FAQ

Clear answers before you connect.

RepoEvidence is intentionally narrow: evidence collection and packaging, without compliance claims.

Does RepoEvidence read source code?

No. The requested GitHub App permissions cover repository metadata, pull requests, checks, workflows, and administration metadata. File contents are outside the collection path.

What makes a report deterministic?

The same normalized observation produces the same canonical JSON byte sequence and SHA-256 seal. Keys are sorted, timestamps are explicit, and presentation files derive from that record.

Is this a SOC 2 certification?

No. RepoEvidence supplies change-control observations. Your auditor and control owner decide whether those observations satisfy your control design and audit scope.

Can I delete my data?

Yes. Owners can remove an installation and request tenant deletion. Scheduled retention cleanup also removes expired report payloads.