Sanctra touches your repository. That deserves conservative defaults, transparent behavior, and mechanics you can audit. Here's how we approach it.
Sanctra requests only the GitHub scopes required to analyze code and open PRs. Installation is per-repository and revocable at any time.
Every change ships as a pull request on a Sanctra branch. Sanctra cannot merge, force-push, or modify your default branch.
Sanctra generates .env templates and secret checklists. It never retrieves, stores, or forwards secret values.
Every analysis, generation, and PR is logged with a diagnostic ID. History is preserved even for dismissed recommendations.
We publish incident notes, respond to responsible disclosure, and sign customer questionnaires for beta partners.