We need read access to one repo. Your tests run in a private copy on our CI, nothing is ever pushed to
your repository, and the copy is deleted within 30 days after you cancel.
Where your code goes
A private copy. Your repository is copied into a private GitHub repository in the Trenyx account. Only Trenyx can see it.
Your tests run on GitHub's machines. Each planted bug runs your own test command on GitHub Actions runners, in the private copy. Nothing runs on your systems.
Nothing is pushed to your repo. We never open branches, pull requests or issues on your repository.
AI models. To write the bug list, your code is read by Anthropic's Claude, with training on our data switched off. It is not used to train models and is not sent to any other AI provider.
Access
Read only. For a private repo, a read-only deploy key on that one repository. Remove it at any time and the next run doesn't happen.
No production secrets. Tests run with test values. If your suite needs a database or another service, it starts in a container the way your CI starts it.
Reports are private. Only the people you name can open them.
What we keep, and for how long
Kept while you subscribe: the private copy, each month's bug list, the CI results and your reports.
Deleted within 30 days after you cancel. Ask and we delete sooner.
Confidentiality
Never published without your written permission. Not your code, your results or your name, not even anonymised. Your results never count toward our public numbers unless you opt in.
Real bugs stay private. If a run turns up a genuine bug in your shipped code, we tell you privately and separately. It is never locked behind payment.
NDA. Happy to sign yours before you share anything.