Candidate code never touches your machine.
Every review runs in a single-use, isolated sandbox that's destroyed after the report is generated. Here's exactly how we keep your environment — and your candidates' work — safe.
Every repository runs inside an isolated, single-tenant virtual machine on E2B. The sandbox is destroyed immediately after the report is generated — no shared state, no neighbour escape surface.
Repos are cloned into the sandbox at run time and never stored on CodeVerdict servers afterward. Only the structured report and reviewer-visible logs are retained.
For private repos you provide a fine-grained, read-only token scoped to the specific repository. Tokens are encrypted at rest and used only for the clone step.
Generated reports and any uploaded brief PDFs are stored in S3 with SSE-KMS and accessed via signed, short-lived URLs only — never via public buckets.
Data handling
We take responsible disclosure seriously. Email security details directly instead of filing a public GitHub issue.
[email protected]Ready to try a sandboxed review?
Drop a GitHub URL — the next page shows you the full setup, test, and execution trace inside the sandbox.