Security and code handling
Our home page asks you to send us a repository. This page is what you get to read before you do. Everything below is written into the engagement contract, so it is enforceable rather than reassuring.
1. What we ask for
Read access to the repositories in scope, and nothing beyond them. An audit does not need production credentials, customer data, or access to live systems. Where a rewrite later needs to run, it runs against your non-production environment.
If your organisation cannot grant external access at all, we work inside your infrastructure on your accounts. That option is always available and costs the same.
2. Where your code lives
Each engagement names one of two arrangements before any access is granted:
- Our environment: your code is cloned into a per-client workspace, used only by the engineers named in the contract, and deleted when the engagement closes.
- Your environment: your code never leaves your accounts. We work through the access you provision and remove nothing from it.
3. Which models touch your code
We use AI as leverage, so you are entitled to know exactly what that means for your source.
The default is a commercial model provider under enterprise terms that exclude training on submitted content and apply zero data retention. The provider is named in the contract, along with the terms it operates under, so the claim is checkable rather than a slogan.
You can override the default. If your risk assessment requires it, the engagement runs on self-hosted open-weight models, or entirely inside your own tenancy using your own model credentials. The choice is yours and it is recorded in writing before work starts.
We do not fine-tune on client code, and we do not reuse one client's source in another client's engagement.
4. Confidentiality
We sign your NDA. If you would rather not draft one, we bring a mutual NDA to the first call. Confidentiality covers the codebase, the architecture, the findings, and the fact that a rewrite is happening at all: no client is named publicly without written consent, which is why our case descriptions are anonymised.
5. What happens at the end
Deliverables and their intellectual property belong to you, as set out in our Terms of Service. Working copies in our environment are deleted at the close of the engagement, and we confirm the deletion in writing when you ask for it.
6. This website
The site itself collects as little as possible: no cookies, no tracking pixels, no analytics. The contact form sends your message to us by email, validates and length-caps its fields server-side, and rate-limits submissions per IP address. Full detail is in the Privacy Policy.
7. Reporting a vulnerability
Found a problem in this site or in something we built for you? Write to security@override.tech. We acknowledge within two working days and we will not pursue anyone who reports in good faith and does not access other people's data.