Your code stays where it is.
Groundrule needs your rules, not your source. Checks run on your machines; the platform keeps the rulebook, results and proposals, separated by workspace in the database itself. This page lists what's in place and, just as plainly, what isn't yet.
Four things Groundrule is built not to hold.
What Groundrule never keeps.
Your source code
Checks run on your laptop or CI runner. A scan uploads results: counts, outcomes, and at most three one-line snippets per rule (200 characters, secrets redacted, none for security rules). --no-snippets uploads none.
Uploaded files
A document is read into text passages and the file is discarded. The passages are deleted when reading ends, whatever the outcome.
Raw secrets
Passwords exist only as scrypt hashes; sessions, email links and API tokens only as SHA-256 hashes; connected-app tokens only encrypted.
What you send to AI
The usage ledger records counts and cost: feature, person, model, tokens, status. Never the text sent or returned.
Each row describes what the code does today, checked against the service on 10 October 2026.
What protects a workspace.
02.1Workspace isolation
- Row-level security
- Every workspace's data carries its workspace ID, and Postgres row-level security restricts every query to the signed-in person's workspace. The application checks it as well.
- A least-privilege database role
- The service connects as a role that is not the owner, not a superuser and cannot bypass row-level security. Migrations run as a separate owner role.
- Leak tests
- Every workspace-scoped query has an automated test that a second workspace cannot read it.
- No hints to outsiders
- Someone who isn't a member gets “not found” for a workspace's address, never “forbidden”, so workspace names aren't revealed.
02.2Signing in
- Passwords
- scrypt with N=2^17, r=8, p=1 and a random salt; 10 to 128 characters; common breached passwords and passwords containing your email are refused; compared in constant time.
- Sessions
- One HTTP-only, SameSite=Lax, Secure cookie (gr_session), valid 30 days. Changing or resetting your password ends every other session.
- Email links
- Sign-in links work once for 15 minutes, reset links once for 30 minutes, confirmations once for 24 hours. Only a hash of each link is stored.
- No account enumeration
- Sign-in failures take the same time and say the same thing whether or not the email has an account. Forgot password always shows “Check your inbox”.
- Request forgery
- Every request made with a session must come from the Groundrule app's own origin.
- Rate limits
- On sign-in, sign-up, email links, password changes, AI requests, imports, proposals and scan uploads, per person, per address and per workspace.
02.3API and CLI tokens
- Scoped
- Reading the rulebook is always included; uploading scans and proposing rules are optional. No token can change the rulebook, members or settings, and tokens never work with a cookie.
- Stored as hashes
- grt_ followed by 32 random bytes, shown once. Only a SHA-256 hash and the first 12 characters are kept.
- Expiring and revocable
- 30, 90 or 365 days, or never. CLI sign-in tokens last 90 days and need approval in the browser. Admins can revoke anyone's.
- HTTPS only
- The CLI refuses to send credentials over plain HTTP to anything but localhost.
02.4Connected apps and GitHub
- Read-only by design
- Notion: read content. Google: documents.readonly (a document you paste the link to, not your Drive). Confluence: read pages. GitHub App: pull requests and metadata, read-only.
- Encrypted tokens
- Notion, Google and Confluence tokens are encrypted with AES-256-GCM and never shown. Disconnecting deletes them.
- Verified installs
- A GitHub installation is saved only after GitHub confirms the person installing it can see it, so an installation ID can't be swapped for someone else's.
- Signed webhooks
- Every GitHub delivery is verified by its HMAC-SHA256 signature over the raw body, handled once, and bots are ignored.
02.5AI
- Secrets removed first
- Private keys, cloud and API tokens, passwords assigned in code, credentials in connection strings and long random-looking strings are masked in everything before it is sent to the model.
- One provider
- Anthropic's Claude API. Standard retention, or zero retention where a zero-data-retention agreement is in place, in which case no answers are cached either.
- A person decides
- Every AI result is a proposal labelled AI with a confidence. Nothing AI writes takes effect until someone accepts it.
- Budgets
- A monthly budget per workspace, an estimate before any document is read, and a refusal, with nothing sent, once the budget is spent.
Groundrule is in private early access. If your review needs something on the “not yet” list, tell us.
In place, and not yet.
The “not yet” rows matter as much as the rest. What your review needs changes what we build next.
Every provider that handles workspace data, and why.
The providers behind the service.
| Part | Provider | What it handles |
|---|---|---|
| API and database | Railway | United States (Oregon). Postgres with row-level security; the service has no superuser access. |
| Dashboard, documentation, this website | Vercel | Static and client-side; no data stored there. |
| Resend | Sign-up, sign-in link, password reset and invitation emails. | |
| AI | Anthropic | Only when someone uses an AI feature in a workspace that has AI turned on. |
| Optional, per workspace | GitHub, Notion, Google, Atlassian | Only when an admin connects them, with the read-only access above. |
Something missing? Write to support@groundrule.dev.
What security reviews ask.
Do you train models on our code or documents?
No. Groundrule trains nothing. AI features send the text needed for one request to Anthropic's API, under Anthropic's commercial terms for API customers, with secrets removed first.
Can someone at Groundrule see our rulebook?
The people who run the service can access the database to operate and support it, and only when that's needed. They don't read workspaces otherwise, and the dashboard has no staff view into customer workspaces.
Is our data encrypted?
In transit, always: HTTPS everywhere, with HSTS. Connected-app tokens are encrypted by Groundrule with AES-256-GCM before they're stored, and secrets such as passwords and API tokens are only ever stored as hashes.
How do we report a vulnerability?
Email support@groundrule.dev with “Security” in the subject. Please include steps to reproduce, and don't test against other customers' workspaces. A person who builds Groundrule reads every report.
Review it with your own code.
Connect one repository, scan it with --no-snippets, and look at exactly what reached us on the scan's page. Then decide.