← Back to home

Security and code handling

Last updated: September 2026

Our home page asks you to send us a repository. This page is what you get to read before you do. Everything below is written into the engagement contract, so it is enforceable rather than reassuring.

1. What we ask for

Read access to the repositories in scope, and nothing beyond them. An audit does not need production credentials, customer data, or access to live systems. Where a rewrite later needs to run, it runs against your non-production environment.

If your organisation cannot grant external access at all, we work inside your infrastructure on your accounts. That option is always available and costs the same.

2. Where your code lives

Each engagement names one of two arrangements before any access is granted:

3. Which models touch your code

We use AI as leverage, so you are entitled to know exactly what that means for your source.

The default is a commercial model provider under enterprise terms that exclude training on submitted content and apply zero data retention. The provider is named in the contract, along with the terms it operates under, so the claim is checkable rather than a slogan.

You can override the default. If your risk assessment requires it, the engagement runs on self-hosted open-weight models, or entirely inside your own tenancy using your own model credentials. The choice is yours and it is recorded in writing before work starts.

We do not fine-tune on client code, and we do not reuse one client's source in another client's engagement.

4. Confidentiality

We sign your NDA. If you would rather not draft one, we bring a mutual NDA to the first call. Confidentiality covers the codebase, the architecture, the findings, and the fact that a rewrite is happening at all: no client is named publicly without written consent, which is why our case descriptions are anonymised.

5. What happens at the end

Deliverables and their intellectual property belong to you, as set out in our Terms of Service. Working copies in our environment are deleted at the close of the engagement, and we confirm the deletion in writing when you ask for it.

6. This website

The site itself collects as little as possible: no cookies, no tracking pixels, no analytics. The contact form sends your message to us by email, validates and length-caps its fields server-side, and rate-limits submissions per IP address. Full detail is in the Privacy Policy.

7. Reporting a vulnerability

Found a problem in this site or in something we built for you? Write to security@override.tech. We acknowledge within two working days and we will not pursue anyone who reports in good faith and does not access other people's data.