Security at Dualzo
Dualzo asks for access to your GitHub repositories and runs AI-written code against them. This page explains exactly what happens to your code, where AI-written code is allowed to run, and what stops a bad change from reaching your main branch.
- Nothing runs until a person on your team approves a written plan.
- Indexing only reads your code. It never executes it.
- AI-written code runs only inside a throwaway, locked-down container with no network after install.
- A pull request cannot be opened while validation is failing. This is enforced in code.
- Every step is written to an append-only audit log.
- We do not use your code to train any model.
Repository access
- Dualzo connects through a GitHub App. You choose which repositories it can see when you install it, and you can revoke access from GitHub at any time.
- Dualzo uses short-lived installation tokens, not a personal access token. Tokens are stored encrypted, cached only until they expire, and never written to logs.
- Every GitHub webhook is checked against its signature on the raw request body before anything in it is read.
How your code is handled
- Each job clones your repository into an isolated working directory. That directory is deleted when the job ends, including when it fails. Dualzo does not keep a copy of your source code.
- Indexing parses manifests, CI configuration, and file structure statically. It never installs dependencies or runs your code.
- Only a budgeted slice of your repository — the files and notes relevant to the task — is sent to the AI model, never the whole repository.
- We run the AI models on our own provider account. You do not need to hand us any AI provider keys.
The validation sandbox
After each task, Dualzo runs your repository's own confirmed commands — install, lint, typecheck, test, build — inside an ephemeral container built from your ecosystem's base image. The container is created for that command and removed right after.
| Control | What it means |
|---|---|
| Network | Off for every step except dependency install. |
| File system | Read-only everywhere except the working copy and a small temporary directory. |
| Privileges | All Linux capabilities dropped; processes cannot gain new privileges. |
| Resources | Default limits of 2 CPUs, 2g memory, 512 processes, and 10 minutes per command. |
| Secrets | None of Dualzo's own secrets are in the environment. Only variables you set for your own tests are passed in. |
| Lifetime | The container is thrown away after each command. |
Human approval and failing checks
- Every plan lists its tasks, the files expected to change, the commands to run, a risk level, and rollback notes. Code is only written after a workspace admin approves it.
- Approval links are signed, single-use, and expire. Members who are not admins cannot approve.
- Executions stay blocked on a repository until an admin confirms its validation commands.
- If validation fails, the model gets up to two fix attempts. After that the task stops for human review instead of opening a pull request.
- The pull request service refuses any execution whose validation is not passing. Dualzo never merges; a person always reviews and merges.
Audit trail and isolation
- Webhooks, plans, approvals, each task, each validation run, and each pull request are written to an append-only audit log. There is no way to edit or delete an entry in the app.
- Audit entries are kept for 90 days and then removed automatically.
- Every workspace is isolated: no query can read another workspace's repositories, tasks, or audit log.
Account and payments
- All traffic is served over HTTPS. Passwords are hashed, never stored in plain text.
- Credentials are stored in encrypted database columns and kept out of logs.
- Payments are handled by Paddle. We never see your full card number.
Report a vulnerability
If you think you have found a security issue, email support@dualzo.app. Please give us a reasonable chance to fix it before sharing it publicly. For how we handle personal data, see the Privacy Policy.
Team plan — $119/month, 5 seats included. AI model usage included.