Your source remains your confidential work.
A production-readiness review requires source access. These commitments define how VerifiedCode may use that source while delivering the service.
Our commitments
- You retain ownership of your source and intellectual property.
- We use source only to scope, perform, quality-check, support, and secure your review.
- Source access is limited to authorized operators, the assigned reviewer, and the QA owner where needed.
- Reviewers must not copy source to personal storage or submit it to an unapproved external AI service.
- Repository packages are kept in private storage and source access is recorded.
- Source packages are deleted 30 days after review completion, or queued for deletion when a review is cancelled.
- We do not use customer source for model training, marketing, case studies, or unrelated benchmarking without separate permission.
Source retention
Repository source packages are deleted 30 days after the review reaches a terminal outcome: customer acceptance, automatic acceptance, or final dispute resolution. Cancellation blocks package access and queues deletion immediately. Security, audit, dispute, and legal records that do not contain the active repository package may be retained separately.
This source-handling commitment supplements the privacy notice. It is not a penetration-test certification or a promise that submitted source contains no security risk.