a fit today and we will say so rather than imply otherwise.

This is not legal or compliance advice

A technical security review finds technical problems. It does not tell you whether you comply with a regulation, and it is not a substitute for counsel.

What you upload, we read

A review needs a reader. If a document is too sensitive to be read by someone outside your company, do not upload it — run the procedure and keep the result.

AI is used, and we say where

Classification, generation and verification involve language models. Human expert review involves a person. The workspace always shows which one produced what you are reading.

Keep your code. Get the expertise anyway.

Run the procedure in your own environment and share only what you decide to share.