Commitments

Twelve things Mendward will not do.

They are written as refusals because a refusal is checkable. A reviewer can hold any change to this list, and a change that breaks one is a regression, whatever else it improves.

  1. 01

    It will not report a check as passed when it did not run.

    A skipped check is recorded as skipped, with the reason, in the database, the interface and the pull request. It never turns green later.

  2. 02

    It will not output a confidence percentage.

    You get a level, LOW, MEDIUM or HIGH, plus every signal that produced it. Three weak findings and one strong one do not average to 72%.

  3. 03

    It will not fabricate a number.

    Counts, lines, durations and outputs come from a measurement a code path performed. An empty value means nothing was measured, never zero.

  4. 04

    It will not touch a line no edit claimed.

    Every changed line is attributed to a specific edit and checked against an independently computed diff. Reflowed whitespace is refused outright.

  5. 05

    It will not hide a repository it could not verify.

    If verification could not run, the pull request says so on its first screen, not in a footnote.

  6. 06

    It will not read your repository as instructions.

    A model sees repository text only in a delimited data channel, with a static system prompt, provenance on every fragment and visible truncation.

  7. 07

    It will not ask GitHub for a permission it cannot justify.

    Four permissions, each traced to one product behaviour. Anything it might be tempted to add is named in a forbidden list that fails the build.

  8. 08

    It will not run your code outside a sealed container.

    No network, a read-only worktree, dropped capabilities and hard resource ceilings. Production refuses to start on an unpatched runtime.

  9. 09

    It will not forward a secret into a container, an error or a log.

    Environment is passed by explicit value only, and 23 control-plane secret names are refused even when asked for.

  10. 10

    It will not delete or edit an audit row.

    The audit trail is append-only at the database level and hash-chained per organization, so an edit breaks the chain.

  11. 11

    It will not tell you your code is safe when it does not know.

    An empty set of findings is a hard failure, not a reassuring empty plan. Not knowing is reported as not knowing.

  12. 12

    It will not average.

    If four places need a human, it says four places need a human, and names them.

A tool that is right most of the time and silent about the rest is a tool you have to check every time. These commitments are how Mendward earns not being checked.

See it run on your own repository.

Mendward is in private beta for teams that integrate with third-party APIs from TypeScript on GitHub.

Request access
0:00 / 1:08
UpDown to moveEnter to runType / for a few more