Security

A set of properties, each with a test that fails if it stops being true.

Mendward will hold some of the most sensitive code a company has. We do not call it secure. We say what it does, how it is enforced, and where the edges still are.

Tenants cannot see each other.

Every tenant table carries the organization, with row-level security enabled and forced, and composite keys that make a cross-organization reference impossible to write.

  • A cross-tenant request returns a 404 byte-for-byte identical to a real miss. A 403 would confirm the resource exists.
  • The application database role is checked at startup: if it is a superuser or can bypass row-level security, the process refuses to boot.
  • A verifier walks every table and every database function and exits non-zero on any violation. Last run: 20 tables, 8 functions, 0 violations.

Four permissions, and nothing else.

Mendward is a GitHub App, not a personal token. It asks for contents read, contents write, pull requests write and metadata read. Each is traced to one behaviour.

  • Checks write, workflows write, packages write and members read are on a forbidden list. Adding one fails the build.
  • Installation tokens are minted on demand, cached in memory for at most an hour, and never written to a database.
  • A GitHub installation belongs to exactly one organization, enforced by a unique constraint across the whole database.
  • Webhooks are verified over the raw bytes with a constant-time comparison before anything parses them.

Sign-in that gives nothing away.

Passwords are hashed with Argon2id. Sessions are opaque, server-side and rotated. Three independent layers stop cross-site requests.

  • An unknown address and a wrong password take the same time to answer, so neither leaks which accounts exist.
  • Sign-in throttling is durable and shared across every process, not a counter in one process’s memory.
  • Idle and absolute session lifetimes are enforced by a reaper that runs on a schedule.
  • Four roles. Only an owner can change or remove an owner.

Your code runs in a sealed container.

Verification never runs on the control plane. Every container is built from one reviewed argument list, asserted element by element in a golden test.

  • No network. A read-only worktree. All Linux capabilities dropped, no new privileges, and hard ceilings on memory, swap, processes, files and file size.
  • Environment variables are passed by explicit value only, and 23 control-plane secret names are refused even when requested.
  • Production refuses to start on an unpatched container runtime, an unlisted image, or a host path outside its root.
  • Red-team cases covering address encodings, symlink traversal and resource bombs were all contained.

A model never reads your repository as instructions.

When a model is used at all, it sees repository text only in a delimited data channel, with a static system prompt, provenance on every fragment and visible truncation.

  • Customer source and accidentally committed secrets are kept out of model requests, proven by 45 tests on that boundary.
  • No model is required. The whole pipeline runs with the model switched off, and that is the default.
  • A model never certifies its own work. Verification owns correctness.

An audit trail the audited cannot edit.

Important actions are written to an append-only, per-organization, hash-chained log. The application role can insert and read, never update or delete.

  • Denied and failed outcomes are recorded, not only successes. A trail that records only success is not an audit trail.
  • Each entry hashes the previous one under a per-organization lock, so two writers cannot fork the chain.

What we do not claim yet.

A security page that lists only strengths is a brochure. These are the edges, in our words, before a reviewer has to find them.

Docker is not a hostile multi-tenant boundary.
Containers are hardened and production refuses unpatched runtimes, but only gVisor or a microVM per job is a boundary we would stake untrusted workloads at scale on. A hosted product for untrusted workloads waits for that work, without exception.
No independent audit yet.
Every control above is proven by tests in our own suite and by our own red-team cases. No outside penetration test has been done yet, and we will say so until one has.
No compliance certificates.
Not SOC 2, not ISO 27001, not yet. We will not imply otherwise in a sales call.
GitHub only.
GitHub Enterprise Server, GitLab, Bitbucket and Azure DevOps are not supported, and nothing pretends they are.

Found something?

Write to security@mendward.com. Include what you did, what you saw, and how to reproduce it. We read every report and reply to it.

Bring your security team to the first call.

We would rather answer hard questions before you connect a repository than after.

Request access
0:00 / 1:08
UpDown to moveEnter to runType / for a few more