Security and data
Security and data, path by path.
This page covers Bracel in customer-CI mode on GitHub Actions, and hosted mode where it differs. It separates what we observed in our tests from how Bracel is designed, and says which is which.
- your repository · summary, log, evidence file
- Docker Hub · image pulled by digest
- npm registry · install requests only
- Bracel · nothing
Where it runs
In your runner. Not on our servers.
In customer-CI mode, the check runs in your own GitHub Actions runner. No part of it runs on Bracel’s servers.
Hosted mode
For teams that want independently controlled evidence, hosted mode runs the check on Bracel infrastructure under the trust class bracel-hosted. Code is processed only while a run executes and is deleted by default. Each customer has its own encryption keys and access logs; on Enterprise you can hold the key yourself. See Enterprise.
Every data path
Five paths. One of them is empty.
What leaves the runner, what it contains, and where it goes.
-
Check summary and job log
The report: rules, routes from your rules file, status codes, numbers, commit SHAs
Your repository on GitHub
-
Evidence file · opt-in
The same fields as JSON
A workflow artifact in your repository, kept 7 days, readable by whoever can read your Actions artifacts (anyone, for a public repository)
-
Runtime image
Nothing from you
Pulled from Docker Hub, pinned by digest
-
Dependency install
Requests for the packages your lockfile names
The public npm registry only; other destinations are refused
-
Bracel
Nothing. There is no telemetry.
—
What we tested
Observed, and scoped.
In our tests on GitHub-hosted runners
- The action sends no telemetry and no data to us.
- It runs with a read-only GitHub token and needs no secrets.
- Dependency install reaches only the public npm registry, which sees the package names and versions requested from the runner’s address. The build and your running application have no network access.
The check summary and evidence file are built from an allowlist of fields, so they are designed not to contain your source code, application responses, application logs, or the values of configured headers and environment variables. Tests that planted marker strings in each of those found none. This rests on the allowlist and those tests, not on a formal proof.
Where the tool and the rules come from
Where the tool comes from
A pinned release you own.
From a pinned, versioned release with checksums, installed into a private repository you own and referenced by full commit SHA. It never comes from the pull request’s own checkout. Every result shows the commit and code digest of the release that ran.
Whose rules apply
Yours, from the base commit.
Rules and configuration are read from the pull request’s base commit, never from its head. A pull request that changes Bracel’s rules, code owners, or workflows gets UNKNOWN (policy-review-required), not a verdict. A rule takes effect only after it is merged into your base branch through your normal review.
What it protects against
Accidents, not adversaries with write access.
Every result carries the trust class customer-ci: it ran in your runner, and Bracel did not observe it.
Protects against
Accidental regressions in an approved rule, including ones introduced by AI coding tools.
Does not protect against
A contributor who modifies the workflow. Under the pull_request trigger, GitHub runs the workflow file from the pull request itself, so anyone who can change the workflow, the runner, or the job can change or fake the result.
Protect .github/workflows/ and the rules file with code owners. The workflow we provide does not use pull_request_target and gives pull request code no write-scoped secrets. Bracel changes no merge settings.
If Bracel gets it wrong
An incorrect PASS is a security issue.
We notify affected teams directly, ship a fixed release, and withdraw the affected rule template.
Report a vulnerability
security@bracel.devIncluding a suspected incorrect PASS. Please include the release version, what you observed, and steps to reproduce. Do not include production data or credentials.