The four trust pillars

EraEvo is built for developers who want to use AI on real codebases — not toy examples. Trust is the binding constraint, so we treat it as a first-class product surface, not marketing language.

  1. No-training guarantee. Your code, prompts, and outputs are never used to train any model — ours or any vendor's. Contractual, not aspirational.
  2. Permission-scoped sandbox. EraEvo can only touch files, commands, and network resources you explicitly allow.
  3. Verified output. Every change is gated by a green build and a passing test suite. We don't ship code that doesn't compile.
  4. Reversible by default. Every execution is a snapshot. Replay, revert, or audit any change in one click.

No-training guarantee

We do not train models on your code. We do not allow our AI vendors to train on your code. We do not retain your prompts or outputs beyond what is required to deliver the service.

Specifically:

  • Code, prompts, and outputs are encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Cloud AI calls (OpenAI, Anthropic, Google) are made under enterprise-grade no-retention agreements where the vendor supports them. For vendors that cannot offer no-retention, we route only to endpoints that exclude your inputs from training.
  • You can verify exactly what was sent to which model on every execution via the per-execution prompt log (Pro and above).
  • Bring-your-own-key (BYO) routing is available on Pro and above — your requests go directly through your own API account, bypassing our keys entirely.
  • If you want zero data leaving your infrastructure, the Enterprise tier ships on-prem (single-tenant Docker bundle) with no outbound calls.

This guarantee is contractual. It is part of every paid plan's Terms of Service and is auditable on request for Enterprise customers.

Permission-scoped sandbox

EraEvo runs generated code under explicit, per-resource permission grants. Every grant has a scope (one directory, one command, one network host) and is visible in the product status bar at all times.

On the Worker side, generated builds run in an isolated container with no network access by default. The container is destroyed at the end of every execution; nothing persists outside the workspace volume you authorised.

Verified output

EraEvo is autonomous, but it is not unsupervised. Before any change is committed to disk:

  • The C# source is parsed by Roslyn — invalid syntax is rejected, not shown.
  • The project builds with dotnet build. If the build fails, EraEvo fixes it (up to 3 attempts) before showing you the result.
  • Tests are generated and run. If tests fail, EraEvo drives a test-targeted fix loop before showing you the result.
  • You see the diff. You approve per file (or all). Only then does anything write to your repository.

Reversible by default

Every execution is captured as a deterministic snapshot — files written, AI calls made, build output, test results, costs. The snapshot is replayable without new AI calls (useful for audits and regression tests) and reversible with a single API call.

When EraEvo opens a pull request through the GitHub App, the change lands on a shadow branch — never directly on your default branch.

Audit trail

Every action — execution started, file written, permission granted, plan changed, key created, key revoked — lands in an audit log keyed to the user who performed it.

  • Free / Pro: 7 / 30 days retention.
  • Team: 365 days retention.
  • Enterprise: unlimited retention, SIEM-ready export (Splunk, Datadog, generic syslog).

Compliance & data residency

  • SOC 2 Type II — audit in progress; Type I evidence pack landing Q3 2026.
  • GDPR — data subject access request endpoints (/account/export, /account/delete) self-serve on every plan.
  • EU data residency — Team and Enterprise tiers can pin workloads to eu-west with no transit through US infrastructure.
  • On-prem deployment — Enterprise option. Single-tenant Docker bundle, signed updates, license-key activation. Nothing leaves your network.

Encryption

  • HTTPS / TLS 1.3 for all transport.
  • AES-256 at rest in PostgreSQL.
  • API keys hashed (SHA-256) before storage; raw keys shown once at creation.
  • OAuth tokens stored under DPAPI encryption on the Windows desktop client.
  • BYO provider keys stored encrypted at the field level using ASP.NET Core Data Protection.

Bug bounty & vulnerability disclosure

We accept responsible-disclosure reports at [email protected]. Public security.txt is published at /.well-known/security.txt. Critical issues are acknowledged within 24 hours and patched within 72.

Subprocessors

EraEvo uses the following subprocessors. We do not add or change subprocessors without notifying paid customers in advance.

  • Anthropic, OpenAI, Google — AI inference. No-retention agreements where supported by the vendor.
  • Stripe — payment processing.
  • Cloudflare — DNS + edge TLS.
  • Oracle Cloud (Mumbai region) — hosting.
  • Better Stack — uptime monitoring + status page.

Reporting an issue

Security questions, audit requests, or compliance documents: [email protected].

Sales / Enterprise procurement: Contact us.