← Back to LWBRUT
✓ Zero Data Retention Verified

Security Architecture & Trust Whitepaper

Published: October 7, 2026

1. Data Minimization & Volatile Processing

LWBRUT is architected from the ground up for strict security posture. Code payloads parsed during PR reviews are maintained strictly in-memory (RAM) in containerized sandbox workers. Upon completion of AST validation and webhook dispatch, worker memory buffers are wiped.

2. Anthropic Commercial API Safeguards

Model reasoning is handled through Anthropic's direct commercial Claude 3.5 Sonnet API endpoints:

  • No Model Training: Anthropic does not train models on prompts or completions submitted through the commercial API.
  • Zero-Day Data Retention: Requests are processed ephemerally without persistent customer prompt caching.
  • End-to-End Encryption: All transit communication occurs over TLS 1.3 with PFS (Perfect Forward Secrecy).

3. Tree-sitter Deterministic Verification

To eliminate security risks stemming from model hallucination, generated patches are passed through Tree-sitter AST validation before any comment or review is recorded on GitHub. Patches that violate syntactic safety or introduce unverified dependencies are discarded.

4. Enterprise VPC & Self-Hosting

For organizations requiring air-gapped or dedicated sovereign clouds, LWBRUT provides Model Context Protocol (MCP) servers and containerized deployments within your AWS VPC, GCP, or Azure subscription.

5. Security Contact & Vulnerability Reporting

We welcome responsible disclosure. Reports may be submitted to security@lwbrut.com.