Private early access · free while in early accessWhat works today
Security · reviewed 10 October 2026

Your code stays where it is.

Groundrule needs your rules, not your source. Checks run on your machines; the platform keeps the rulebook, results and proposals, separated by workspace in the database itself. This page lists what's in place and, just as plainly, what isn't yet.

§ 01never kept

Four things Groundrule is built not to hold.

What Groundrule never keeps.

never · 01

Your source code

Checks run on your laptop or CI runner. A scan uploads results: counts, outcomes, and at most three one-line snippets per rule (200 characters, secrets redacted, none for security rules). --no-snippets uploads none.

never · 02

Uploaded files

A document is read into text passages and the file is discarded. The passages are deleted when reading ends, whatever the outcome.

never · 03

Raw secrets

Passwords exist only as scrypt hashes; sessions, email links and API tokens only as SHA-256 hashes; connected-app tokens only encrypted.

never · 04

What you send to AI

The usage ledger records counts and cost: feature, person, model, tokens, status. Never the text sent or returned.

§ 02controls

Each row describes what the code does today, checked against the service on 10 October 2026.

What protects a workspace.

02.1Workspace isolation

Row-level security
Every workspace's data carries its workspace ID, and Postgres row-level security restricts every query to the signed-in person's workspace. The application checks it as well.
A least-privilege database role
The service connects as a role that is not the owner, not a superuser and cannot bypass row-level security. Migrations run as a separate owner role.
Leak tests
Every workspace-scoped query has an automated test that a second workspace cannot read it.
No hints to outsiders
Someone who isn't a member gets “not found” for a workspace's address, never “forbidden”, so workspace names aren't revealed.

02.2Signing in

Passwords
scrypt with N=2^17, r=8, p=1 and a random salt; 10 to 128 characters; common breached passwords and passwords containing your email are refused; compared in constant time.
Sessions
One HTTP-only, SameSite=Lax, Secure cookie (gr_session), valid 30 days. Changing or resetting your password ends every other session.
Email links
Sign-in links work once for 15 minutes, reset links once for 30 minutes, confirmations once for 24 hours. Only a hash of each link is stored.
No account enumeration
Sign-in failures take the same time and say the same thing whether or not the email has an account. Forgot password always shows “Check your inbox”.
Request forgery
Every request made with a session must come from the Groundrule app's own origin.
Rate limits
On sign-in, sign-up, email links, password changes, AI requests, imports, proposals and scan uploads, per person, per address and per workspace.

02.3API and CLI tokens

Scoped
Reading the rulebook is always included; uploading scans and proposing rules are optional. No token can change the rulebook, members or settings, and tokens never work with a cookie.
Stored as hashes
grt_ followed by 32 random bytes, shown once. Only a SHA-256 hash and the first 12 characters are kept.
Expiring and revocable
30, 90 or 365 days, or never. CLI sign-in tokens last 90 days and need approval in the browser. Admins can revoke anyone's.
HTTPS only
The CLI refuses to send credentials over plain HTTP to anything but localhost.

02.4Connected apps and GitHub

Read-only by design
Notion: read content. Google: documents.readonly (a document you paste the link to, not your Drive). Confluence: read pages. GitHub App: pull requests and metadata, read-only.
Encrypted tokens
Notion, Google and Confluence tokens are encrypted with AES-256-GCM and never shown. Disconnecting deletes them.
Verified installs
A GitHub installation is saved only after GitHub confirms the person installing it can see it, so an installation ID can't be swapped for someone else's.
Signed webhooks
Every GitHub delivery is verified by its HMAC-SHA256 signature over the raw body, handled once, and bots are ignored.

02.5AI

Secrets removed first
Private keys, cloud and API tokens, passwords assigned in code, credentials in connection strings and long random-looking strings are masked in everything before it is sent to the model.
One provider
Anthropic's Claude API. Standard retention, or zero retention where a zero-data-retention agreement is in place, in which case no answers are cached either.
A person decides
Every AI result is a proposal labelled AI with a confidence. Nothing AI writes takes effect until someone accepts it.
Budgets
A monthly budget per workspace, an estimate before any document is read, and a refusal, with nothing sent, once the budget is spent.
§ 03status

Groundrule is in private early access. If your review needs something on the “not yet” list, tell us.

In place, and not yet.

The “not yet” rows matter as much as the rest. What your review needs changes what we build next.

In placeRow-level workspace isolation with leak tests
In placescrypt passwords, hashed sessions, single-use email links, rate limits
In placeScoped, hashed, expiring API tokens; browser-approved CLI sign-in
In placeEncrypted app tokens; read-only connections; signed, de-duplicated webhooks
In placeSecret redaction before AI; usage ledger without content; per-workspace budgets
In placeAn append-only audit log of administrative actions
Not yetTwo-factor authentication, single sign-on (SAML/OIDC) and SCIM
Not yetRevoking CLI and API tokens automatically when a password is reset (revoke them in Settings → API tokens)
Not yetDeleting an account or a workspace from the dashboard (write to us and we do it)
Not yetHosting outside the United States (Oregon)
Not yetA SOC 2 or ISO 27001 report, and a service level agreement
§ 04providers

Every provider that handles workspace data, and why.

The providers behind the service.

PartProviderWhat it handles
API and databaseRailwayUnited States (Oregon). Postgres with row-level security; the service has no superuser access.
Dashboard, documentation, this websiteVercelStatic and client-side; no data stored there.
EmailResendSign-up, sign-in link, password reset and invitation emails.
AIAnthropicOnly when someone uses an AI feature in a workspace that has AI turned on.
Optional, per workspaceGitHub, Notion, Google, AtlassianOnly when an admin connects them, with the read-only access above.
§ 05questions

Something missing? Write to support@groundrule.dev.

What security reviews ask.

Do you train models on our code or documents?

No. Groundrule trains nothing. AI features send the text needed for one request to Anthropic's API, under Anthropic's commercial terms for API customers, with secrets removed first.

Can someone at Groundrule see our rulebook?

The people who run the service can access the database to operate and support it, and only when that's needed. They don't read workspaces otherwise, and the dashboard has no staff view into customer workspaces.

Is our data encrypted?

In transit, always: HTTPS everywhere, with HSTS. Connected-app tokens are encrypted by Groundrule with AES-256-GCM before they're stored, and secrets such as passwords and API tokens are only ever stored as hashes.

How do we report a vulnerability?

Email support@groundrule.dev with “Security” in the subject. Please include steps to reproduce, and don't test against other customers' workspaces. A person who builds Groundrule reads every report.

§ 06 · sign-off · Private early access, free while in early access

Review it with your own code.

Connect one repository, scan it with --no-snippets, and look at exactly what reached us on the scan's page. Then decide.