Trust center

Trust that you can check.

A verification product has to be held to its own standard. Here is what we observed, how each claim is scoped, and where to look for yourself.

Observed

In customer-CI mode, in our tests.

Every claim below is scoped: observed in our tests on GitHub-hosted runners. The check runs in your own GitHub Actions; no part of it runs on Bracel’s servers.

Telemetry
None
Data sent to Bracel
None
GitHub token
Read-only, no secrets
Network during install
Public npm registry only
Network during build and run
None
Provenance
Release commit and code digest on every result

Release integrity

Know exactly what runs in your CI.

Every result names the release commit and the code digest it ran with, so a verdict can always be traced back.

  1. 01

    Pinned

    You reference a release by its full commit SHA, never by a tag or branch.

  2. 02

    Checksummed

    Every release ships with published checksums you verify before installing.

  3. 03

    Private to you

    You install the release into a private repository you own.

  4. 04

    Withdrawable

    A template version can be withdrawn by a release; checks that name it report UNKNOWN with template-withdrawn.

Stated limits

What customer-CI mode protects against.

It protects against accidental regressions: a change that breaks an approved rule. It does not protect against a contributor who modifies the workflow itself. Protect your workflows with code owners and branch protection.

Bracel changes no merge settings. If your administrators make the check required, a failing result blocks merging.

Coming soon For independently controlled runs, hosted mode executes under its own trust class, bracel-hosted, and every evidence record states which of the two produced it.